You are on page 1of 3

Hands-On Lab

Activity: Security
and Risk Tools

Step 1
In this Hands-On Lab Activity you will examine just some of the tools that can
assist with governance in the cloud. The purpose is just to demonstrate the wide
variety of tools available.

Log in to the AWS console using the myaccount AWS admin account you
created in the previous lab.
Step 2
Select the menu item called Services in the top left of the console to see a
categorized list of all of the AWS services currently available in the public cloud.
Scroll to the Security, Identity, and Compliance category. Click on the
service named Inspector.

Notice how this service can assist you with vulnerability assessments for your
virtual machines running in the cloud. Notice the use of agent software that is
installed on these virtual machines.

Step 3
Once again, select the Services option in the top left of the console. Scroll to
the Security, Identity, and Compliance category. Select Amazon Macie
from the list of services.

Notice that this service can help you directly in the area of risk management.
This service can analyze the data that exists in your AWS S3 storage buckets and
uses machine learning to help categorize your data in terms of risk and sensitive
information stored in these buckets.

Step 4
Once again, select the Services option in the top left of the console. Scroll to
the Security, Identity, and Compliance category. Select AWS Audit
Manager from the list of services.
AWS Audit Manager helps you continuously audit your AWS usage to simplify
how you assess risk and compliance with regulations and industry standards.
Audit Manager makes it easier to evaluate if your policies, procedures, and
activities are operating as intended. The service offers prebuilt frameworks with
controls that are mapped to well-known industry standards and regulations, full
customization of frameworks and controls, and automated collection and
organization of evidence as defined by each control requirement.

Step 5
Once again, select the Services option in the top left of the console. This time,
scroll to the Management & Governance category. Select CloudWatch from
the list of services.

CloudWatch is the main monitoring service of AWS. You can use this tool to
carefully monitor metrics across most of your workloads and services.

Step 6
Once again, select the Services option in the top left of the console. Again,
scroll to the Management & Governance category. Select CloudTrail from
the list of services.

CloudTrail permits you to carefully audit all the actions against your
infrastructure and public cloud. This tool creates critical artifacts that you can use
to help control and comply with cloud usage policies.

You might also like