AWS Security Best Practices Checklist
AWS security best practices for beginners are a defensive checklist: protect the root user, enforce MFA and least privilege on IAM, turn on CloudTrail and a detector such as GuardDuty, lock down storage and security groups, and watch spend. This guide is a practical checklist — not an exploit walkthrough.
Friends! You opened an AWS account and cheered for free tier — but skipped the security checklist? Risky. Today: defensive checklist: root MFA, IAM, CloudTrail, GuardDuty, SG, S3, budgets. Try on your own account; never change company prod without change control.
मित्रांनो! AWS account open केला आणि free tier cheer — पण security checklist skip? Risky. आज defensive checklist: root MFA, IAM, CloudTrail, GuardDuty, SG, S3, budgets. Own account मध्ये try; company prod मध्ये change control शिवाय नको.
मित्रों! AWS account खोला और free tier cheer — लेकिन security checklist skip? Risky. आज defensive checklist: root MFA, IAM, CloudTrail, GuardDuty, SG, S3, budgets. Own account में try; company prod में change control के बिना नहीं.
Quick answer
AWS defensive checklist (vertical):
- Root: MFA on, no access keys, no daily use.
- Humans: IAM Identity Center or IAM users with MFA; groups by job.
- Workloads: IAM roles — not permanent keys in userdata.
- CloudTrail multi-region on; log file validation; central log bucket.
- GuardDuty (and Config / Security Hub when ready) enabled.
- S3 Block Public Access on by default; encrypt buckets.
- Security groups: least ports; SSH/RDP not open to the world for daily work.
- Budgets and billing alarms so mining surprises email you.
Tiny mental model:
Identity → Logging → Detection → Network/Data hygiene → Money alarms
Root daily use = career-limiting shortcut
No CloudTrail = flying blind
What do I need before this guide?
- An AWS account you own (free tier practice is fine).
- Prior reads: Create IAM user with MFA, Cloud IAM least privilege, What is cloud security?.
- Optional: Security group vs NACL.
What does the checklist look like?
AWS defensive checklist: root MFA, IAM least privilege, CloudTrail, GuardDuty signals, private data and least ports.
AWS defensive checklist: root MFA, IAM least privilege, CloudTrail, GuardDuty signals, private data आणि least ports.
AWS defensive checklist: root MFA, IAM least privilege, CloudTrail, GuardDuty signals, private data और least ports.
Educational warning: every step below is for your account or a named lab. Do not apply deny-all experiments on a shared company account without approval — you can lock teams out.
Real incident themes (public, high level)
Capital One (2019): public analyses emphasised cloud identity, metadata and misconfiguration themes — scope roles tightly and monitor unusual API use.
Leaked access keys: countless public incidents start with an AKIA… key committed to GitHub. Rotate immediately, prefer roles, alert on CreateAccessKey.
Crypto-mining surprise bills: stolen keys or open instances burn money overnight — budgets are a security control, not only finance.
Care-take bullets:
- MFA on root and every human console user.
- No long-lived keys unless unavoidable — then rotate and scope.
- CloudTrail always on; alert if someone stops it.
- Block public S3 unless a written exception exists.
- Billing alarms in the same week you create the account.
Red Team vs Blue Team (awareness only)
| Side | High-level aim | Blue counter |
|---|---|---|
| Red Team | Steal console password or access key | MFA, roles, secret scanning |
| Red Team | Abuse public bucket or open admin port | Block Public Access, least SG rules |
| Red Team | Disable logging after foothold | Org trail, immutable log copy, alerts |
| Blue Team | Shrink blast radius continuously | Least privilege, GuardDuty, reviews |
Stages only — no exploit steps.
How do I apply the AWS checklist step by step?
Step 1 — Root and break-glass
- Sign in as root only to set MFA and account contacts.
- Store MFA backup codes offline; never share root password in chat.
- Do not create root access keys.
- Create a monitored break-glass process for emergencies.
Step 2 — Human identity
- Prefer IAM Identity Center (SSO) if you have multiple accounts.
- Or create an IAM user in an Admins group with MFA — use that daily.
- Developers get deploy permission sets, not
AdministratorAccessforever. - Remove users the same week they leave the project.
Step 3 — Workload identity
- Attach roles to EC2 / ECS / Lambda instead of embedding keys.
- Scope
ActionandResourceto what the app needs (least privilege guide). - Use OIDC from CI to assume roles when you can.
- Delete unused access keys; age them out on a schedule.
Step 4 — Visibility
- Enable CloudTrail in all regions; send to a dedicated log bucket.
- Turn on log file validation.
- Enable GuardDuty in the account (and members if you use Organizations).
- Later: AWS Config rules for public buckets / open SG; Security Hub summary.
Step 5 — Data and network
- S3: Block Public Access account setting ON.
- Default encryption on buckets; careful with ACLs.
- Security groups: web 80/443 only where needed; SSH from My IP or Session Manager.
- RDS / data stores: private subnets, no public accessibility flag for learning apps that do not need it.
Step 6 — Money and hygiene
- Create a zero-spend or monthly budget with email alerts.
- Turn on free-tier usage alerts.
- Tag resources with owner; delete forgotten labs weekly.
- Snapshot important volumes; test one restore.
Ravindra Bagale's Tip
💡 Students launch EC2 and leave Security Group 22 from 0.0.0.0/0 permanently. Demo OK, habit no. Put "SG review" on a weekly calendar. In interviews "I turned on CloudTrail + GuardDuty on free tier" is concrete proof. Mentioning AdministratorAccess as a shortcut makes the panel frown. Never forget!
Ravindra Bagale's Tip – मराठी
💡 Students EC2 launch करतात आणि Security Group मध्ये 22 from 0.0.0.0/0 permanent ठेवतात. Demo OK, habit नाही. Checklist मध्ये "SG review" weekly calendar ठेवा. Interview मध्ये "मी CloudTrail + GuardDuty free tier ला on केले" – concrete proof. AdministratorAccess shortcut सांगितला तर panel frown करेल. बिल्कुल विसरू नका!
Ravindra Bagale's Tip – हिंदी
💡 Students EC2 launch करते हैं और Security Group में 22 from 0.0.0.0/0 permanent रखते हैं. Demo OK, habit नहीं. Checklist में "SG review" weekly calendar रखो. Interview में "मैंने CloudTrail + GuardDuty free tier पर on किया" – concrete proof. AdministratorAccess shortcut बताया तो panel frown करेगा. बिल्कुल मत भूलो!
Quick vocabulary
- CloudTrail — AWS API and console activity history for investigations.
- GuardDuty — managed threat detection using AWS logs and intel.
- Block Public Access — account/bucket controls that stop accidental public S3.
- Security Hub — aggregated security findings (optional next step after GuardDuty/Config).
- Break-glass — rare, monitored emergency admin path.
Priority order if you only have one evening
- Root MFA + stop daily root.
- IAM user/SSO with MFA.
- CloudTrail on.
- S3 Block Public Access.
- Budget alarm.
- GuardDuty on.
- Tighten one overly open security group.
Account and Organizations notes
- If you later use AWS Organizations, prefer an org-level CloudTrail.
- Separate log archive / security tooling accounts when the team grows.
- SCPs can block disabling security services — advanced, but know the idea exists.
- For one personal account, the single-account checklist above is enough to start.
- Never share root or admin passwords into WhatsApp for “quick help”.
Care-take — weekly AWS hygiene
- Root unused; MFA still enrolled.
- No unexpected IAM users or keys.
- GuardDuty findings triage queue not ignored for weeks.
- No new public buckets without review.
- Budget email still arrives on a test threshold.
- CloudTrail still delivering (check the trail status).
How do I fix common AWS security mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Huge bill overnight | Stolen key / open instance / mining | Rotate keys; GuardDuty; budgets; shut unused |
| AccessDenied everywhere | Over-tight policy mid-change | Read needed Action; expand narrowly |
| “Who changed IAM?” | No trail / no alerts | CloudTrail + EventBridge/SNS style alerts |
| Public website bucket by accident | ACL / policy mistake | Block Public Access; fix policy |
| Root used for daily deploys | Convenience | IAM user/SSO + MFA |
| SSH timed out after lock-down | Lost My IP rule | Console SG edit from trusted network; keep break-glass |
Try it at home
In an AWS practice account you own:
- Confirm root MFA; create/verify an IAM admin with MFA.
- Enable CloudTrail and GuardDuty; screenshot both “Enabled”.
- Confirm S3 Block Public Access at account level.
- Create a ₹/USD budget alarm (see billing alarm guide).
- Write three alert ideas: root login, StopLogging, CreateAccessKey.
Learn it properly
- IAM done right
- Detection — CloudTrail, GuardDuty, Config
- Protecting data — S3, encryption and secrets
Related guides: Cloud security explained · IAM MFA · SG vs NACL · Billing alarm
Got it? AWS security = root MFA + IAM least privilege + CloudTrail/GuardDuty + private data + least ports + budgets. Run the checklist weekly. Next: see the SOC and SOC analyst role guide.
समजलं का? AWS security = root MFA + IAM least privilege + CloudTrail/GuardDuty + private data + least ports + budgets. Checklist weekly चालवा. आता SOC आणि SOC analyst role guide बघा.
समझ में आया? AWS security = root MFA + IAM least privilege + CloudTrail/GuardDuty + private data + least ports + budgets. Checklist weekly चलाओ. आगे SOC और SOC analyst role guide देखो.
Frequently asked questions
What is the first AWS security step?
Root MFA and stop using root for everyday work.
Why enable CloudTrail?
Without an audit trail you cannot investigate who changed IAM, storage or network settings.
Is GuardDuty required on day one?
It is a strong free-tier–friendly detector to enable early; triage findings instead of ignoring them.
Should SSH be open to 0.0.0.0/0?
Not as a daily habit — prefer My IP, bastion or Session Manager patterns.
How do leaked keys relate?
Public incidents often start with long-lived keys in git — prefer roles and rotate fast.
Where are related guides?
Cloud security explained, IAM MFA, SG vs NACL and billing alarm guides on this site.