European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory…
Tag: AWS Security Blog
Architecting a secure landing zone in the AWS European Sovereign Cloud
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within…
AWS STS simplifies session token size limits and adds session token size monitoring
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has…
Architecting resilient authentication with Amazon Cognito multi-Region replication
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and…
Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they…
AWS Security Reference Architecture: A deep dive into PCI DSS compliance
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data…
The state of AI for security: Measuring what matters most for building trust
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response,…
The state of AI for security: Measuring what matters most for building trust
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response,…
OSPAR 2026 report now available with 167 services in scope
We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment…
Incident response guide for AWS CloudTrail investigations – Part 2
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware…
Incident response guide for AWS CloudTrail investigations – Part 1
AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how…
Managing identity source transition for AWS IAM Identity Center
September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center…
Agentic security: Detection and response at machine speed
After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant…
We invited a direct competitor into Security Hub Extended. Here’s why.
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we…
Automate IAM Identity Center governance with continuous discovery and reporting
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution…
Extend your data perimeter to the AWS Management Console with Private Access
Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated…
Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data,…
ICYMI: July 2026 @AWS Security
If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service…
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business…
Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS
This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA)…
