Meilenstein 1: Automated-Incident-Response-Capstone
Entwirf einen Multi-Account-Workflow, der:
- AWS Health-, CloudTrail-, Application- und Compliance-Events empfängt,
- Severity und Ownership klassifiziert,
- Resource- und Deployment-Context enriched,
- Operational Work Item oder Incident Record erstellt,
- Responder notifyt und eskaliert,
- eine sichere Systems-Manager- oder Step-Functions-Remediation ausführt,
- Failed Events speichert,
- Recovery verifiziert,
- vollständige Timeline erfasst,
- Post-Incident Actions erstellt.
Destruktive oder High-Risk-Actions benötigen Manual Approval.