Meilenstein 1: Multi-Account-Security-Plattform
Entwirf eine governte Security-Plattform für mindestens fünf Konten und zwei Regionen.
Enthalten:
- IAM Identity Center und Workload Roles,
- SCPs und Delegated Security Administration,
- KMS-, Secrets-Manager-, Certificate- und Data-Classification-Controls,
- Central Config und CloudTrail,
- Security-Hub-Posture und Finding Aggregation,
- GuardDuty-, Inspector-, Macie- und Access-Analyzer-Coverage,
- Automated Finding Enrichment und begrenzte Remediation,
- geschützte Security-Tooling- und Log-Archive-Konten,
- Security Metrics, Exceptions, Evidence und Cost Governance.
Eine Coverage Matrix und einen getesteten Security-Response-Workflow liefern.