AWS Concepts
Core AWS services that show up in every trustworthy cloud application — with common mistakes and better patterns.
Users, groups, roles, policies, permissions, and resources. Least privilege is the foundation.
{
"Effect": "Allow",
"Action": "*",
"Resource": "*"
}{
"Effect": "Allow",
"Action": ["dynamodb:PutItem"],
"Resource": "arn:aws:dynamodb:ap-south-1:123456789012:table/EventRegistrations"
}A managed secret store for API keys, DB passwords, and tokens. Never hardcode secrets in code or frontends.
const API_KEY = "college-event-secret";const apiKey = await secrets.getSecretValue("event/api-key");Logs, metrics, alarms, and dashboards. Structured logs make investigation possible.
print("success")logger.info("registration.saved", { userId, requestId });Records account activity and API events. Answers who did what, when, and where.
No record of admin activity.CloudTrail event: user=admin action=UpdateFunctionConfiguration time=...Tracks resource configuration and evaluates it against managed rules to detect drift.
S3 bucket became public. Nobody noticed.Rule: s3-bucket-public-read-prohibited → non-compliant → alert.Serverless building blocks: API Gateway routes requests, Lambda runs code without servers, DynamoDB stores data at scale.
Lambda with AdministratorAccess role.Lambda with a role scoped to one DynamoDB table and one action.Security standards
Security standards are sets of controls used to evaluate whether systems follow expected security practices.
- AWS Foundational Security Best Practices
- CIS AWS Foundations Benchmark
- ISO 27001-style controls
- SOC 2-style controls