Trustworthy Software Lab
Module 2

AWS Concepts

Core AWS services that show up in every trustworthy cloud application — with common mistakes and better patterns.

IAM — Identity and Access Management

Users, groups, roles, policies, permissions, and resources. Least privilege is the foundation.

Bad
{
  "Effect": "Allow",
  "Action": "*",
  "Resource": "*"
}
Better
{
  "Effect": "Allow",
  "Action": ["dynamodb:PutItem"],
  "Resource": "arn:aws:dynamodb:ap-south-1:123456789012:table/EventRegistrations"
}
Secrets Manager

A managed secret store for API keys, DB passwords, and tokens. Never hardcode secrets in code or frontends.

Bad
const API_KEY = "college-event-secret";
Better
const apiKey = await secrets.getSecretValue("event/api-key");
CloudWatch

Logs, metrics, alarms, and dashboards. Structured logs make investigation possible.

Bad
print("success")
Better
logger.info("registration.saved", { userId, requestId });
CloudTrail

Records account activity and API events. Answers who did what, when, and where.

Bad
No record of admin activity.
Better
CloudTrail event: user=admin action=UpdateFunctionConfiguration time=...
AWS Config

Tracks resource configuration and evaluates it against managed rules to detect drift.

Bad
S3 bucket became public. Nobody noticed.
Better
Rule: s3-bucket-public-read-prohibited → non-compliant → alert.
API Gateway, Lambda, DynamoDB

Serverless building blocks: API Gateway routes requests, Lambda runs code without servers, DynamoDB stores data at scale.

Bad
Lambda with AdministratorAccess role.
Better
Lambda with a role scoped to one DynamoDB table and one action.

Security standards

Security standards are sets of controls used to evaluate whether systems follow expected security practices.

  • AWS Foundational Security Best Practices
  • CIS AWS Foundations Benchmark
  • ISO 27001-style controls
  • SOC 2-style controls
Keep it student-friendly
You don't need to memorize every control. Understand the intent: prove that your system enforces expected security practices.