Resources
Resources & Glossary
A companion reference for the session and for self-study afterwards.
Session summary
Trustworthy software is more than code that runs. It is secure, reliable, observable, auditable, and compliance-aware. AWS gives you the primitives — IAM, Secrets Manager, CloudWatch, CloudTrail, and Config — but the mindset is what turns primitives into trust.
Beginner learning checklist
- Learn basic web application architecture
- Learn AWS account and IAM basics
- Build and deploy a simple app
- Add logs
- Remove secrets from code
- Learn audit trail basics
- Understand security checks
- Add CI/CD
- Practice DevSecOps tools
- Build a security-aware portfolio project
Suggested student project ideas
- Secure event registration app
- Student complaint tracking system
- Placement document assistant
- Cloud cost alert dashboard
- Serverless URL shortener with audit logs
- Secure file upload system
- AI chatbot with document-grounded answers
- DevSecOps pipeline demo project
Recommended AWS learning areas
IAM (users, roles, policies)
S3 (buckets, encryption, access)
Lambda + API Gateway
DynamoDB basics
Secrets Manager
CloudWatch (logs, metrics, alarms)
CloudTrail
AWS Config
Bedrock (for AI-native apps)
Glossary
| Term | Definition |
|---|---|
| IAM | Identity and Access Management — controls who can do what in AWS. |
| Policy | A JSON document that grants or denies permissions. |
| Role | An IAM identity assumed by services or users to get temporary permissions. |
| Secret | Sensitive value like an API key, password, or token. |
| Log | A recorded event from your application or infrastructure. |
| Metric | A numeric measurement over time (latency, error rate, request count). |
| Audit trail | A record of who did what, when, and where in an account. |
| Compliance | Proof that a system follows required rules and controls. |
| Config drift | When a system moves away from its approved secure state. |
| Least privilege | Grant only the permissions needed to perform the task. |
| DevSecOps | Adding security practices into every step of software delivery. |
| Incident | An unexpected event that impacts availability, security, or trust. |
| Observability | The ability to understand system behavior from its outputs. |
| Encryption | Transforming data so only authorized parties can read it. |
| API | A defined way for programs to communicate. |
| Serverless | Running code without managing servers, billed per use. |
| AI-native application | An application whose core capabilities depend on AI models. |
Final takeaway
This learning app is not designed to replace AWS hands-on practice. It is designed to help students understand the security and compliance mindset before they enter a real AWS account.