AWS Well-Architected Security Pillar
Amazon Web Services security best practices framework
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
AWS Well-Architected Security Pillar: Cloud Governance
Governance of cloud security (AWS Well-Architected Security Pillar)
| Code | Title |
|---|---|
| AWS-WA-01 | Shared responsibility model definition |
| AWS-WA-02 | Cloud security policy and strategy |
| AWS-WA-03 | Cloud risk assessment |
| AWS-WA-04 | Regulatory compliance for cloud services |
| AWS-WA-05 | Cloud security roles and responsibilities |
AWS Well-Architected Security Pillar: Cloud Infrastructure Security
Securing cloud infrastructure (AWS Well-Architected Security Pillar)
| Code | Title |
|---|---|
| AWS-WA-16 | Virtual network segmentation |
| AWS-WA-17 | Container and serverless security |
| AWS-WA-18 | Cloud workload protection |
| AWS-WA-19 | Image and template hardening |
| AWS-WA-20 | Cloud configuration management |
AWS Well-Architected Security Pillar: Cloud Operations & Monitoring
Operating and monitoring cloud securely (AWS Well-Architected Security Pillar)
| Code | Title |
|---|---|
| AWS-WA-21 | Cloud security monitoring and logging |
| AWS-WA-22 | Incident response in cloud |
| AWS-WA-23 | Cloud vulnerability management |
| AWS-WA-24 | Cloud change management |
| AWS-WA-25 | Service level agreement management |
AWS Well-Architected Security Pillar: Data Protection in Cloud
Protecting data in cloud services (AWS Well-Architected Security Pillar)
| Code | Title |
|---|---|
| AWS-WA-11 | Data classification for cloud |
| AWS-WA-12 | Encryption of cloud-stored data |
| AWS-WA-13 | Data residency and sovereignty |
| AWS-WA-14 | Data backup and recovery in cloud |
| AWS-WA-15 | Secure data deletion in cloud |
AWS Well-Architected Security Pillar: Identity & Access in Cloud
Identity management in cloud environments (AWS Well-Architected Security Pillar)
| Code | Title |
|---|---|
| AWS-WA-06 | Cloud identity management |
| AWS-WA-07 | Multi-factor authentication for cloud |
| AWS-WA-08 | Privileged access in cloud environments |
| AWS-WA-09 | Federation and single sign-on |
| AWS-WA-10 | API security and access tokens |
Maps to 641 other frameworks
Frequently Asked Questions
What is AWS Well-Architected Security Pillar?
AWS Well-Architected Security Pillar is a compliance framework from International with 5 domains and 25 controls. Amazon Web Services security best practices framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does AWS Well-Architected Security Pillar have?
AWS Well-Architected Security Pillar has 25 controls organised across 5 domains. The largest domains are AWS Well-Architected Security Pillar: Cloud Governance (5 controls), AWS Well-Architected Security Pillar: Cloud Infrastructure Security (5 controls), AWS Well-Architected Security Pillar: Cloud Operations & Monitoring (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does AWS Well-Architected Security Pillar map to?
AWS Well-Architected Security Pillar maps to 641 other compliance frameworks. The top mapping partners are Azure Security Benchmark (76% coverage), NIST SP 800-190 (76% coverage), CAIQ (CSA) (76% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with AWS Well-Architected Security Pillar compliance?
Start your AWS Well-Architected Security Pillar compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AWS Well-Architected Security Pillar requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required