AWS Well-Architected Security Pillar
Amazon Web Services security best practices framework
AWS Well-Architected Security Pillar is a compliance framework from International with 7 domains and 63 controls that map to 28 other frameworks. The largest domains are Identity & Access Management (15 controls), Data Protection (11 controls), Infrastructure Protection (9 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit docs.aws.amazon.comFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Application Security
| Code | Title |
|---|---|
| SEC11-BP01 | Train for application security |
| SEC11-BP02 | Automate testing throughout the development and release lifecycle |
| SEC11-BP03 | Perform regular penetration testing |
| SEC11-BP04 | Conduct code reviews |
| SEC11-BP05 | Centralize services for packages and dependencies |
| SEC11-BP06 | Deploy software programmatically |
| SEC11-BP07 | Regularly assess security properties of the pipelines |
| SEC11-BP08 | Build a program that embeds security ownership in workload teams |
Data Protection
| Code | Title |
|---|---|
| SEC07-BP01 | Understand your data classification scheme |
| SEC07-BP02 | Apply data protection controls based on data sensitivity |
| SEC07-BP03 | Automate identification and classification |
| SEC07-BP04 | Define scalable data lifecycle management |
| SEC08-BP01 | Implement secure key management |
| SEC08-BP02 | Enforce encryption at rest |
| SEC08-BP03 | Automate data at rest protection |
| SEC08-BP04 | Enforce access control |
| SEC09-BP01 | Implement secure key and certificate management |
| SEC09-BP02 | Enforce encryption in transit |
| SEC09-BP03 | Authenticate network communications |
Detection
| Code | Title |
|---|---|
| SEC04-BP01 | Configure service and application logging |
| SEC04-BP02 | Capture logs, findings, and metrics in standardized locations |
| SEC04-BP03 | Correlate and enrich security alerts |
| SEC04-BP04 | Initiate remediation for non-compliant resources |
Identity & Access Management
| Code | Title |
|---|---|
| SEC02-BP01 | Use strong sign-in mechanisms |
| SEC02-BP02 | Use temporary credentials |
| SEC02-BP03 | Store and use secrets securely |
| SEC02-BP04 | Rely on a centralized identity provider |
| SEC02-BP05 | Audit and rotate credentials periodically |
| SEC02-BP06 | Employ user groups and attributes |
| SEC03-BP01 | Define access requirements |
| SEC03-BP02 | Grant least privilege access |
| SEC03-BP03 | Establish emergency access process |
| SEC03-BP04 | Reduce permissions continuously |
| SEC03-BP05 | Define permission guardrails for your organization |
| SEC03-BP06 | Manage access based on lifecycle |
| SEC03-BP07 | Analyze public and cross-account access |
| SEC03-BP08 | Share resources securely within your organization |
| SEC03-BP09 | Share resources securely with a third party |
Incident Response
| Code | Title |
|---|---|
| SEC10-BP01 | Identify key personnel and external resources |
| SEC10-BP02 | Develop incident management plans |
| SEC10-BP03 | Prepare forensic capabilities |
| SEC10-BP04 | Develop and test security incident response playbooks |
| SEC10-BP05 | Pre-provision access |
| SEC10-BP06 | Pre-deploy tools |
| SEC10-BP07 | Run simulations |
| SEC10-BP08 | Establish a framework for learning from incidents |
Infrastructure Protection
| Code | Title |
|---|---|
| SEC05-BP01 | Create network layers |
| SEC05-BP02 | Control traffic flow within your network layers |
| SEC05-BP03 | Implement inspection-based protection |
| SEC05-BP04 | Automate network protection |
| SEC06-BP01 | Perform vulnerability management |
| SEC06-BP02 | Provision compute from hardened images |
| SEC06-BP03 | Reduce manual management and interactive access |
| SEC06-BP04 | Validate software integrity |
| SEC06-BP05 | Automate compute protection |
Security Foundations
| Code | Title |
|---|---|
| SEC01-BP01 | Separate workloads using accounts |
| SEC01-BP02 | Secure account root user and properties |
| SEC01-BP03 | Identify and validate control objectives |
| SEC01-BP04 | Stay up to date with security threats and recommendations |
| SEC01-BP05 | Reduce security management scope |
| SEC01-BP06 | Automate deployment of standard security controls |
| SEC01-BP07 | Identify threats and prioritize mitigations using a threat model |
| SEC01-BP08 | Evaluate and implement new security services and features regularly |
Your Compliance Coverage
If you comply with AWS Well-Architected Security Pillar, you already cover:
NIST SP 800-53 Rev 5
100%
63 controls mapped
Compare →Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
100%
63 controls mapped
Compare →ISO 27002:2022
100%
63 controls mapped
Compare →+ 25 more: ISO 27001:2022 (100%), NIST SP 800-171 Rev 3 (98%)
See all 28 mapped frameworks ↓Maps to 28 other frameworks
What is AWS Well-Architected Security Pillar and who does it apply to?
AWS Well-Architected Security Pillar is a compliance framework from International with 7 domains and 63 controls. Amazon Web Services security best practices framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does AWS Well-Architected Security Pillar actually require?
AWS Well-Architected Security Pillar has 63 controls organised across 7 domains. The largest domains are Identity & Access Management (15 controls), Data Protection (11 controls), Infrastructure Protection (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of AWS Well-Architected Security Pillar do I already cover?
AWS Well-Architected Security Pillar maps to 28 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (100% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), ISO 27002:2022 (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement AWS Well-Architected Security Pillar?
Start your AWS Well-Architected Security Pillar compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AWS Well-Architected Security Pillar requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 63 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required