Back to Frameworks

AWS Well-Architected Security Pillar

International
v2024
7 domains
63 controls

Amazon Web Services security best practices framework

Verified

AWS Well-Architected Security Pillar is a compliance framework from International with 7 domains and 63 controls that map to 28 other frameworks. The largest domains are Identity & Access Management (15 controls), Data Protection (11 controls), Infrastructure Protection (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit docs.aws.amazon.com

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Application Security

8 controls
Controls in the Application Security domain of AWS Well-Architected Security Pillar8 controls
CodeTitle
SEC11-BP01Train for application security
SEC11-BP02Automate testing throughout the development and release lifecycle
SEC11-BP03Perform regular penetration testing
SEC11-BP04Conduct code reviews
SEC11-BP05Centralize services for packages and dependencies
SEC11-BP06Deploy software programmatically
SEC11-BP07Regularly assess security properties of the pipelines
SEC11-BP08Build a program that embeds security ownership in workload teams

Data Protection

11 controls
Controls in the Data Protection domain of AWS Well-Architected Security Pillar11 controls
CodeTitle
SEC07-BP01Understand your data classification scheme
SEC07-BP02Apply data protection controls based on data sensitivity
SEC07-BP03Automate identification and classification
SEC07-BP04Define scalable data lifecycle management
SEC08-BP01Implement secure key management
SEC08-BP02Enforce encryption at rest
SEC08-BP03Automate data at rest protection
SEC08-BP04Enforce access control
SEC09-BP01Implement secure key and certificate management
SEC09-BP02Enforce encryption in transit
SEC09-BP03Authenticate network communications

Detection

4 controls
Controls in the Detection domain of AWS Well-Architected Security Pillar4 controls
CodeTitle
SEC04-BP01Configure service and application logging
SEC04-BP02Capture logs, findings, and metrics in standardized locations
SEC04-BP03Correlate and enrich security alerts
SEC04-BP04Initiate remediation for non-compliant resources

Identity & Access Management

15 controls
Controls in the Identity & Access Management domain of AWS Well-Architected Security Pillar15 controls
CodeTitle
SEC02-BP01Use strong sign-in mechanisms
SEC02-BP02Use temporary credentials
SEC02-BP03Store and use secrets securely
SEC02-BP04Rely on a centralized identity provider
SEC02-BP05Audit and rotate credentials periodically
SEC02-BP06Employ user groups and attributes
SEC03-BP01Define access requirements
SEC03-BP02Grant least privilege access
SEC03-BP03Establish emergency access process
SEC03-BP04Reduce permissions continuously
SEC03-BP05Define permission guardrails for your organization
SEC03-BP06Manage access based on lifecycle
SEC03-BP07Analyze public and cross-account access
SEC03-BP08Share resources securely within your organization
SEC03-BP09Share resources securely with a third party

Incident Response

8 controls
Controls in the Incident Response domain of AWS Well-Architected Security Pillar8 controls
CodeTitle
SEC10-BP01Identify key personnel and external resources
SEC10-BP02Develop incident management plans
SEC10-BP03Prepare forensic capabilities
SEC10-BP04Develop and test security incident response playbooks
SEC10-BP05Pre-provision access
SEC10-BP06Pre-deploy tools
SEC10-BP07Run simulations
SEC10-BP08Establish a framework for learning from incidents

Infrastructure Protection

9 controls
Controls in the Infrastructure Protection domain of AWS Well-Architected Security Pillar9 controls
CodeTitle
SEC05-BP01Create network layers
SEC05-BP02Control traffic flow within your network layers
SEC05-BP03Implement inspection-based protection
SEC05-BP04Automate network protection
SEC06-BP01Perform vulnerability management
SEC06-BP02Provision compute from hardened images
SEC06-BP03Reduce manual management and interactive access
SEC06-BP04Validate software integrity
SEC06-BP05Automate compute protection

Security Foundations

8 controls
Controls in the Security Foundations domain of AWS Well-Architected Security Pillar8 controls
CodeTitle
SEC01-BP01Separate workloads using accounts
SEC01-BP02Secure account root user and properties
SEC01-BP03Identify and validate control objectives
SEC01-BP04Stay up to date with security threats and recommendations
SEC01-BP05Reduce security management scope
SEC01-BP06Automate deployment of standard security controls
SEC01-BP07Identify threats and prioritize mitigations using a threat model
SEC01-BP08Evaluate and implement new security services and features regularly

Your Compliance Coverage

If you comply with AWS Well-Architected Security Pillar, you already cover:

Maps to 28 other frameworks

63 total controls
NIST SP 800-53 Rev 5
63 source controls mapped|95 target controls covered
100%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
63 source controls mapped|102 target controls covered
100%
ISO 27002:2022
63 source controls mapped|57 target controls covered
100%
ISO 27001:2022
63 source controls mapped|61 target controls covered
100%
NIST SP 800-171 Rev 3
62 source controls mapped|70 target controls covered
98%
FedRAMP High
62 source controls mapped|154 target controls covered
98%
FedRAMP Moderate
62 source controls mapped|155 target controls covered
98%
NIST Cybersecurity Framework 2.0
62 source controls mapped|67 target controls covered
98%
Azure Security Benchmark
61 source controls mapped|71 target controls covered
97%
NIST SP 800-161 Rev 1
60 source controls mapped|98 target controls covered
95%
CMMC 2.0
59 source controls mapped|77 target controls covered
94%
PCI DSS 4.0
59 source controls mapped|116 target controls covered
94%
NIST SP 800-53 Revision 5.1 HIGH
58 source controls mapped|111 target controls covered
92%
SOC 2
58 source controls mapped|31 target controls covered
92%
NIST SP 800-53 Rev 5 MODERATE
57 source controls mapped|107 target controls covered
90%
CIS Controls v8
56 source controls mapped|94 target controls covered
89%
C5 (Germany)
52 source controls mapped|69 target controls covered
83%
HIPAA Security Rule
52 source controls mapped|37 target controls covered
83%
NIST SP 800-66 Rev 2
51 source controls mapped|35 target controls covered
81%
NIST SP 800-53 Rev 5 LOW
47 source controls mapped|58 target controls covered
75%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
41 source controls mapped|32 target controls covered
65%
ISO 27701:2019
31 source controls mapped|34 target controls covered
49%
Australia Consumer Data Right - Banking (CDR)
24 source controls mapped|12 target controls covered
38%
NIST SP 800-218
21 source controls mapped|31 target controls covered
33%
ACSC Essential Eight
21 source controls mapped|14 target controls covered
33%
UK Cyber Essentials
19 source controls mapped|25 target controls covered
30%
ASD Strategies to Mitigate Cyber Security Incidents
18 source controls mapped|23 target controls covered
29%
ISO/IEC 42001:2023
5 source controls mapped|5 target controls covered
8%

What is AWS Well-Architected Security Pillar and who does it apply to?

AWS Well-Architected Security Pillar is a compliance framework from International with 7 domains and 63 controls. Amazon Web Services security best practices framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does AWS Well-Architected Security Pillar actually require?

AWS Well-Architected Security Pillar has 63 controls organised across 7 domains. The largest domains are Identity & Access Management (15 controls), Data Protection (11 controls), Infrastructure Protection (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of AWS Well-Architected Security Pillar do I already cover?

AWS Well-Architected Security Pillar maps to 28 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (100% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), ISO 27002:2022 (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement AWS Well-Architected Security Pillar?

Start your AWS Well-Architected Security Pillar compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AWS Well-Architected Security Pillar requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 63 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required