Instiq
Chapter 5 · Security and the Shared Responsibility Model·v2.1.0·Updated 6/14/2026·~12 min

What's changed: In-scope coverage: added a security/identity in-scope services block to Ch5 (IAM Identity Center/Cognito/Directory Service/Certificate Manager/CloudHSM/Firewall Manager/Detective/Audit Manager)

5.2Security and Compliance Services

Key points

Organize key AWS security services by purpose (detect/audit, protect, protect data, identity) and understand AWS Artifact for compliance information.

AWS has many security services, and memorizing names alone gets confusing. The trick is to group them by purpose into five buckets—detect/audit, protect, protect data, identity, compliance. With this map, you can place any new service name into the right bucket.

Diagram grouping AWS security services by purpose: detect/audit (CloudTrail/Config/GuardDuty), protect (WAF/Shield), protect data (KMS/Secrets Manager), identity (IAM), and compliance (AWS Artifact).
AWS security/compliance services by purpose

5.2.1Detect and audit

  • CloudTrail: records an audit log of API activity (who did what, and when).
  • AWS Config: records resource configuration and evaluates compliance with rules (tracks config changes).
  • Amazon GuardDuty: analyzes logs to detect threats automatically. Also in "detect": Security Hub (aggregates findings), Amazon Inspector (vulnerability scanning), Amazon Macie (sensitive-data discovery in S3, etc.).

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.