Module 9
IAM Groups

Example: Making groups reflect job roles

Challenges with scaling RBAC

Attribute Based Access Control
ABAC
Benefits
Federating Users

Example: Identity federation for AWS Management Console access

Example: Identity federation for AWS Management Console using SAML

Federation example

Cognito Example

Two ways for separating resource access
SCP's


AWS Control Tower
Data at rest encryption
Client-side encryption (CSE)
Server-side encryption (SSE)
Client-side example

Server-side example

AWS Security tools

Using AWS Security Hub with AWS Trusted Advisor
Last updated