AWS Startup Security Baseline
The AWS Startup Security Baseline (SSB) is a set of controls that create a minimum foundation for businesses to build securely on AWS without decreasing their agility. These controls form the basis of your security posture and are focused on securing credentials, enabling logging and visibility, managing contact information, and implementing basic data boundaries.
The controls in this guide are designed with early startups in mind, mitigating the most common security risks without requiring significant effort. Many startups begin their journey in the AWS Cloud with a single AWS account. As organizations grow, they migrate to multi-account architectures. The guidance in this guide is designed for single-account architectures, but it helps you set up security controls that are easily migrated or modified as you transition to a multi-account architecture.
The controls in the AWS SSB are separated into two categories: account and workload. Account controls help keep your AWS account secure. It includes recommendations for setting up user access, policies, and permissions, and it includes recommendations for how to monitor your account for unauthorized or potentially malicious activity. Workload controls help secure your resources and code in the cloud, such as applications, backend processes, and data. It includes recommendations such as encryption and reducing the scope of access. You can find guides/information on this workshop: https://catalog.workshops.aws/startup-security-baseline/en-US to learn more about it
Read more
The controls in this guide are designed with early startups in mind, mitigating the most common security risks without requiring significant effort. Many startups begin their journey in the AWS Cloud with a single AWS account. As organizations grow, they migrate to multi-account architectures. The guidance in this guide is designed for single-account architectures, but it helps you set up security controls that are easily migrated or modified as you transition to a multi-account architecture.
The controls in the AWS SSB are separated into two categories: account and workload. Account controls help keep your AWS account secure. It includes recommendations for setting up user access, policies, and permissions, and it includes recommendations for how to monitor your account for unauthorized or potentially malicious activity. Workload controls help secure your resources and code in the cloud, such as applications, backend processes, and data. It includes recommendations such as encryption and reducing the scope of access. You can find guides/information on this workshop: https://catalog.workshops.aws/startup-security-baseline/en-US to learn more about it
Read more
Summary: [Not available:15] | [Compliant:7] | [Need Attention:5]
Breakdown
Framework. AWS Startup Security Baseline
Category | Rule ID | Compliance Status | Description | Reference |
---|---|---|---|---|
Account | ACCT.01 | Compliant |
| |
Account | ACCT.02 | Compliant |
| |
Account | ACCT.03 | Compliant |
| |
Account | ACCT.04 | Need Attention |
| AWS Docs AWS Docs AWS Docs Organization GuardRail Blog |
Account | ACCT.05 | Need Attention |
| AWS MFA IAM Best Practices |
Account | ACCT.06 | Need Attention |
| IAM Password Policy |
Account | ACCT.07 | Not available | ||
Account | ACCT.08 | Compliant |
| |
Account | ACCT.09 | Not available | ||
Account | ACCT.10 | Compliant |
| |
Account | ACCT.11 | Compliant |
| |
Account | ACCT.12 | Not available | ||
Workloads | WKLD.01 | Compliant |
| |
Workloads | WKLD.02 | Not available | ||
Workloads | WKLD.03 | Not available | ||
Workloads | WKLD.04 | Not available | ||
Workloads | WKLD.05 | Not available | ||
Workloads | WKLD.06 | Not available | ||
Workloads | WKLD.07 | Not available | ||
Workloads | WKLD.08 | Need Attention |
| Best practices for Amazon EC2 |
Workloads | WKLD.09 | Not available | ||
Workloads | WKLD.10 | Not available | ||
Workloads | WKLD.11 | Need Attention |
| Best practices for Amazon EC2 ALB Configuration Guide |
Workloads | WKLD.12 | Not available | ||
Workloads | WKLD.13 | Not available | ||
Workloads | WKLD.14 | Not available | ||
Workloads | WKLD.15 | Not available |