SEC01-BP08 Evaluate and implement new security services and features regularly
Evaluate and implement security services and features from AWS and AWS Partners that help you evolve the security posture of your workload.
Desired outcome: You have a standard practice in place that informs you of new features and services released by AWS and AWS Partners. You evaluate how these new capabilities influence the design of current and new controls for your environments and workloads.
Common anti-patterns:
-
You don't subscribe to AWS blogs and RSS feeds to learn of relevant new features and services quickly
-
You rely on news and updates about security services and features from second-hand sources
-
You don't encourage AWS users in your organization to stay informed on the latest updates
Benefits of establishing this best practice: When you stay on top of new security services and features, you can make informed decisions about the implementation of controls in your cloud environments and workloads. These sources help raise awareness of the evolving security landscape and how AWS services can be used to protect against new and emerging threats.
Level of risk exposed if this best practice is not established: Low
Implementation guidance
AWS informs customers of new security services and features through several channels:
You can subscribe to an
AWS Daily Feature Updates
New services and features are also announced and described in
detail during
conferences,
events, and webinars
You can also ask your
AWS account team
Implementation steps
-
Subscribe to the various blogs and bulletins with your favorite RSS reader or to the Daily Features Updates SNS topic.
-
Evaluate which AWS events to attend to learn first-hand about new features and services.
-
Set up meetings with your AWS account team for any questions about updating security services and features.
-
Consider subscribing to Enterprise Support to have regular consultations with a Technical Account Manager (TAM).
Resources
Related best practices: