SlideShare a Scribd company logo
By Crishantha Nanayakkara
AWS Security Hub
Source: AWS Blogs
Agenda
●
What is Security Hub?
●
The Need 
●
The Benefits 
●
How it works
●
Security Hub – Integrations
●
Security Hub – Compliance
●
Pricing
●
Demo
Re­Invent 2018 – Security Hub Launch
Andy Jassy, AWS CEO at Re-Invent 2018, Las Vegas
Reference: https://www.youtube.com/watch?v=a4l1UCo3YHE
The Competition
Azure Security Center Google Cloud Security Command Center
The Need
●
Security Compliance Issues – Which Security 
compliance is most suited?
●
So many security alert formats from different 
security products – Need to spend a lot of money to 
get them to a common format, which can be searched 
and analyzed
●
Too many security alerts from so many products and 
services
●
To have a single integrated view for all security 
alerts
AWS Security Hub provides you with a comprehensive 
view of your security state in your AWS environment and 
helps you check your compliance with the security 
industry standards and best practices.
What is Security Hub?
Security Hub collects security data from across AWS 
accounts, services, and supported third­party partner 
products and helps you analyze your security trends and 
identify the highest priority security issues.
The Benefits
●
Reduces the effort to collect and prioritize security 
findings across accounts from integrated AWS services 
and AWS partner products.
●
Automatically runs continuous, account level 
configuration and compliance checks based on 
industry standards such as CIS benchmarking. 
●
Consolidate your security findings across accounts on  
to a dashboard.
●
Supports integration with CloudWatch events, which 
lets you automate specific findings by defining custom 
actions and send them to a ticketing system.
AWS Security Hub
How it works
Security Hub aggregates, organizes and prioritizes your 
security alerts or findings from multiple AWS services such as 
Amazon GuardDuty, Amazon Inspector and Amazon Macie, 
as well as from AWS partner solutions (30+)
AWS Security Hub
●
AWS GuardDuty: A threat detection service that continuously 
monitors VPC flow logs, CloudTrail logs and DNS logs. It is an 
intelligent threat detection service coupled with Lambda 
functions to take actions.
●
AWS Inspector: A security assessment service, which is used 
to check for application exposures. 
●
AWS Macie: A security service that uses machine learning to 
automatically discover, classify, and protect sensitive data in 
AWS
Security Integrations ­ Services
Security Integrations ­ Partners
Extended the ecosystem to many security partner products
●
AWS Security Hub Findings from AWS Security Services and 
third party products are possessed by Security Hub using a 
standard finding format called AWS Security Finding Format 
(JSON type). 
●
This basically eliminates the need of any time­consuming data 
conversion efforts.
●
Then these findings are correlated via Security Hub by some 
prioritization   
●
Reference: 
https://docs.aws.amazon.com/securityhub/latest/userguide/se
curityhub­findings­format.html
 
AWS Security Finding Format
Security Hub ­ Compliance
Only one Compliance Guideline (43) – CIS Benchmark
How to get there?
CIS Benchmarks
(https://www.cisecurity.org/cis­benchmarks/)
Resource: https://www.cisecurity.org/cis-benchmarks/
CIS AWS Benchmark Report V1.20
The checklist has three 
main parts: 
 IAM, Logging, Monitoring
●
The initial Quick Start Guide was created by 
Accenture in collaboration with AWS.
●
Quick Start sets up the following:
– AWS Config Rules
– CloudWatch Alarms
– CloudWatch Events
– Lambda Functions
– AWS CloudTrail
CIS Quick Start Deployment
CIS Quick Start Deployment 
Architecture
CIS Quick Start Deployment
(The Prerequisites)
Requires AWS CloudTrail and AWS Config 
to be enabled in all AWS Regions
AWS Config
●
AWS Config provides a detailed view of the 
configurations of AWS resources in an AWS account. 
AWS CloudTrail
●
AWS Best Practice: Having the “trail” in a single 
region
CIS Quick Start Deployment
(The Steps)
●
Once login to the AWS console, select the region you 
want to run the compliance.
●
Move to “CloudFormation” on the console.
●
Select the CloudFormation Template from: 
The original version is in: 
https://github.com/aws­quickstart/quickstart­compliance­cis­bench
mark
CIS Quick Start Deployment
(The Steps)
●
If all go well, check Cloudwatch console for the 
events and Logs.
●
You could see a separate set of events, alarms, filters 
and lambda functions are installed on your setup. 
●
These will basically set up the CIS compliance for 
you!!
CIS Quick Start Deployment
(The Steps)
●
If all go well, check Cloudwatch console for the 
events and Logs.
●
You could see a separate set of events, alarms, filters 
and lambda functions are installed on your setup. 
●
These will basically set up the CIS compliance for 
you!!
References
●
CIS Quick Start Compliance Git (Original): 
https://github.com/aws­quickstart/quickstart­compliance­cis­benchmark
●
CIS Benchmark Template Git (Modified): 
https://github.com/cnanayakkara/cis­benchmark­template 
●
AWS Control Tower and Security Hub: 
https://aws.amazon.com/blogs/enterprise­strategy/aws­control­tower­and­a
ws­security­hub­powerful­enterprise­twins/
●
AWS Re­Inforce 2019: 
https://www.youtube.com/watch?v=HsWtPG_rTak&t=1034s 
●
AWS Security Hub – User Guide : 
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub.pd
f
●
AWS CIS Quick Start Reference Deployment: 
https://aws­quickstart.s3.amazonaws.com/quickstart­compliance­cis­benc
hmark/doc/cis­benchmark­on­the­aws­cloud.pdf
 
Thank YouThank You
Auxenta YouTube Channel: Auxenta YouTube Channel: Auxenta 360Auxenta 360
Auxenta VLOGS: Auxenta VLOGS: http://auxenta.com/vlog.phphttp://auxenta.com/vlog.php

More Related Content

PPTX
AWS core services
PPTX
AWS Monitoring & Logging
PDF
AWS Systems Manager
PDF
Amazon CloudWatch Tutorial | AWS Certification | Cloud Monitoring Tools | AWS...
PPTX
Aws config
PDF
AWS IAM -- Notes of 20130403 Doc Version
PDF
Amazon EC2 notes.pdf
PPTX
AWS Cloud trail
AWS core services
AWS Monitoring & Logging
AWS Systems Manager
Amazon CloudWatch Tutorial | AWS Certification | Cloud Monitoring Tools | AWS...
Aws config
AWS IAM -- Notes of 20130403 Doc Version
Amazon EC2 notes.pdf
AWS Cloud trail

What's hot (20)

PPTX
Securityhub
PDF
Azure fundamentals
PDF
Azure governance v4.0
PDF
Building an Enterprise-Grade Azure Governance Model
PPTX
AWS VPC & Networking basic concepts
PDF
AWS Control Tower
PDF
AWS Tutorial | AWS Certified Solutions Architect | Amazon AWS | AWS Training ...
PPTX
Azure Identity and access management
PDF
[Azure Governance] Lesson 4 : Azure Policy
PDF
TechnicalTerraformLandingZones121120229238.pdf
PDF
Azure Security Overview
PDF
Azure 101
PPTX
AWS Security Hub Deep Dive
PPTX
Microsoft Azure - Introduction
PDF
Azure Monitoring Overview
PPTX
CAF presentation 09 16-2020
PPTX
PPT Azure Firewall vs 3rd Party NVA Comparison v1.0.pptx
PPTX
PDF
Microsoft Azure Active Directory
PDF
Azure cloud migration simplified
Securityhub
Azure fundamentals
Azure governance v4.0
Building an Enterprise-Grade Azure Governance Model
AWS VPC & Networking basic concepts
AWS Control Tower
AWS Tutorial | AWS Certified Solutions Architect | Amazon AWS | AWS Training ...
Azure Identity and access management
[Azure Governance] Lesson 4 : Azure Policy
TechnicalTerraformLandingZones121120229238.pdf
Azure Security Overview
Azure 101
AWS Security Hub Deep Dive
Microsoft Azure - Introduction
Azure Monitoring Overview
CAF presentation 09 16-2020
PPT Azure Firewall vs 3rd Party NVA Comparison v1.0.pptx
Microsoft Azure Active Directory
Azure cloud migration simplified
Ad

Similar to AWS Security Hub (20)

PPTX
Unravelling Cloud Security Posture Management using AWS Security Hub
PDF
securityhub.pdf
PPTX
AWS User Group - Security & Compliance
PDF
1. aws security and compliance wwps pre-day sao paolo - markry
PPTX
AWS Landing Zone - Architecting Security and Governance.pptx
PDF
Security @ (Cloud) Scale Deep Dive
PDF
AWS Community Day 2022 Mahak Patil_Case Study_ Security Hub in FinTech
PPTX
CSS17: Atlanta - The AWS Shared Responsibility Model in Practice
PPTX
Blue Chip Tek Connect and Protect Presentation #3
PDF
The AWS Shared Responsibility Model in Practice
PDF
Oas un llamado a la accion para proteger a ciudadanos-Sector Privado y Gobi...
PDF
Oas un llamado a la accion
PDF
AWS Enterprise Summit - 클라우드에서의 보안 - 양승도
PPTX
Automating AWS security and compliance
PPTX
Evident.io corp overview
PDF
The AWS Shared Responsibility Model: Presented by Amazon Web Services
PDF
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
PDF
AWS - Security & Compliance
PDF
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
PPTX
How to prepare for & respond to security incidents in your AWS environment
Unravelling Cloud Security Posture Management using AWS Security Hub
securityhub.pdf
AWS User Group - Security & Compliance
1. aws security and compliance wwps pre-day sao paolo - markry
AWS Landing Zone - Architecting Security and Governance.pptx
Security @ (Cloud) Scale Deep Dive
AWS Community Day 2022 Mahak Patil_Case Study_ Security Hub in FinTech
CSS17: Atlanta - The AWS Shared Responsibility Model in Practice
Blue Chip Tek Connect and Protect Presentation #3
The AWS Shared Responsibility Model in Practice
Oas un llamado a la accion para proteger a ciudadanos-Sector Privado y Gobi...
Oas un llamado a la accion
AWS Enterprise Summit - 클라우드에서의 보안 - 양승도
Automating AWS security and compliance
Evident.io corp overview
The AWS Shared Responsibility Model: Presented by Amazon Web Services
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS - Security & Compliance
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
How to prepare for & respond to security incidents in your AWS environment
Ad

More from Crishantha Nanayakkara (20)

PDF
Sri Lanka Government Enterprise Architecture
PDF
Application Deployement Strategies
PDF
Azure for AWS Developers
PDF
Enterprise Integration in Cloud Native Microservices Architectures
PDF
AWS Big Data Landscape
PDF
1BT_Designing_Microservices
PDF
1BT_Tech_Talk_AWS_Cross_Account_Access
PDF
Resiilient Architectures on AWS
PDF
Reactive Microservices
PDF
Expectaions in IT industry
PDF
Towards Cloud Enabled Data Intensive Digital Transformation
PDF
Container Architecture
PDF
Domain Driven Design and Hexagonal Architecture
PDF
Microservices
PDF
Enterprise architecture in the current e-Government context in Sri Lanka
PDF
Modern Trends in IT
PDF
ICTA Meetup 12 - Message Brokers
PDF
ICTA Meetup 11 - Big Data
PDF
Lanka Gate Core Components - Government CIO Workshop Dec 2013
PDF
ICTA Technology Meetup 06 - Enterprise Application Design Patterns
Sri Lanka Government Enterprise Architecture
Application Deployement Strategies
Azure for AWS Developers
Enterprise Integration in Cloud Native Microservices Architectures
AWS Big Data Landscape
1BT_Designing_Microservices
1BT_Tech_Talk_AWS_Cross_Account_Access
Resiilient Architectures on AWS
Reactive Microservices
Expectaions in IT industry
Towards Cloud Enabled Data Intensive Digital Transformation
Container Architecture
Domain Driven Design and Hexagonal Architecture
Microservices
Enterprise architecture in the current e-Government context in Sri Lanka
Modern Trends in IT
ICTA Meetup 12 - Message Brokers
ICTA Meetup 11 - Big Data
Lanka Gate Core Components - Government CIO Workshop Dec 2013
ICTA Technology Meetup 06 - Enterprise Application Design Patterns

Recently uploaded (20)

PPTX
Strings in CPP - Strings in C++ are sequences of characters used to store and...
PPTX
Sustainable Sites - Green Building Construction
DOCX
ASol_English-Language-Literature-Set-1-27-02-2023-converted.docx
PPTX
UNIT-1 - COAL BASED THERMAL POWER PLANTS
PPTX
Lesson 3_Tessellation.pptx finite Mathematics
PPTX
bas. eng. economics group 4 presentation 1.pptx
PDF
PRIZ Academy - 9 Windows Thinking Where to Invest Today to Win Tomorrow.pdf
PDF
SM_6th-Sem__Cse_Internet-of-Things.pdf IOT
PDF
BMEC211 - INTRODUCTION TO MECHATRONICS-1.pdf
PDF
Digital Logic Computer Design lecture notes
PPTX
web development for engineering and engineering
PDF
keyrequirementskkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
PPTX
MCN 401 KTU-2019-PPE KITS-MODULE 2.pptx
PPTX
Recipes for Real Time Voice AI WebRTC, SLMs and Open Source Software.pptx
PPTX
Geodesy 1.pptx...............................................
PPTX
UNIT 4 Total Quality Management .pptx
PPTX
Lecture Notes Electrical Wiring System Components
PPTX
Welding lecture in detail for understanding
PPTX
CARTOGRAPHY AND GEOINFORMATION VISUALIZATION chapter1 NPTE (2).pptx
PPTX
Engineering Ethics, Safety and Environment [Autosaved] (1).pptx
Strings in CPP - Strings in C++ are sequences of characters used to store and...
Sustainable Sites - Green Building Construction
ASol_English-Language-Literature-Set-1-27-02-2023-converted.docx
UNIT-1 - COAL BASED THERMAL POWER PLANTS
Lesson 3_Tessellation.pptx finite Mathematics
bas. eng. economics group 4 presentation 1.pptx
PRIZ Academy - 9 Windows Thinking Where to Invest Today to Win Tomorrow.pdf
SM_6th-Sem__Cse_Internet-of-Things.pdf IOT
BMEC211 - INTRODUCTION TO MECHATRONICS-1.pdf
Digital Logic Computer Design lecture notes
web development for engineering and engineering
keyrequirementskkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
MCN 401 KTU-2019-PPE KITS-MODULE 2.pptx
Recipes for Real Time Voice AI WebRTC, SLMs and Open Source Software.pptx
Geodesy 1.pptx...............................................
UNIT 4 Total Quality Management .pptx
Lecture Notes Electrical Wiring System Components
Welding lecture in detail for understanding
CARTOGRAPHY AND GEOINFORMATION VISUALIZATION chapter1 NPTE (2).pptx
Engineering Ethics, Safety and Environment [Autosaved] (1).pptx

AWS Security Hub