Unlike legacy and most on-prem IT infrastructure, AWS cloud was build with security in mind. AWS is responsible for the security “of” the cloud including hardware, hypervisors, and networks. Customers are still responsible for the security of their data and applications “in” the cloud.
To help customers, AWS offers numerous cloud native security tools. This diagram, which I derived from the latest AWS Online Summit on May 13, 2020, depicts AWS services that customers can use when implementing the five NIST cybersecurity framework – Identify, Protect, Detect, Respond, and Recover – to secure their data and applications in the cloud.