Using AWS Config to record, audit, and evaluate changes to AWS resources to enable traceability is an example of which AWS Well-Architected Framework pillar?
From the Security section of https://d1.awsstatic.com/whitepapers/architecture/AWS_Well-Architected_Framework.pdf " • Enable traceability: Monitor, alert, and audit actions and changes to your environment in real time. Integrate log and metric collection with systems to automatically
investigate and take action."
Performance Efficiency vs. Security:
While Performance Efficiency focuses on optimizing cloud resources for performance, Security involves safeguarding data, systems, and applications by continuously monitoring and auditing for vulnerabilities, misconfigurations, and other risks.
AWS Config and Its Relationship with Security:
AWS Config helps you record and track the configuration of AWS resources, and it also evaluates changes to ensure compliance with security and operational best practices.
The primary goal is to audit changes to resources, ensuring that your environment remains secure and compliant with established policies.
Using AWS Config to record, audit, and evaluate changes to AWS resources to enable traceability aligns with the "Operational Excellence" pillar of the AWS Well-Architected Framework.
The Operational Excellence pillar focuses on the ability to run and monitor systems to deliver business value, and continually improve processes and procedures. AWS Config helps in achieving this by providing a detailed record of configuration changes to AWS resources, enabling auditability, compliance, and governance. It allows organizations to maintain a complete inventory of their AWS resources and track changes over time, facilitating operational excellence through enhanced visibility and control.
Both the Security and Operational Excellence pillars of the AWS Well-Architected Framework can have relevance to the use of AWS Config, depending on the specific context.
Security Pillar: AWS Config is valuable for ensuring resources are compliant with security best practices and policies. It assists in detecting drifts from the baseline and can help spot potential security vulnerabilities. From the perspective of maintaining a security posture and ensuring compliance, AWS Config aligns with the Security pillar.
Operational Excellence Pillar: AWS Config also plays a role in the continuous monitoring and refinement of operations. Knowing the state of resources, understanding changes, and being able to trace these changes over time can support operational best practices. If the primary goal is to provide traceability, monitor changes, and ensure that the operations are running according to defined standards, then AWS Config can indeed be associated with the Operational Excellence pillar.
search for AWS Config to find out its usage. https://docs.aws.amazon.com/pdfs/wellarchitected/latest/operational-excellence-pillar/wellarchitected-operational-excellence-pillar.pdf
Its A, Changed mind
https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/security.html
Maintain traceability: Monitor, alert, and audit actions and changes to your environment in real time. Integrate log and metric collection with systems to automatically investigate and take action.
Using AWS Config to record, audit, and evaluate changes to AWS resources aligns with the Security pillar of the AWS Well-Architected Framework. The Security pillar focuses on protecting information, systems, and assets while maintaining data confidentiality, integrity, and availability.
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources over time. It records changes to resource configurations and provides a detailed view of how the configurations are aligned with best practices and desired configurations. By using AWS Config, you can track and maintain traceability of changes to your resources, helping to enforce security controls, detect unauthorized changes, and ensure compliance with security requirements.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
JohnO1971
Highly Voted 3 years, 6 months agoPSL95
Highly Voted 3 years, 7 months agoHebaXX
Most Recent 1 month agosonaljain
3 months, 4 weeks agoAKSH_SURANI
1 year, 1 month agoManikRoy
1 year, 3 months agosukjubae
1 year, 3 months agoHOYIITPUCO
1 year, 6 months agoOripresa
1 year, 7 months agoMable777
1 year, 7 months agotushmish
1 year, 7 months agotushmish
1 year, 7 months agojekum
1 year, 8 months agoGulsah
1 year, 9 months agoman5484
1 year, 9 months agokhanda
1 year, 9 months agoESAJRR
1 year, 10 months agoWarsame21
1 year, 10 months agoRon_Mistah
1 year, 8 months ago