ITSec in AWS

Amazon Web Services (AWS) is the most seasoned cloud service offering the widest portfolio in the market. The organic development of the wide offerings of the services has been pushing forward the continuous and integrated development of IT security along the de facto standards and best practices. 

Strict requirements

As AWS has got several multinational clients, national and local governments and their suppliers, the services provided should be compliant with various local, national and regional regulations, especially in the field of personal data protection.

Shared responsibility

The shared responsibility model defined in T&Cs by AWS (see the figure) defines the boundary between the Security OF the Cloud, as well as the Security IN the Cloud, the i.e. the responsibility of the service provider, and the users/clients, respectively.

Integrated IAM system

AWS Identity and Access Management (IAM) is an integral part of the AWS management console, where users, groups, roles, temporary access and users with root access, all are well-known roles from operating systems, are managed. Elements that can be defined from the console

  • Users
  • Groups
  • Roles
  • TEMP accesses
  • Root user management

AWS IAM is a proprietary environment having simulation and testing tool for policy development in JSON. Once it is tested and validated, it can be deployed by another AWS service throughout all AWS ECS2 instances.

Integrated logging systems

AWS CloudTrail, a logging, analysis, audit and forensic tool, is logging the AWS API calls. The entries, namely the API caller, time of the call, the IP address of the caller, parameters of the call and the response of the sevice, are logged for every event. These API calls in the AWS Management Console, can be arrived from AWS SDK, command line and higher level AWS services (e.g. .AWS CloudFormation).


  • AWS ISM Letter of Compliance
  • AWS ASD Letter of Certification
  • AWS ISO9001:2008 Certification
  • AWS ISO27001:2013 Certification
  • AWS ISO27017:2015Certification
  • AWS ISO27018:2014 Certification
  • Multi-Tier Cloud Security Standard Level-3 (CSP) Certification, AWS SOC 3 Report

Benefits of AWS based ITSec

The consistent and continuous development the standardized IT security infrastructure provides a clear set of requirements for IT professionals. That has been allowing AWS to develop standardized development programs for AWS experts with formal examinations and to define professional levels.

This framework is a considerable mitigation of operational and sourcing risks comparing to proprietary environments resulting in cost savings.


It is expertise the most important criteria to develop cloud based IT. The AWS is a uniquely efficient solution, we can help you to benefit from.
We design, deliver and operate.