Issue #133

Monday · December 04, 2023

🥖 Palate Cleanser

Hey Folks,

Hope you're doing well! I've had my nose buried in all sorts of articles, blog posts, and updates in the AWS Security universe so that you can skip the heavy lifting.

Here's a roundup of the juiciest stuff you need to know this week. First up, let's get into an eye-opening piece on Security Hub by Chris Faris. Trust me, you'll want to hear the key takeaways:
  • Misleading Metrics & Dashboards: Security Hub may present metrics and dashboards that don't accurately reflect the security posture. They often lean towards compliance rather than assessing real risks, causing both misalignment and tension between engineering and security teams.

  • Cost Underestimation: While Security Hub might seem cost-effective initially, the total cost can escalate when combined with AWS Config and other associated services. The pricing structure can be confusing, causing budgeting issues.

  • Configuration Challenges: Despite features like Delegated Admin and Region Aggregation, disabling specific controls or customizing findings is far from straightforward. You'll need to dive into each account and region, making configuration and management cumbersome.

See the full article below.

Victor

📋 Chef's selections

  1. [Video] The Rising Threat of S3 Ransomware: Mastering Detection and Investigation
  2. AWS Security Monitoring in 2023: Untangle the chaos
  3. Security Hub gives me imposter syndrome

🍛 Reddit threads on r/aws

🍪 API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.