21% of AWS Well-Architected Security Pillar you already have
Protective Security Policy Framework (PSPF) Release 2024 already covers about 21% of AWS Well-Architected Security Pillar, leaving
70 of 89 controls as genuinely new work.
Already covered 3
Likely covered 16
New work 70
What is genuinely new work
Nothing in Protective Security Policy Framework (PSPF) Release 2024 reaches these. This is the list to scope.
AWS-WA-09Federation and single sign-on
AWS-WA-10API security and access tokens
AWS-WA-13Data residency and sovereignty
AWS-WA-17Container and serverless security
AWS-WA-18Cloud workload protection
AWS-WA-25Service level agreement management
SEC01-BP01Separate workloads using accounts
SEC01-BP02Secure account root user and properties
SEC01-BP03Identify and validate control objectives
SEC01-BP04Stay up to date with security threats and recommendations
SEC01-BP06Automate testing and validation of security controls
SEC01-BP07Identify threats and prioritize mitigations using a threat model
SEC02-BP01Use strong sign-in mechanisms
SEC02-BP02Use temporary credentials
SEC02-BP03Store and use secrets securely
SEC02-BP04Rely on a centralized identity provider
SEC02-BP05Audit and rotate credentials periodically
SEC02-BP06Employ user groups and attributes
SEC03-BP01Define access requirements
SEC03-BP02Grant least privilege access
SEC03-BP03Establish emergency access process
SEC03-BP04Reduce permissions continuously
SEC03-BP05Define permission guardrails for your organization
SEC03-BP06Manage access based on lifecycle
SEC03-BP07Analyze public and cross-account access
SEC03-BP08Share resources securely within your organization
SEC03-BP09Share resources securely with a third party
SEC04-BP01Configure service and application logging
SEC04-BP02Capture logs, findings, and metrics in standardized locations
SEC04-BP03Correlate and enrich security alerts
SEC04-BP04Initiate remediation for non-compliant resources
SEC04-BP05Implement actionable security events
SEC05-BP01Create network layers
SEC05-BP02Control traffic at all layers
SEC05-BP03Implement inspection-based protection
SEC05-BP04Automate network protection
SEC06-BP01Perform vulnerability management
SEC06-BP02Reduce attack surface
SEC06-BP03Implement managed services
SEC06-BP04Automate compute protection
SEC06-BP05Enable people to perform actions at a distance
SEC06-BP06Validate software integrity
SEC07-BP01Identify the data within your workload
SEC07-BP02Define data protection controls
SEC07-BP03Automate identification and classification
SEC07-BP04Define data lifecycle management
SEC08-BP01Implement secure key management
SEC08-BP02Enforce encryption at rest
SEC08-BP03Automate data at rest protection
SEC08-BP04Enforce access control
SEC09-BP01Implement secure key and certificate management
SEC09-BP02Enforce encryption in transit
SEC09-BP03Automate detection of unintended data access
SEC09-BP04Authenticate network communications
SEC10-BP01Identify key personnel and external resources
SEC10-BP02Develop incident management plans
SEC10-BP03Prepare forensic capabilities
SEC10-BP04Automate containment capability
SEC10-BP05Identify forensic and incident response tools
SEC10-BP06Pre-deploy tools
SEC10-BP07Run simulations
SEC10-BP08Establish a framework for learning from incidents
SEC11-BP01Train for application security
SEC11-BP02Automate testing throughout the development and release lifecycle
SEC11-BP03Perform regular penetration testing
SEC11-BP04Conduct code reviews
SEC11-BP05Centralize services for packages and dependencies
SEC11-BP06Deploy software programmatically
SEC11-BP07Regularly assess security properties of the pipelines
SEC11-BP08Build a program that embeds security ownership in workload teams
Show the 19 you already have
AWS-WA-01Shared responsibility model definition
AWS-WA-11Data classification for cloud
AWS-WA-22Incident response in cloud
AWS-WA-02Cloud security policy and strategy
AWS-WA-03Cloud risk assessment
AWS-WA-04Regulatory compliance for cloud services
AWS-WA-05Cloud security roles and responsibilities
AWS-WA-06Cloud identity management
AWS-WA-07Multi-factor authentication for cloud
AWS-WA-08Privileged access in cloud environments
AWS-WA-12Encryption of cloud-stored data
AWS-WA-14Data backup and recovery in cloud
AWS-WA-15Secure data deletion in cloud
AWS-WA-16Virtual network segmentation
AWS-WA-19Image and template hardening
AWS-WA-20Cloud configuration management
AWS-WA-21Cloud security monitoring and logging
AWS-WA-23Cloud vulnerability management
AWS-WA-24Cloud change management
How this is calculated
Already covered means a mapping runs from a control in Protective Security Policy Framework (PSPF) Release 2024 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition