Scan with Phone

Scan to instantly open and share this page on your mobile device.

Link copied to clipboard!

Group 11: Security & Identity

Authentication, authorization, and data protection services: IAM, Cognito, Secrets Manager, KMS, GuardDuty.

Security Principle: Implement defense-in-depth with least privilege access, encryption at rest/transit, and continuous monitoring for comprehensive threat protection.

Services & Roles

IAM

Identity and access management for AWS resources with fine-grained permissions.
  • Policies & roles
  • Multi-factor auth
  • Cross-account access

Cognito

User identity and authentication for web/mobile applications.
  • User pools
  • Identity pools
  • Social identity providers

Secrets Manager

Centralized secrets storage with automatic rotation and fine-grained access.
  • Automatic rotation
  • Cross-region replication
  • Fine-grained access

KMS

Managed encryption key service with hardware security modules (HSMs).
  • Customer managed keys
  • Envelope encryption
  • CloudTrail integration

GuardDuty

Intelligent threat detection using machine learning and behavioral analysis.
  • ML threat detection
  • Behavioral analysis
  • Integrated threat intel

Key Differences

DimensionIAMCognitoSecrets ManagerKMSGuardDuty
ScopeAWS resourcesApplication usersSecrets storageEncryption keysThreat detection
AuthenticationAWS identitiesEnd usersProgrammatic accessKey accessMonitoring only
Use CaseAWS access controlUser managementPassword/API keysData encryptionSecurity monitoring
IntegrationAll AWS servicesWeb/mobile appsApplicationsStorage/databasesSecurity services
Cost ModelFreeMAU pricingSecrets + API callsKey usageEvents analyzed

Selection Model

0–10 sliders weight security requirements, identity management needs, and threat protection priorities.

{{c.desc}}
Score_IAM = 0.30*C_awsResourceAccess + 0.26*C_roleBasedAccess + 0.18*C_crossAccountAccess + 0.12*C_policyManagement + 0.08*C_serviceIntegration + 0.06*C_auditTrail Score_Cognito = 0.32*C_userAuthentication + 0.28*C_mobileWebApps + 0.18*C_socialProviders + 0.12*C_userDirectory + 0.06*C_federatedIdentity + 0.04*(10 - C_awsResourceAccess) Score_SecretsManager= 0.30*C_secretsManagement + 0.26*C_automaticRotation + 0.18*C_applicationCredentials + 0.12*C_crossRegionSecrets + 0.08*C_finegrainedAccess + 0.06*C_integrationEase Score_KMS = 0.32*C_encryptionRequirements + 0.24*C_keyManagement + 0.18*C_envelopeEncryption + 0.12*C_complianceRequirements + 0.08*C_cloudTrailIntegration + 0.06*C_hsmsecurity Score_GuardDuty = 0.34*C_threatDetection + 0.26*C_behavioralAnalysis + 0.18*C_securityMonitoring + 0.12*C_mlThreatIntel + 0.06*C_incidentResponse + 0.04*C_continuousMonitoring
IAM {{vm.scores.iam|number:2}}
Cognito {{vm.scores.cognito|number:2}}
Secrets Manager {{vm.scores.secretsmanager|number:2}}
KMS {{vm.scores.kms|number:2}}
GuardDuty {{vm.scores.guardduty|number:2}}
Primary Emphasis: {{vm.recommended.name}} ({{vm.recommended.score|number:2}})

Heuristics

  • High C_awsResourceAccess + C_roleBasedAccess → IAM for AWS permissions.
  • Strong C_userAuthentication + C_mobileWebApps → Cognito for app users.
  • High C_secretsManagement + C_automaticRotation → Secrets Manager for credentials.
  • C_encryptionRequirements + C_keyManagement → KMS for data protection.
  • C_threatDetection + C_behavioralAnalysis → GuardDuty for security monitoring.

Anti-Patterns

  • Using IAM for end-user authentication (use Cognito instead).
  • Hardcoding secrets in applications (use Secrets Manager).
  • Managing encryption keys manually (use KMS).
  • Ignoring security monitoring (enable GuardDuty).

Summary

Choose IAM for AWS access, Cognito for users, Secrets Manager for credentials, KMS for encryption, GuardDuty for threat detection.

Next: Application Integration provides messaging and workflow orchestration capabilities.

next