Listing Thumbnail

    Security control assessment and refinement

     Info
    Security assessment and refinement on AWS architecture

    Overview

    AWS Services Control Policies (SCP)

    • Review the control policy based on the services that currently used
    • Refine and document the policy
    • Develop JSONs for all SCPs

    AWS Organizations

    • Review existing enabled services
    • Enable backup policy and plan for enforced across estate

    StackSets in master account

    • Review the StackSets functionality and the deployment consistency status
    • Update and refine the policy for cloudformation StackSet
    • Broken services review and fix
    • Potentially issues review and fix

    GuardDuty

    • Configure Guardduty runs on central delegate master account
    • Setup notifications and emails
    • Setup process and policies to manage remediation

    AWS Config

    • Review and apply the agreed config conformance packs
    • Review SecurityHub recommendations and impelment the fix
    • Review and update the Cloudformation

    SecurityHub

    • Create scripts to disable certain checks if there are false positives and automate the auto-fix process
    • Review and enable SecurityHub out of the box integrations which adds values to the overall security position and security governance monitoring

    CloudWatch Eventbus notifications and Dashboard

    • Review and update the configurations
    • Review master account visibility of security alerts and posture

    Application Monitoring (Per Ventures)

    • Automate EC2 and app availability monitoring
    • Review data visualization
    • Review Synthetic monitoring

    Governance and Compliance Check

    • Setup notification when violation occurs, e.g. security control by OSPAR

    Highlights

    • Security Control Recommendations - Improvement recommendations for: - AWS Services Control Policies (SCP) - AWS Organizations - StackSets in Master Account - AWS Config Conformance Packs - SecurityHub - EC2 and app monitoring guideline for each ventures
    • Documentation - Changes introduced to the existing implementations - Operations and Incident Management - CloudWatch Eventbus Notifications and Dashboard
    • Technical configurations/automation - Automation scripts - Configuration fixes enhancements to: - SCP + Master CloudFormation StackSets - SecurityHub - GuardDuty

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Sales enquiry : Email : sales@hkmci.com  Phone : +852 3589 6700

    Support enquiry : support@hkmci.com  Support portal :

    Software associated with this service