AWS Network Security Manager
Define network security policies once and enforce them across accounts and resources.
Benefits of Network Security Manager
Define policies once and enforce them automatically across in-scope accounts and resources, including new resources as they are created. Network Security Manager monitors for configuration drift and restores your defined baseline automatically, so your intended security posture and your actual deployment stay aligned.
Use hierarchical policies that layer from organization-wide baselines down to application-specific rules, and scope them precisely by account, OU, resource type, tags, or resource attributes using AND/OR/NOT logic. Network Security Manager resolves applicable layers into a unified configuration for each resource, so your security model follows your organizational structure.
Keep changes in draft state until you are ready to deploy, validate before publishing, and roll back to a previous version in one click. Every published version is immutable and auditable. Describe your requirements in natural language and let Network Security Manager generate the rules, so you can respond to new threats in minutes instead of days.
Use cases for Network Security Manager
Deploy AWS WAF rules, Shield Advanced protections, and logging configurations to internet-facing resources across production accounts. Policies apply automatically to new resources as they are created.
Central security sets the non-negotiable baseline. Application teams add rules for their own workloads within those guardrails. Neither team waits on the other, and Network Security Manager merges both sets of rules into one consistent configuration per resource.
When a new advisory is published, add the corresponding rule to the relevant policy, publish it, and Network Security Manager deploys the update across your organization in minutes.