Skip to main content

AWS Network Security Manager

AWS Network Security Manager FAQs

General

Open all

    AWS Network Security Manager is a security management service that allows you to centrally configure and manage security policies across your accounts and applications in AWS Organizations. As new applications are created, Network Security Manager makes it easy to bring new applications and resources into compliance by enforcing a common set of security policies. You have a single service to build policies, create security standards, and enforce them in a consistent, hierarchical manner across your entire organization or individual accounts.. As new applications are created, Network Security Manager makes it easy to bring new applications and resources into compliance by enforcing a common set of security policies. You have a single service to build policies, create security standards, and enforce them in a consistent, hierarchical manner across your entire organization.    

    Network Security Manager is integrated with AWS Organizations so you can enable security protections across multiple AWS accounts and resources from a single place. Network Security Manager monitors for new resources or accounts created to ensure they comply with a mandatory set of security policies from day one. You can group rules, templates, build policies, and centrally apply those policies across your entire infrastructure. For example, you can delegate the creation of application-specific rules within an account while retaining the ability to enforce global security policies across accounts.

    Using Network Security Manager, you can centrally configure AWS WAF rules and AWS Shield Advanced protections across accounts and resources in your organization.    

    Using Network Security Manager, you can easily roll out AWS WAF rules across Application Load Balancers, API Gateways, and Amazon CloudFront distributions. You can create AWS Shield Advanced protections for your Application Load Balancers, ELB Classic Load Balancers, Elastic IP Addresses, and CloudFront distributions.

    Please visit the AWS Region Table to see the current region availability for AWS Network Security Manager.

Enabling AWS Network Security Manager

Open all

    There are no prerequisites if you are using an individual account.
    AWS Organizations: If your accounts are a part of AWS Organizations then it must have enabled all features. You need to enable trusted access, and set up an Administrator account. See AWS Organizations documentation for more details.

    See the documentation guide for more information.

    Once you have completed the prerequisites, you will define NSM rules, you can then optionally organize the rules into templates, and then organize templates and or rules into a policy. Rules and templates can be reused across policies. When rule or template objects are organized, they are ordered to determine operational priority. The next step would be the definition of a scope. Scopes define what within your AWS footprint will be protected. You can determine asset types, Organizational constructs, and networks. Your scope definitions determine what assets will have firewalls automatically created or updated with whatever policies you apply. The application of policies to scopes is called a deployment and it  is the final step. Here a single or multiple policies will be applied to the target scope, and it is a this stage that the process of orchestration is initiated to ensure that the assets you want protected are secured with the policies you desire..

    Yes, you can configure a Network Security Manager policy in two modes. Automatic remediation allows you to automatically monitor for drift in policy and apply rules on out of synch resources. Manual remediation deploys the desired policy with the associated rules and protections in each account. After the policy is created, you can choose to take manual action for each local account.

    Each Network Security Manager policy can be scoped to have at most 50,000 accounts, which is the default limit for number of accounts in AWS Organizations.

    There is no limit on the number of resources managed by Network Security Manager at this time.

    No, Network Security Manager security policies are region specific. Each policy can only include resources available in that specified AWS Region. You can create a new policy for each region where you operate.

    Yes. You can exclude accounts. You can also use tags to specify the resources that should be excluded from the policy scope.

Dashboard and Visibility

Open all

    In dynamic environments with active participants, it can be challenging to ensure that the desired security policy remains intact. Loosely managed Infrastructure-as-Code actions or unaware development or management teams may inadvertently alter the security policy such that it is no longer synchronized with the desired standard. This puts your security at risk or potentially your security state out of compliance. With Network Security Manager, changes to the policy are detected, and remediated automatically to ensure that your standards are kept aligned with the policies deployed.

    For each Network Security Manager policy created, you can aggregate CloudWatch metrics for each native firewall rule in the rule group within that firewall’s CloudWatch space, indicating how many requests were allowed or blocked across the entire organization. This gives you a central place to set up alerts for threats across your organization.