Skip to main content

Domain title*

AWS Network Security Manager

AWS Network Security Manager features

General

Open all

    Network Security Manager is integrated with AWS Organizations and will automatically fetch the list of accounts in your AWS organization to enable you to group resources across accounts. You build protection policies that define a group of resources and associate the group with your policy. Then you specify the scope of the policy to cover a specific set of AWS accounts, or all of your organization's accounts. Network Security Manager deploys the protections only on the resources in the accounts based on the scopes which you defined.

    AWS environments provide significant operational flexibility, which may result in security policy drift. You need to know when deployed configurations no longer match what you defined. Network Security Manager displays the synchronization state of the policies on the firewall relative to the Network Security Manager policy.

    Policy changes at scale often rely on brittle undocumented scripts and the hope that nothing is broken in the process. Network Security Manager allows you to create protection policies in a hierarchical manner, where sub-policy objects can cascade automatically or rollback, throughout their associations from rule, to template, to policy, to deployment. Security teams maintain simple policy objects without having to ensure that equivalent controls are propagated untouched across dozens of policies. They can change things once, and those updates automatically roll up to all policies where they are included.

    Managing security across a large organization means grouping resources in ways that match how your teams work. Within Network Security Manager, you can group resources by Organization, Account, Resource Type, and by Tag. Your security team can create policies for all resources within a particular group or across accounts in the organization.

    When your organization grows to dozens or hundreds of accounts, keeping security protections consistent can be challenging. Network Security Manager addresses this challenge at scale. You can automatically enforce policies on AWS resources that currently exist or as they are created, aligning your security standards across the organization. Network Security Manager gives you the ability to apply AWS WAF rules, including Managed Rules for AWS WAF, on Application Load Balancers, API Gateways, and Amazon CloudFront distributions. 

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages