Lesson 07 — Enterprise Security Assessment
Learning Path
☁️ Phase 2 – AWS Cloud Security
📘 Module 01 – AWS Security Foundations
🎯 Lesson Objective
Section titled “🎯 Lesson Objective”By the end of this lesson, you will be able to:
- Perform an enterprise AWS security assessment.
- Identify common AWS security risks.
- Prioritise security findings.
- Recommend remediation actions.
- Think like a Cloud Security Engineer.
- Prepare a professional security assessment report.
📚 Lesson Information
Estimated Time: 3 Hours
Difficulty: Beginner
Prerequisites: Lessons 01–06
Hands-on Lab: Yes
Assignment: Yes
💼 Business Value
Section titled “💼 Business Value”Every organisation performs periodic security assessments.
These assessments help answer questions such as:
- Are our AWS accounts secure?
- Are we following best practices?
- Are there any security gaps?
- Are we compliant?
- What should be fixed first?
Cloud Security Engineers perform these reviews before:
- Production deployments
- Compliance audits
- Cloud migrations
- Customer onboarding
- Penetration tests
🏢 In the Company
Section titled “🏢 In the Company”CloudNova Technologies has completed its AWS onboarding.
Before the development teams begin deploying production workloads, the CISO has requested a complete security review.
You have been assigned as the Cloud Security Engineer responsible for approving the AWS environment.
Your task is to determine whether the environment is ready for production.
📋 Security Assessment Scope
Section titled “📋 Security Assessment Scope”During today’s assessment you will review:
- AWS Account Security
- IAM
- MFA
- Root User
- CloudTrail
- Password Policy
- Billing Alerts
- Security Groups
- Encryption
- Regions
- AWS CLI Configuration
🛡 Security Assessment Methodology
Section titled “🛡 Security Assessment Methodology”Every assessment follows the same process.
Information Gathering │ ▼Configuration Review │ ▼Risk Identification │ ▼Risk Prioritisation │ ▼Recommendations │ ▼Final Report🚨 Risk Rating
Section titled “🚨 Risk Rating”Use the following priorities.
| Severity | Description |
|---|---|
| Critical | Immediate business impact |
| High | Serious security weakness |
| Medium | Should be remediated soon |
| Low | Improvement recommendation |
| Informational | No immediate action required |
🧪 Enterprise Mission 01 — Verify Your AWS Identity
Section titled “🧪 Enterprise Mission 01 — Verify Your AWS Identity”Run
aws sts get-caller-identityRecord:
- Account ID
- IAM User
- ARN
Question
Am I using the Root User?
Yes or No?
🧪 Enterprise Mission 02 — Review IAM Summary
Section titled “🧪 Enterprise Mission 02 — Review IAM Summary”Run
aws iam get-account-summaryRecord
- Users
- Roles
- Groups
- MFA Devices
- Policies
Assessment Questions
- Too many users?
- MFA enabled?
- Administrator users?
- Unused identities?
🧪 Enterprise Mission 03 — Review Password Policy
Section titled “🧪 Enterprise Mission 03 — Review Password Policy”aws iam get-account-password-policyReview
-
Minimum Length
-
Complexity
-
Symbols
-
Numbers
-
Password Reuse
Document recommendations.
🧪 Enterprise Mission 04 — Review CloudTrail
Section titled “🧪 Enterprise Mission 04 — Review CloudTrail”aws cloudtrail describe-trailsQuestions
-
CloudTrail enabled?
-
Multi-Region?
-
Logging Management Events?
-
S3 Bucket Configured?
🧪 Enterprise Mission 05 — Review Security Groups
Section titled “🧪 Enterprise Mission 05 — Review Security Groups”aws ec2 describe-security-groupsReview
-
SSH Open
-
RDP Open
-
Any
0.0.0.0/0Rules
Questions
-
Which Security Groups are risky?
-
Which ports should be removed?
🧪 Enterprise Mission 06 — Review S3 Buckets
Section titled “🧪 Enterprise Mission 06 — Review S3 Buckets”List buckets
aws s3api list-bucketsCheck Public Access
aws s3api get-public-access-block \--bucket YOUR_BUCKET_NAMECheck Encryption
aws s3api get-bucket-encryption \--bucket YOUR_BUCKET_NAMEQuestions
-
Public?
-
Encrypted?
-
Versioning?
🧪 Enterprise Mission 07 — Review EC2 Instances
Section titled “🧪 Enterprise Mission 07 — Review EC2 Instances”aws ec2 describe-instancesReview
-
Running
-
Stopped
-
Public IP
-
Security Groups
Questions
-
Are instances exposed?
-
Should they be in private subnets?
🧪 Enterprise Mission 08 — Review IAM Users
Section titled “🧪 Enterprise Mission 08 — Review IAM Users”aws iam list-usersQuestions
-
Old Users?
-
Unused Users?
-
Administrator Accounts?
-
MFA Enabled?
🧪 Enterprise Mission 09 — Review AWS Regions
Section titled “🧪 Enterprise Mission 09 — Review AWS Regions”aws ec2 describe-regionsQuestions
-
Approved Regions?
-
Disaster Recovery Region?
-
Any unexpected Regions?
🧪 Enterprise Mission 10 — Build Findings Register
Section titled “🧪 Enterprise Mission 10 — Build Findings Register”Document findings.
| Finding | Severity | Recommendation |
|---|---|---|
| Root Account Used | Critical | Use IAM User |
| No MFA | Critical | Enable MFA |
| CloudTrail Disabled | High | Enable CloudTrail |
| Public SSH | High | Restrict Access |
| Weak Password Policy | Medium | Improve Policy |
| Unencrypted Storage | High | Enable KMS |
🏢 Enterprise Scenario
Section titled “🏢 Enterprise Scenario”CloudNova Technologies wants to launch its first production workload.
The CISO asks:
“Would you approve this AWS account for production?”
Prepare your response.
Include:
-
Security strengths
-
Security weaknesses
-
Risks
-
Recommendations
-
Final approval
Would you:
✅ Approve
OR
❌ Reject
Explain why.
🧪 Enterprise Challenge
Section titled “🧪 Enterprise Challenge”Imagine you have just joined a consulting company.
Your client asks:
“Can you assess our AWS environment in one day?”
Prepare your assessment approach.
Include:
-
Information Gathering
-
Identity Review
-
Logging
-
Monitoring
-
Encryption
-
Networking
-
Compliance
-
Final Report
📊 Knowledge Check
Section titled “📊 Knowledge Check”-
Why do organisations perform security assessments?
-
What information does
aws sts get-caller-identityprovide?
-
Why should CloudTrail always be enabled?
-
Why should Security Groups be reviewed regularly?
-
What are Critical findings?
-
Why review password policies?
-
Why review IAM Users?
-
Why review S3 Bucket permissions?
-
Why document findings?
-
What should every assessment include?
📝 Assignment
Section titled “📝 Assignment”Create a professional AWS Security Assessment Report.
Include
-
Executive Summary
-
Scope
-
Assessment Methodology
-
Findings
-
Severity
-
Recommendations
-
Final Approval Decision
-
Lessons Learned
Include screenshots of your AWS Console and CLI output where appropriate.
Length
5–8 Pages
✅ Lesson Completion Checklist
Section titled “✅ Lesson Completion Checklist”| Task | Status |
|---|---|
| AWS Identity Reviewed | ☐ |
| IAM Reviewed | ☐ |
| Password Policy Reviewed | ☐ |
| CloudTrail Reviewed | ☐ |
| Security Groups Reviewed | ☐ |
| S3 Reviewed | ☐ |
| EC2 Reviewed | ☐ |
| Regions Reviewed | ☐ |
| Findings Register Completed | ☐ |
| Assessment Report Created | ☐ |
💡 Key Takeaways
Section titled “💡 Key Takeaways”After completing this lesson, you should be able to:
- Perform an enterprise AWS security assessment.
- Identify security risks using both the AWS Console and AWS CLI.
- Prioritise findings based on business impact.
- Recommend practical remediation steps.
- Produce a professional security assessment report suitable for technical and management audiences.
This lesson marks your transition from learning AWS concepts to applying them in a realistic enterprise review.
📚 Further Reading
Section titled “📚 Further Reading”- AWS Well-Architected Framework – Security Pillar
- AWS Security Best Practices
- AWS IAM Best Practices
- AWS CloudTrail User Guide
- AWS Config Documentation
🚀 Next Lesson
Section titled “🚀 Next Lesson”➡️ Lesson 08 — Enterprise Security Baseline Project