Main areas covered
| Layer | Components | Description |
|---|---|---|
| Web tier | ALB, CloudFront, WAF | Require HTTPS and TLS 1.2 or later, associate a WAF, and primarily allow HTTP/HTTPS traffic |
| Application tier | EC2, Lambda, IAM | Use least-privilege IAM roles, limit security groups to internal communication, and use IMDSv2 for instance metadata |
| Database tier | RDS, ElastiCache | Block public access, encrypt data at rest, and restrict security groups to the application tier |
| Networking | VPC, subnets | Separate public and private subnets, configure route tables and NACLs, and restrict default VPC use |
| Logging | CloudTrail, VPC Flow Logs | Use multi-Region trails and enable flow logs |
| Encryption | EBS, S3, RDS | Use EBS encryption by default, S3 server-side encryption, and RDS encryption at rest |