01 /Identity & account security
Review IAM, least privilege, root-account protection, MFA, access keys, and permission boundaries where appropriate.
02 /Network architecture
Assess VPC design, public access, security groups, and separation between workloads and management paths.
03 /Logging & detection
Review CloudTrail, AWS Config, GuardDuty, and Security Hub coverage, with attention to retention, routing, and accountable response.
04 /Storage & encryption
Review S3 exposure, resource policies, KMS key access, encryption settings, and the paths through which sensitive data moves.
05 /Backup & recovery
Examine recovery objectives, backup access, retention, and restore evidence. A configured backup is only part of a recovery plan.
06 /Architecture review
Use AWS Well-Architected security concepts to examine how controls work together. Document tradeoffs and prioritize changes for your environment.