
6 steps that all customers have to do to improve security in Cloud
A hands-on walkthrough of six practical steps to harden an AWS account, from enabling MFA on the root user and swapping access keys for IAM roles to locking down security groups, automating patches with Systems Manager, and blocking public S3 access. Ideal for anyone setting up a secure baseline.
Steps:
- Protect privileged credentials
- Use temporary credentials
- Replace hardcoded credentials
- Limit Network Access
- Apply patches
- Restrict public storage
Prerequisite:
An
AWS account that you are able to use for your use case.Step 1: Protect privileged credentials:
In this step, we will use AWS IAM in the AWS Management Console to configure and enable a virtual MFA (Multi-Factor Authentication) device for the root account. To manage MFA devices for the AWS account, you must be signed in to AWS using your root credentials. You can not manage MFA devices for the root user using other credentials.
For more information, please follow the following docs: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html
Step 2: Use Temporary Credentials:
In this step, we will use AWS IAM roles to avoid the usage of AWS IAM access keys that may be required by the Amazon Elastic Compute Cloud (EC2) instance to access AWS resources. We will create a Role and assign it to the EC2 instance, instead of hard coding the access keys within the EC2 instance.
For more information please follow the following docs: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html
Step 3: Replace Hardcoded Credentials:
In this step, we will use AWS Secrets Manager to easily manage and retrieve credentials i.e., username/passwords, API Keys, and other secrets through their Lifecycle.
For more information please follow the following docs: https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html
Step 4: Limit Network Access
In this step, we will use AWS Trusted Advisor's basic security checks to identify remote access risks associated with the EC2 instance and fix them. Furthermore, we will use AWS Systems Manager's feature to secure our remote access.
It involves removing a rule that allows open access to ports from the internet in the inbound rules of a security group. Once the issue is fixed, the instructions demonstrate how to access the EC2 instance securely using AWS System's Manager capability called Session Manager. The instructions involve changing account settings to use an advanced instance tier and starting a session to access the instance through a Microsoft Windows command prompt or Linux terminal window. The session can be exited using the relevant OS command or by clicking Terminate.
For more information please follow the following docs: https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
Step 5: Apply patches:
In this step, we will perform automated vulnerability scanning and patching using
AWS Systems Manager Patch Manager, a capability of AWS Systems Manager, that automates the process of patching managed nodes with both security-related updates and other types of updates. It can apply patches for both operating systems and applications.- From the AWS console, click Services and select AWS Systems Manager.
- Click on Quick Setup on the menu on the left side of the console.
- Make sure that the correct region is selected on the top right corner of the console. Click on Get Started.
- On the Quick Setup page click on Create.
- On the 'Choose a configuration type' page, select Host Management settings and click Next.
- On the 'Customize Host Management configuration options' page leave the default values as is and click on Create.
- Notification will appear on the screen once the host management setup is completed successfully (may take up to 5 minutes).
- On the menu, on the left side, scroll down and click on Compliance under Node Management.
- On the 'Compliance resources summary' page the non-compliance status against Patch will be visible if the systems manager detects missing patches within the EC2 instance. Click on the number showing against the missing patches.
- For patching the Operating System, click on Patch Manager under Node Management.
- Click on Patch now on the upper right side.
- On the 'Patch instances now' page select Scan and Install. Leave the remaining options as is, scroll down, and click Patch now.
- On the 'Association execution summary' page the Status of the operation will become a success after a few minutes.
- Now go back to the 'Compliance' section under Node Management on the left side menu.
- On the 'Compliance resources summary' section, the Patch Compliance type will now show as Compliant.
- Click on the Instance ID shown under the resource, which will take you to the Fleet Manager console. Click on the Patch tab, which will show that no more updates are required.
For more information please follow the following docs: https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager.html https://docs.aws.amazon.com/inspector/latest/userguide/inspector_introduction.html
Step 6: Restrict Public Storage:
In this step, we will configure S3 Block Public Access, an easy way to prevent public access to your S3 bucket.
- From the AWS console, click Services and select S3.
- Click the bucket name that you want to block public access.
- Click on the Permissions tab.
- Click Edit under the section 'Block public access (bucket settings)'.
- Select Block all public access to prevent all sorts of public access to your bucket.
- Click on Save Changes.
- Confirm the settings by typing confirm in the field of the confirmation dialogue box and clicking on Confirm.
- The buckets and objects will now have no public access as shown in the permission overview.
- You can also configure the policy to block public access to all the existing and newly created buckets in the account by clicking on the S3 menu bar on the left side of the S3 management console.
- Click on Block Public Access setting for this account.
- Click on Block all public Access on the right side of the S3 management console.
- Click on Save Changes.
- Confirm the settings by typing confirm in the field of the confirmation dialogue box and clicking on Confirm.
- Click on Buckets and note that all of the buckets in your account no longer have public access.
For more information please follow the following docs: https://docs.aws.amazon.com/AmazonS3/latest/userguide/security.html
Conclusion:
This is a good starting point for a guide to improving cloud security. However, it is important to note that these steps may not be sufficient to fully secure a cloud environment, and additional measures may be required based on specific use cases and compliance requirements. It is also critical to review and updates security measures on a regular basis in order to stay ahead of potential threats.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article