Behavior Driven Chaos with AWS Fault Injection Simulator

TutoSartup excerpt from this article:
In this post, we will explore a working example of how you can build chaos experiments using human readable language, AWS Fault Injection Simulator (FIS), and a framework familiar to Developers and Test Engineers... Chaos experiment attributes For a chaos experiment to be considered complete, the experiment should exhibit the following attributes: Defined steady state Hypothesis Define...

Data masking and granular access control using Amazon Macie and AWS Lake Formation

TutoSartup excerpt from this article:
Prerequisites To implement the proposed solution, you must have an active AWS account and AWS Identity and Access Management (IAM) permissions to use the following services: Amazon Athena AWS CloudFormation AWS Database Migration Service (AWS DMS) Amazon Elastic Compute Cloud (Amazon EC2) AWS Glue Amazon EventBridge IAM AWS Key Management Service (AWS KMS) Amazon Kinesis Dat...

Architect defense-in-depth security for generative AI applications using the OWASP Top 10 for LLMs

TutoSartup excerpt from this article:
Examples of applications include conversational search, customer support agent assistance, customer support analytics, self-service virtual assistants, chatbots, rich media generation, content moderation, coding companions to accelerate secure, high-performance software development, deeper insights from multimodal content sources, acceleration of your organization’s security investigations and ...

Export a Software Bill of Materials using Amazon Inspector

TutoSartup excerpt from this article:
Amazon Inspector has expanded capability that allows customers to export a consolidated Software Bill of Materials (SBOM) for supported Amazon Inspector monitored resources, excluding Windows EC2 instances... This blog post includes steps that you can follow to export a consolidated SBOM for the resources monitored by Amazon Inspector across your organization in industry standard formats, includ...

How three IT experts built AWS skills to tap into the power of generative AI

TutoSartup excerpt from this article:
At Baker Tilly I am encouraged to learn and pursue AWS Certifications... That’s where I learned about all the different AWS services, as well as the pillars of the AWS Well-Architected Framework,” he says... Like many who never received formal cloud training in university programs, she did much of her learning on the job, augmented by whatever other knowledge she could pick up online... In 20...

AWS re:Invent 2023: Security, identity, and compliance recap

TutoSartup excerpt from this article:
Key announcements To help you more efficiently manage identity and access at scale, we introduced several new features: A week before re:Invent, we announced two new features of Amazon Verified Permissions: Batch authorization — Batch authorization is a new way for you to process authorization decisions within your application... You can set up automated notification workflows by ...

2023 PiTuKri ISAE 3000 Type II attestation report available with 171 services in scope

TutoSartup excerpt from this article:
The scope of the report covers a total of 171 services and 29 global AWS Regions... The Finnish Transport and Communications Agency (Traficom) Cyber Security Centre published PiTuKri, which consists of 52 criteria that provide guidance when assessing the security of cloud service providers... The criteria are organized into the following 11 subdivisions: Framework conditions Security manag...