
Amazon Macie + Detective on AWS: Data Security Posture Management and Forensic Investigation in Production
Macie + Detective: S3 DSPM and forensic graphs. July 2026 — scope costs, KMS decrypt, paired Security Hub pipeline.
Tagged

Macie + Detective: S3 DSPM and forensic graphs. July 2026 — scope costs, KMS decrypt, paired Security Hub pipeline.

Network Firewall + Firewall Manager for Org-wide L3–L7. July 2026: centralized inspection, Suricata, TLS bypass, rollout checklist.

RDS performance: gp3 IOPS, Performance Insights / Database Insights, Proxy, replicas, ElastiCache. July 2026 tuning checklist.

Hardening quick wins: private DMS, OpenSearch encryption, SageMaker VPC-only, Lambda runtime EOL. July 2026 checklist.

Verified Access ZTNA: Cedar policies, Identity Center, TCP endpoints (GA). July 2026 Client VPN migration checklist.

DORA on AWS since Jan 2025: RoI, TLPT/TIBER-EU, incident clocks, Artifact addendum. July 2026 readiness checklist.

EU AI Act compliance on AWS — risk classification, prohibited practices, GPAI obligations, the high-risk Annex III framework (enforceable 2 August 2026), and the AWS-native control mapping using Bedrock Guardrails, SageMaker Model Cards, and Audit Manager governance.

How to build a vulnerability management program that scales beyond CVE-counting. Inspector v2 deployment, CVSS + CISA KEV + reachability for risk-based prioritization, container and IaC scanning in CI/CD, and remediation SLAs that survive audits.

GDPR compliance on AWS for SaaS companies handling EU resident data. Region selection, the AWS DPA, data subject rights automation, RoPA documentation, breach notification, and the technical controls regulators expect.

ISO 27001:2022 on AWS: ISMS scope, 93 Annex A mapping, Stage 1/2 evidence. July 2026 stage checklist.

NIS2 on AWS: Essential/Important scope, Art. 21 measures, 24h/72h clocks, supply chain. July 2026 checklist.

NIST CSF 2.0 on AWS: Govern + six functions, tiers, 800-53/171/CMMC. July 2026 Tier-3 checklist.