View a markdown version of this page

Document history - AWS Prescriptive Guidance

Document history

The following table describes significant changes to this guide.

Change

Description

Date

Major updates

  • Added guidance around building architectures for multi-Region environments.

  • Various AWS service updates: CloudWatch support for ingesting Security Hub CSPM findings, availability of IAM policy autopilot MCP server, AWS Managed Microsoft AD support for STIG-aligned configurations, AWS Secrets Manager support for hybrid post-quantum key exchange, and AWS Security Incident Response AI-powered investigative agent

  • Updated AWS Audit Manager to note that service is not available to new customers

  • Added CloudWatch Unified Data Store as the recommended primary option for centralized log collection and analytics across the organization. Amazon Security Lake is recommended as the secondary option.

  • Removed all references to AWS CloudTrail Lake following service deprecation.

  • Added new services to the checklist: AWS Security Hub, AWS Network Firewall, Route 53 Resolver DNS Firewall, AWS KMS, AWS Private CA, AWS IAM Identity Center, AWS Systems Manager, and AWS Secrets Manager.

  • In the checklist, added new checks for existing services: AWS Security Hub CSPM, Amazon GuardDuty, and AWS Firewall Manager

  • Updated the appendix with new AWS services

June 30, 2026

Content restructure and updates

December 22, 2025

Major updates

  • Added information about new IAM centralized root user access management, resource control policies (RCPs), and declarative policies.

  • Updated references to new Security Hub CSPM.

  • Included new service features for Amazon GuardDuty and Security Hub CSPM.

  • Added AWS Security Incident Response service guidance.

  • Updated IAM deep dive guidance to include VPC Lattice for machine-to-machine identity management.

  • Added a new deep dive guidance: SRA for IoT.

August 29, 2025

Additions and clarifications

  • In the Security Tooling account section, updated the AWS KMS guidance.

  • In the Customer identity management section, expanded the information about authorizing API Gateway.

  • Updated the Generative AI section to add a design consideration for OU and account design. Removed explicit callout to prompt injection attack as the security controls referenced is more at infrastructure layer and not at application layer.

  • In the Code repository section, added information about the new Patch Manager solution.

September 12, 2024

Major updates

  • Added two sections for deep dive architectural guidance: Generative AI using Amazon Bedrock and Identity management.

  • Updated the IAM Access Analyzer, Amazon Inspector, AWS WAF, AWS Config, Amazon Security Lake, and AWS Security Hub CSPM sections with new service features.

  • Updated the AWS SRA code repository section to include the new Terraform deployment option and the addition of AWS Shield Advanced and AMI Bakery solutions.

June 7, 2024

Major updates

  • Updated the Network account and Application account sections to add architectural guidance for Amazon Verified Permissions, AWS Verified Access, and Amazon VPC Lattice.

  • Added deep dive architectural guidance based on security functionality.

  • Added new guidance around how AWS services use AI/ML to provide better security outcomes.

  • Added guidance on how plan your security architecture in a phased manner.

November 4, 2023

Security Lake addition

Updated the Security Tooling account and Log Archive account sectionsto add design guidance related to Amazon Security Lake.

September 22, 2023

Minor updates

  • Updated existing guidance to reflect new AWS service features and best practices.

  • Updated architectural guidance for AWS CloudTrail, AWS IAM Identity Center, and edge security.

May 11, 2023

Survey

Added a short survey to gain a better understanding of how you use the AWS SRA in your organization.

December 14, 2022

Source files for reference architecture diagrams

Added a downloadable file that provides the architecture diagrams for this guide in editable PowerPoint format.

November 17, 2022

Updates to Security foundations section

Updated the information about Well-Architected pillars and security design principles.

September 27, 2022

Added new guidance, updated and clarified existing guidance

  • Added information about how to use the AWS SRA and key implementation guidelines.

  • Added architectural guidance for additional AWS services such as AWS Artifact, Amazon Inspector, AWS RAM, Amazon Route 53, AWS Control Tower, AWS Audit Manager, Directory Service, Amazon Cognito, and Network Access Analyzer.

  • Updated existing guidance to reflect new AWS service features and best practices.

July 25, 2022

Initial publication

June 23, 2021