Change | Description | Date |
|---|
Major updates | Added guidance around building architectures for multi-Region environments. Various AWS service updates: CloudWatch support for ingesting Security Hub CSPM findings, availability of IAM policy autopilot MCP server, AWS Managed Microsoft AD support for STIG-aligned configurations, AWS Secrets Manager support for hybrid post-quantum key exchange, and AWS Security Incident Response AI-powered investigative agent Updated AWS Audit Manager to note that service is not available to new customers Added CloudWatch Unified Data Store as the recommended primary option for centralized log collection and analytics across the organization. Amazon Security Lake is recommended as the secondary option. Removed all references to AWS CloudTrail Lake following service deprecation. Added new services to the checklist: AWS Security Hub, AWS Network Firewall, Route 53 Resolver DNS Firewall, AWS KMS, AWS Private CA, AWS IAM Identity Center, AWS Systems Manager, and AWS Secrets Manager. In the checklist, added new checks for existing services: AWS Security Hub CSPM, Amazon GuardDuty, and AWS Firewall Manager Updated the appendix with new AWS services
| June 30, 2026 |
Content restructure and updates | Added guidance for AWS Security Hub and AWS Nitro Enclaves. Restructured the AWS SRA to focus on the core architecture and moved the deep dive sections to separate guides for identity management, perimeter security, cyber forensics, generative AI, and IoT. Updated existing guidance to include additional details for AWS CloudTrail, AWS Config, Amazon Detective, AWS Firewall Manager, Amazon GuardDuty, IAM Access Analyzer, Amazon Security Lake, AWS Shield Advanced, and AWS Audit Manager.
| December 22, 2025 |
Major updates | Added information about new IAM centralized root user access management, resource control policies (RCPs), and declarative policies. Updated references to new Security Hub CSPM. Included new service features for Amazon GuardDuty and Security Hub CSPM. Added AWS Security Incident Response service guidance. Updated IAM deep dive guidance to include VPC Lattice for machine-to-machine identity management. Added a new deep dive guidance: SRA for IoT.
| August 29, 2025 |
Additions and clarifications | In the Security Tooling account section, updated the AWS KMS guidance. In the Customer identity management section, expanded the information about authorizing API Gateway. Updated the Generative AI section to add a design consideration for OU and account design. Removed explicit callout to prompt injection attack as the security controls referenced is more at infrastructure layer and not at application layer. In the Code repository section, added information about the new Patch Manager solution.
| September 12, 2024 |
Major updates | Added two sections for deep dive architectural guidance: Generative AI using Amazon Bedrock and Identity management. Updated the IAM Access Analyzer, Amazon Inspector, AWS WAF, AWS Config, Amazon Security Lake, and AWS Security Hub CSPM sections with new service features. Updated the AWS SRA code repository section to include the new Terraform deployment option and the addition of AWS Shield Advanced and AMI Bakery solutions.
| June 7, 2024 |
Major updates | Updated the Network account and Application account sections to add architectural guidance for Amazon Verified Permissions, AWS Verified Access, and Amazon VPC Lattice. Added deep dive architectural guidance based on security functionality. Added new guidance around how AWS services use AI/ML to provide better security outcomes. Added guidance on how plan your security architecture in a phased manner.
| November 4, 2023 |
Security Lake addition | Updated the Security Tooling account and Log Archive account sectionsto add design guidance related to Amazon Security Lake. | September 22, 2023 |
Minor updates | Updated existing guidance to reflect new AWS service features and best practices. Updated architectural guidance for AWS CloudTrail, AWS IAM Identity Center, and edge security.
| May 11, 2023 |
Survey | Added a short survey to gain a better understanding of how you use the AWS SRA in your organization. | December 14, 2022 |
Source files for reference architecture diagrams | Added a downloadable file that provides the architecture diagrams for this guide in editable PowerPoint format. | November 17, 2022 |
Updates to Security foundations section | Updated the information about Well-Architected pillars and security design principles. | September 27, 2022 |
Added new guidance, updated and clarified existing guidance
| Added information about how to use the AWS SRA and key implementation guidelines. Added architectural guidance for additional AWS services such as AWS Artifact, Amazon Inspector, AWS RAM, Amazon Route 53, AWS Control Tower, AWS Audit Manager, Directory Service, Amazon Cognito, and Network Access Analyzer. Updated existing guidance to reflect new AWS service features and best practices.
| July 25, 2022
|
Initial publication | — | June 23, 2021 |