AWS Services and Features for Securing AI Systems
Why it matters
The story: A clinic's filing room holds patients' names, bank details, and medical histories. If it's broken into, the clinic faces lawsuits and fines, not just embarrassment.
In AI/AWS terms: AI systems often process sensitive data such as personal, financial, and proprietary information, so a breach has legal and financial consequences.
For the exam: AI systems often handle sensitive data, so a breach has legal and financial consequences.
Shared responsibility model
The story: Renting an apartment. The landlord is responsible for the building: the foundations, the walls, the main door, the wiring. You're responsible for what happens inside your flat: who you give keys to, locking your own door, and keeping your valuables safe. If you rent a fully serviced apartment, the landlord handles more (cleaning, furniture), and you handle less.
In AI/AWS terms: Start security planning here.
- AWS: security of the cloud (the building). Physical facilities, hardware, the host operating system, and the virtualization layer.
- Customer: security in the cloud (your flat). Customer data, applications, IAM, guest operating system, network and firewall configuration, client-side and server-side encryption, and network traffic protection.
Your share depends on which services you use: more managed services means less for you to handle (the serviced apartment).
For the exam: AWS = security of the cloud. Customer = security in the cloud, including data, IAM, and encryption settings.
Four foundational security services
The story: Four basics every building needs: a locksmith who makes and manages keys, a control room showing every alarm on one screen with ready-made response plans, a guard who spots suspicious behavior, and a crowd-control team that keeps mobs from blocking the entrance.
In AI/AWS terms:
| Building role | Service | Security domain | Purpose |
|---|---|---|---|
| Locksmith | AWS KMS | Data protection | Encryption with AWS managed or customer managed keys |
| Control room | AWS Security Hub | Incident response | One dashboard of security findings, with automated playbooks |
| Guard | Amazon GuardDuty | Threat detection | Detects suspicious activity and unauthorized behavior |
| Crowd control | AWS Shield Advanced | Network and application protection | Managed DDoS protection |
For the exam: Encryption keys = KMS. One dashboard of findings = Security Hub. Suspicious activity = GuardDuty. DDoS = Shield Advanced.
Services by job
The story: More specialists around the building:
- A clerk who goes through the filing cabinets before anything is shared, flagging pages with personal or medical details.
- The badge office: who gets a badge, which doors it opens, and an auditor who checks nobody has more access than they need.
- Doors that check your identity every single time, instead of trusting you because you're already inside.
- Ready-made badge types for common jobs in the lab.
- Private corridors and a gate that inspects every package leaving, plus a private tunnel to a partner building so nothing goes through the public street.
- Guards, inspectors, and a detective who investigates after an incident.
- An office that automates incident reports and compliance paperwork.
- A front-door screener who blocks known troublemakers and bots.
In AI/AWS terms:
| Job | Services |
|---|---|
| Find sensitive data before training | Amazon Macie: ML-based discovery of PII, PHI, and financial data in S3 |
| Manage identities and access | AWS IAM (users, groups, roles, policies), IAM Identity Center, IAM Access Analyzer for least privilege |
| Zero trust access | AWS Verified Access (no VPN needed), Amazon Verified Permissions |
| ML-specific roles | SageMaker Role Manager: preconfigured personas for data scientist, MLOps, and SageMaker compute |
| Stop data exfiltration | Amazon VPC, AWS Network Firewall (deep packet inspection), AWS PrivateLink (private connection from your VPC to Amazon Bedrock without the internet) |
| Detect threats | GuardDuty, Inspector (vulnerabilities), Amazon Detective (forensic investigation) |
| Automate incident response and compliance | Security Hub, Config, Audit Manager, Artifact |
| Protect web apps | AWS WAF (web exploits, bots, account takeover), Shield Advanced, Firewall Manager |
For the exam: Finding PII in S3 = Macie. Reaching Bedrock without the public internet = PrivateLink. Least privilege = IAM Access Analyzer. Investigating after an incident = Detective.