Company context
In this section, you evaluate your current control or solution to make sure that it meets your organization's business and technical requirements. If you don't have a control or solution in place, you should evaluate the AWS security service and skip directly to the AWS security service evaluation section.
1.1 Is a compliance, security, or privacy mandate not attended?
Organizations are under the scope of laws and regulations regarding data security and privacy. Any violations of these mandates can result in severe consequences. If your company is unable to meet a compliance, security, or privacy requirement, you should evaluate the AWS security service.
1.2 Do you have a high risk that is not addressed?
Organizations need to identify and manage significant security risks in their environment. A high risk could involve potential data breaches, system vulnerabilities, operational disruptions, or other critical security concerns. If your current solution (or absence of it) is not adequately mitigating these high risks, proceed with evaluating the AWS security service.
1.3 Do you have a manual or error-prone solution?
Solutions that require manual steps or human interaction are more error prone. Inconsistency, low data reliability, noncompliant assets, and lack of scalability are common in these scenarios. Automated controls are fundamentally important for IT systems and workloads. If your current solution does not support full automation, consider evaluating the AWS security service.
1.4 Do you face management, agility, or scalability issues?
It is important to map any problem related to management. The following are some examples: Lack of compatibility managing different assets, the solution does not cover all devices, errors and disruptions during updates, and negative performance impact in production. The solution must offer agility so that teams can innovate from a strong security posture. You must support scalability to achieve exponential business growth. If you have any management, availability, or scaling issues, you should evaluate the AWS security service.
1.5 Do you have a high total cost of ownership?
Evaluate the total cost of ownership (TCO) for your current security solution by comparing costs against industry benchmarks and internal metrics. Generally, organizations invest 6-14% of their IT budget in cybersecurity, and 10% is the average. Consider factors such as licensing, implementation, maintenance, support, and operational costs for protecting your assets. You can include your internal tools that cover the same number of assets to be protected. An unbalanced security budget for tools can also indicate a high TCO, such as if 60% of the budget is directed to a single tool. If your TCO is higher than these benchmarks, proceed with evaluating the AWS security service.