Security
When you build systems on AWS infrastructure, security
responsibilities are shared between you and AWS. This
shared
responsibility model
IAM roles
IAM roles allow this solution to assign granular access policies and permissions to services and users on the AWS Cloud. This solution creates IAM roles that grant the solution's Lambda functions access to manage Regional resources.
VPC security groups
The solution creates security groups designed to control and isolate network traffic between the Lambda functions, Amazon EC2 instances, and remote virtual private network (VPN) endpoints. We recommend that you review the security groups and further restrict access as needed once the deployment is up and running.