πΌ Cost Optimization | 5 | | 3 | | no data |
γπΌ Cost effective resources | 4 | | | | no data |
γγπΌ Evaluate cost when selecting services | 6 | | | | no data |
γγγπΌ COST05-BP01 Identify organization requirements for cost | | | | | no data |
γγγπΌ COST05-BP02 Analyze all components of the workload | | | | | no data |
γγγπΌ COST05-BP03 Perform a thorough analysis of each component | | | | | no data |
γγγπΌ COST05-BP04 Select software with cost-effective licensing | | | | | no data |
γγγπΌ COST05-BP05 Select components of this workload to optimize cost in line with organization priorities | | | | | no data |
γγγπΌ COST05-BP06 Perform cost analysis for different usage over time | | | | | no data |
γγπΌ Plan for data transfer | 3 | | | | no data |
γγγπΌ COST08-BP01 Perform data transfer modeling | | | | | no data |
γγγπΌ COST08-BP02 Select components to optimize data transfer cost | | | | | no data |
γγγπΌ COST08-BP03 Implement services to reduce data transfer costs | | | | | no data |
γγπΌ Select the best pricing model | 5 | | | | no data |
γγγπΌ COST07-BP01 Perform pricing model analysis | | | | | no data |
γγγπΌ COST07-BP02 Choose Regions based on cost | | | | | no data |
γγγπΌ COST07-BP03 Select third-party agreements with cost-efficient terms | | | | | no data |
γγγπΌ COST07-BP04 Implement pricing models for all components of this workload | | | | | no data |
γγγπΌ COST07-BP05 Perform pricing model analysis at the management account level | | | | | no data |
γγπΌ Select the correct resource type, size, and number | 4 | | | | no data |
γγγπΌ COST06-BP01 Perform cost modeling | | | | | no data |
γγγπΌ COST06-BP02 Select resource type, size, and number based on data | | | | | no data |
γγγπΌ COST06-BP03 Select resource type, size, and number automatically based on metrics | | | | | no data |
γγγπΌ COST06-BP04 Consider using shared resources | | | | | no data |
γπΌ Expenditure and usage awareness | 3 | | 3 | | no data |
γγπΌ Decommission resources | 5 | | | | no data |
γγγπΌ COST04-BP01 Track resources over their lifetime | | | | | no data |
γγγπΌ COST04-BP02 Implement a decommissioning process | | | | | no data |
γγγπΌ COST04-BP03 Decommission resources | | | | | no data |
γγγπΌ COST04-BP04 Decommission resources automatically | | | | | no data |
γγγπΌ COST04-BP05 Enforce data retention policies | | | | | no data |
γγπΌ Governance | 6 | | 3 | | no data |
γγγπΌ COST02-BP01 Develop policies based on your organization requirements | | | | | no data |
γγγπΌ COST02-BP02 Implement goals and targets | | | | | no data |
γγγπΌ COST02-BP03 Implement an account structure | | | | | no data |
γγγπΌ COST02-BP04 Implement groups and roles | | | 3 | | no data |
γγγπΌ COST02-BP05 Implement cost controls | | | | | no data |
γγγπΌ COST02-BP06 Track project lifecycle | | | | | no data |
γγπΌ Monitor cost and usage | 6 | | | | no data |
γγγπΌ COST03-BP01 Configure detailed information sources | | | | | no data |
γγγπΌ COST03-BP02 Add organization information to cost and usage | | | | | no data |
γγγπΌ COST03-BP03 Identify cost attribution categories | | | | | no data |
γγγπΌ COST03-BP04 Establish organization metrics | | | | | no data |
γγγπΌ COST03-BP05 Configure billing and cost management tools | | | | | no data |
γγγπΌ COST03-BP06 Allocate costs based on workload metrics | | | | | no data |
γπΌ Manage demand and supply resources | 3 | | | | no data |
γγπΌ COST09-BP01 Perform an analysis on the workload demand | | | | | no data |
γγπΌ COST09-BP02 Implement a buffer or throttle to manage demand | | | | | no data |
γγπΌ COST09-BP03 Supply resources dynamically | | | | | no data |
γπΌ Optimize over time | 2 | | | | no data |
γγπΌ Automating operations | 1 | | | | no data |
γγγπΌ COST11-BP01 Perform automation for operations | | | | | no data |
γγπΌ Define a review process and analyze your workload regularly | 2 | | | | no data |
γγγπΌ COST10-BP01 Develop a workload review process | | | | | no data |
γγγπΌ COST10-BP02 Review and analyze this workload regularly | | | | | no data |
γπΌ Practice Cloud Financial Management | 9 | | | | no data |
γγπΌ COST01-BP01 Establish ownership of cost optimization | | | | | no data |
γγπΌ COST01-BP02 Establish a partnership between finance and technology | | | | | no data |
γγπΌ COST01-BP03 Establish cloud budgets and forecasts | | | | | no data |
γγπΌ COST01-BP04 Implement cost awareness in your organizational processes | | | | | no data |
γγπΌ COST01-BP05 Report and notify on cost optimization | | | | | no data |
γγπΌ COST01-BP06 Monitor cost proactively | | | | | no data |
γγπΌ COST01-BP07 Keep up-to-date with new service releases | | | | | no data |
γγπΌ COST01-BP08 Create a cost-aware culture | | | | | no data |
γγπΌ COST01-BP08 Create a cost-aware culture | | | | | no data |
πΌ Operational Excellence | 4 | | 3 | | no data |
γπΌ Evolve | 1 | | | | no data |
γγπΌ Learn, share, and improve | 9 | | | | no data |
γγγπΌ OPS11-BP01 Have a process for continuous improvement | | | | | no data |
γγγπΌ OPS11-BP02 Perform post-incident analysis | | | | | no data |
γγγπΌ OPS11-BP03 Implement feedback loops | | | | | no data |
γγγπΌ OPS11-BP04 Perform knowledge management | | | | | no data |
γγγπΌ OPS11-BP05 Define drivers for improvement | | | | | no data |
γγγπΌ OPS11-BP06 Validate insights | | | | | no data |
γγγπΌ OPS11-BP07 Perform operations metrics reviews | | | | | no data |
γγγπΌ OPS11-BP08 Document and share lessons learned | | | | | no data |
γγγπΌ OPS11-BP09 Allocate time to make improvements | | | | | no data |
γπΌ Operate | 3 | | | | no data |
γγπΌ Responding to events | 7 | | | | no data |
γγγπΌ OPS10-BP01 Use a process for event, incident, and problem management | | | | | no data |
γγγπΌ OPS10-BP02 Have a process per alert | | | | | no data |
γγγπΌ OPS10-BP03 Prioritize operational events based on business impact | | | | | no data |
γγγπΌ OPS10-BP04 Define escalation paths | | | | | no data |
γγγπΌ OPS10-BP05 Define a customer communication plan for service-impacting events | | | | | no data |
γγγπΌ OPS10-BP06 Communicate status through dashboards | | | | | no data |
γγγπΌ OPS10-BP07 Automate responses to events | | | | | no data |
γγπΌ Understanding operational health | 3 | | | | no data |
γγγπΌ OPS05-BP03 Use configuration management systems | | | | | no data |
γγγπΌ OPS09-BP01 Measure operations goals and KPIs with metrics | | | | | no data |
γγγπΌ OPS09-BP02 Communicate status and trends to ensure visibility into operation | | | | | no data |
γγπΌ Utilizing workload observability | 5 | | | | no data |
γγγπΌ OPS08-BP01 Analyze workload metrics | | | | | no data |
γγγπΌ OPS08-BP02 Analyze workload logs | | | | | no data |
γγγπΌ OPS08-BP03 Analyze workload traces | | | | | no data |
γγγπΌ OPS08-BP04 Create actionable alerts | | | | | no data |
γγγπΌ OPS08-BP05 Create dashboards | | | | | no data |
γπΌ Organization | 3 | | | | no data |
γγπΌ Operating model | 6 | | | | no data |
γγγπΌ OPS02-BP01 Resources have identified owners | | | | | no data |
γγγπΌ OPS02-BP02 Processes and procedures have identified owners | | | | | no data |
γγγπΌ OPS02-BP03 Operations activities have identified owners responsible for their performance | | | | | no data |
γγγπΌ OPS02-BP04 Mechanisms exist to manage responsibilities and ownership | | | | | no data |
γγγπΌ OPS02-BP05 Mechanisms exist to request additions, changes, and exceptions | | | | | no data |
γγγπΌ OPS02-BP06 Responsibilities between teams are predefined or negotiated | | | | | no data |
γγπΌ Organization priorities | 6 | | | | no data |
γγγπΌ OPS01-BP01 Evaluate external customer needs | | | | | no data |
γγγπΌ OPS01-BP02 Evaluate internal customer needs | | | | | no data |
γγγπΌ OPS01-BP03 Evaluate governance requirements | | | | | no data |
γγγπΌ OPS01-BP04 Evaluate compliance requirements | | | | | no data |
γγγπΌ OPS01-BP05 Evaluate threat landscape | | | | | no data |
γγγπΌ OPS01-BP06 Evaluate tradeoffs while managing benefits and risks | | | | | no data |
γγπΌ Organizational culture | 7 | | | | no data |
γγγπΌ OPS03-BP01 Provide executive sponsorship | | | | | no data |
γγγπΌ OPS03-BP02 Team members are empowered to take action when outcomes are at risk | | | | | no data |
γγγπΌ OPS03-BP03 Escalation is encouraged | | | | | no data |
γγγπΌ OPS03-BP04 Communications are timely, clear, and actionable | | | | | no data |
γγγπΌ OPS03-BP05 Experimentation is encouraged | | | | | no data |
γγγπΌ OPS03-BP06 Team members are encouraged to maintain and grow their skill sets | | | | | no data |
γγγπΌ OPS03-BP07 Resource teams appropriately | | | | | no data |
γπΌ Prepare | 4 | | 3 | | no data |
γγπΌ Design for operations | 10 | | 2 | | no data |
γγγπΌ OPS05-BP01 Use version control | | | | | no data |
γγγπΌ OPS05-BP02 Test and validate changes | | | | | no data |
γγγπΌ OPS05-BP03 Use configuration management systems | | | | | no data |
γγγπΌ OPS05-BP04 Use build and deployment management systems | | | | | no data |
γγγπΌ OPS05-BP05 Perform patch management | | | 2 | | no data |
γγγπΌ OPS05-BP06 Share design standards | | | | | no data |
γγγπΌ OPS05-BP07 Implement practices to improve code quality | | | | | no data |
γγγπΌ OPS05-BP08 Use multiple environment | | | | | no data |
γγγπΌ OPS05-BP09 Make frequent, small, reversible changes | | | | | no data |
γγγπΌ OPS05-BP10 Fully automate integration and deployment | | | | | no data |
γγπΌ Implement observability | 5 | | 1 | | no data |
γγγπΌ OPS04-BP01 Identify key performance indicators | | | | | no data |
γγγπΌ OPS04-BP02 Implement application telemetry | | | | | no data |
γγγπΌ OPS04-BP03 Implement user experience telemetry | | | | | no data |
γγγπΌ OPS04-BP04 Implement dependency telemetry | | | | | no data |
γγγπΌ OPS04-BP05 Implement distributed tracing | | | 1 | | no data |
γγπΌ Mitigate deployment risks | 4 | | | | no data |
γγγπΌ OPS06-BP01 Plan for unsuccessful changes | | | | | no data |
γγγπΌ OPS06-BP02 Test deployments | | | | | no data |
γγγπΌ OPS06-BP03 Employ safe deployment strategies | | | | | no data |
γγγπΌ OPS06-BP04 Automate testing and rollback | | | | | no data |
γγπΌ Operational readiness and change management | 6 | | | | no data |
γγγπΌ OPS07-BP01 Ensure personnel capability | | | | | no data |
γγγπΌ OPS07-BP02 Ensure a consistent review of operational readiness | | | | | no data |
γγγπΌ OPS07-BP03 Use runbooks to perform procedures | | | | | no data |
γγγπΌ OPS07-BP04 Use playbooks to investigate issues | | | | | no data |
γγγπΌ OPS07-BP05 Make informed decisions to deploy systems and changes | | | | | no data |
γγγπΌ OPS07-BP06 Create support plans for production workloads | | | | | no data |
πΌ Performance Efficiency | 5 | | | | no data |
γπΌ Architecture selection | 7 | | | | no data |
γγπΌ PERF01-BP01 Learn about and understand available cloud services and features | | | | | no data |
γγπΌ PERF01-BP02 Use guidance from your cloud provider or an appropriate partner to learn about architecture patterns and best practices | | | | | no data |
γγπΌ PERF01-BP03 Factor cost into architectural decisions | | | | | no data |
γγπΌ PERF01-BP04 Evaluate how trade-offs impact customers and architecture efficiency | | | | | no data |
γγπΌ PERF01-BP05 Use policies and reference architectures | | | | | no data |
γγπΌ PERF01-BP06 Use benchmarking to drive architectural decisions | | | | | no data |
γγπΌ PERF01-BP07 Use a data-driven approach for architectural choices | | | | | no data |
γπΌ Compute and hardware | 6 | | | | no data |
γγπΌ PERF02-BP01 Select the best compute options for your workload | | | | | no data |
γγπΌ PERF02-BP02 Understand the available compute configuration and features | | | | | no data |
γγπΌ PERF02-BP03 Collect compute-related metrics | | | | | no data |
γγπΌ PERF02-BP04 Configure and right-size compute resources | | | | | no data |
γγπΌ PERF02-BP05 Scale your compute resources dynamically | | | | | no data |
γγπΌ PERF02-BP06 Use optimized hardware-based compute accelerators | | | | | no data |
γπΌ Data management | 4 | | | | no data |
γγπΌ PERF03-BP01 Use a purpose-built data store that best supports your data access and storage requirements | | | | | no data |
γγπΌ PERF03-BP02 Evaluate available configuration options for data store | | | | | no data |
γγπΌ PERF03-BP03 Collect and record data store performance metrics | | | | | no data |
γγπΌ PERF03-BP04 Implement strategies to improve query performance in data store | | | | | no data |
γπΌ Networking and content delivery | 7 | | | | no data |
γγπΌ PERF04-BP01 Understand how networking impacts performance | | | | | no data |
γγπΌ PERF04-BP02 Evaluate available networking features | | | | | no data |
γγπΌ PERF04-BP03 Choose appropriate dedicated connectivity or VPN for your workload | | | | | no data |
γγπΌ PERF04-BP04 Use load balancing to distribute traffic across multiple resources | | | | | no data |
γγπΌ PERF04-BP05 Choose network protocols to improve performance | | | | | no data |
γγπΌ PERF04-BP06 Choose your workload's location based on network requirements | | | | | no data |
γγπΌ PERF04-BP07 Optimize network configuration based on metrics | | | | | no data |
γπΌ Process and culture | 7 | | | | no data |
γγπΌ PERF05-BP01 Establish key performance indicators (KPIs) to measure workload health and performance | | | | | no data |
γγπΌ PERF05-BP02 Use monitoring solutions to understand the areas where performance is most critical | | | | | no data |
γγπΌ PERF05-BP03 Define a process to improve workload performance | | | | | no data |
γγπΌ PERF05-BP04 Load test your workload | | | | | no data |
γγπΌ PERF05-BP05 Use automation to proactively remediate performance-related issues | | | | | no data |
γγπΌ PERF05-BP06 Keep your workload and services up-to-date | | | | | no data |
γγπΌ PERF05-BP07 Review metrics at regular intervals | | | | | no data |
πΌ Reliability | 4 | | | | no data |
γπΌ Change management | 3 | | | | no data |
γγπΌ Design your workload to adapt to changes in demand | 4 | | | | no data |
γγγπΌ REL07-BP01 Use automation when obtaining or scaling resources | | | | | no data |
γγγπΌ REL07-BP02 Obtain resources upon detection of impairment to a workload | | | | | no data |
γγγπΌ REL07-BP03 Obtain resources upon detection that more resources are needed for a workload | | | | | no data |
γγγπΌ REL07-BP04 Load test your workload | | | | | no data |
γγπΌ Implement change | 5 | | | | no data |
γγγπΌ REL08-BP01 Use runbooks for standard activities such as deployment | | | | | no data |
γγγπΌ REL08-BP02 Integrate functional testing as part of your deployment | | | | | no data |
γγγπΌ REL08-BP03 Integrate resiliency testing as part of your deployment | | | | | no data |
γγγπΌ REL08-BP04 Deploy using immutable infrastructure | | | | | no data |
γγγπΌ REL08-BP05 Deploy changes with automation | | | | | no data |
γγπΌ Monitor workload resources | 7 | | | | no data |
γγγπΌ REL06-BP01 Monitor all components for the workload (Generation) | | | | | no data |
γγγπΌ REL06-BP02 Define and calculate metrics (Aggregation) | | | | | no data |
γγγπΌ REL06-BP03 Send notifications (Real-time processing and alarming) | | | | | no data |
γγγπΌ REL06-BP04 Automate responses (Real-time processing and alarming) | | | | | no data |
γγγπΌ REL06-BP05 Analyze logs | | | | | no data |
γγγπΌ REL06-BP06 Regularly review monitoring scope and metrics | | | | | no data |
γγγπΌ REL06-BP07 Monitor end-to-end tracing of requests through your system | | | | | no data |
γπΌ Failure management | 5 | | | | no data |
γγπΌ Back up data | 4 | | | | no data |
γγγπΌ REL09-BP01 Identify and back up all data that needs to be backed up, or reproduce the data from sources | | | | | no data |
γγγπΌ REL09-BP02 Secure and encrypt backups | | | | | no data |
γγγπΌ REL09-BP03 Perform data backup automatically | | | | | no data |
γγγπΌ REL09-BP04 Perform periodic recovery of the data to verify backup integrity and processes | | | | | no data |
γγπΌ Design your workload to withstand component failures | 7 | | | | no data |
γγγπΌ REL11-BP01 Monitor all components of the workload to detect failures | | | | | no data |
γγγπΌ REL11-BP02 Fail over to healthy resources | | | | | no data |
γγγπΌ REL11-BP03 Automate healing on all layers | | | | | no data |
γγγπΌ REL11-BP04 Rely on the data plane and not the control plane during recovery | | | | | no data |
γγγπΌ REL11-BP05 Use static stability to prevent bimodal behavior | | | | | no data |
γγγπΌ REL11-BP06 Send notifications when events impact availability | | | | | no data |
γγγπΌ REL11-BP07 Architect your product to meet availability targets and uptime service level agreements (SLAs) | | | | | no data |
γγπΌ Plan for Disaster Recovery (DR) | 5 | | | | no data |
γγγπΌ REL13-BP01 Define recovery objectives for downtime and data loss | | | | | no data |
γγγπΌ REL13-BP02 Use defined recovery strategies to meet the recovery objectives | | | | | no data |
γγγπΌ REL13-BP03 Test disaster recovery implementation to validate the implementation | | | | | no data |
γγγπΌ REL13-BP04 Manage configuration drift at the DR site or Region | | | | | no data |
γγγπΌ REL13-BP05 Automate recovery | | | | | no data |
γγπΌ Test reliability | 5 | | | | no data |
γγγπΌ REL12-BP01 Use playbooks to investigate failures | | | | | no data |
γγγπΌ REL12-BP02 Perform post-incident analysis | | | | | no data |
γγγπΌ REL12-BP03 Test scalability and performance requirements | | | | | no data |
γγγπΌ REL12-BP04 Test resiliency using chaos engineering | | | | | no data |
γγγπΌ REL12-BP05 Conduct game days regularly | | | | | no data |
γγπΌ Use fault isolation to protect your workload | 3 | | | | no data |
γγγπΌ REL10-BP01 Deploy the workload to multiple locations | | | | | no data |
γγγπΌ REL10-BP02 Automate recovery for components constrained to a single location | | | | | no data |
γγγπΌ REL10-BP03 Use bulkhead architectures to limit scope of impact | | | | | no data |
γπΌ Foundations | 2 | | | | no data |
γγπΌ Manage service quotas and constraints | 6 | | | | no data |
γγγπΌ REL01-BP01 Aware of service quotas and constraints | | | | | no data |
γγγπΌ REL01-BP02 Manage service quotas across accounts and regions | | | | | no data |
γγγπΌ REL01-BP03 Accommodate fixed service quotas and constraints through architecture | | | | | no data |
γγγπΌ REL01-BP04 Monitor and manage quotas | | | | | no data |
γγγπΌ REL01-BP05 Automate quota management | | | | | no data |
γγγπΌ REL01-BP06 Ensure that a sufficient gap exists between the current quotas and the maximum usage to accommodate failover | | | | | no data |
γγπΌ Plan your network topology | 5 | | | | no data |
γγγπΌ REL02-BP01 Use highly available network connectivity for your workload public endpoints | | | | | no data |
γγγπΌ REL02-BP02 Provision redundant connectivity between private networks in the cloud and on-premises environments | | | | | no data |
γγγπΌ REL02-BP03 Ensure IP subnet allocation accounts for expansion and availability | | | | | no data |
γγγπΌ REL02-BP04 Prefer hub-and-spoke topologies over many-to-many mesh | | | | | no data |
γγγπΌ REL02-BP05 Enforce non-overlapping private IP address ranges in all private address spaces where they are connected | | | | | no data |
γπΌ Workload architecture | 3 | | | | no data |
γγπΌ Design interactions in a distributed system to mitigate or withstand failures | 7 | | | | no data |
γγγπΌ REL05-BP01 Implement graceful degradation to transform applicable hard dependencies into soft dependencies | | | | | no data |
γγγπΌ REL05-BP02 Throttle requests | | | | | no data |
γγγπΌ REL05-BP03 Control and limit retry calls | | | | | no data |
γγγπΌ REL05-BP04 Fail fast and limit queues | | | | | no data |
γγγπΌ REL05-BP05 Set client timeouts | | | | | no data |
γγγπΌ REL05-BP06 Make systems stateless where possible | | | | | no data |
γγγπΌ REL05-BP07 Implement emergency levers | | | | | no data |
γγπΌ Design interactions in a distributed system to prevent failures | 4 | | | | no data |
γγγπΌ REL04-BP01 Identify the kind of distributed systems you depend on | | | | | no data |
γγγπΌ REL04-BP02 Implement loosely coupled dependencies | | | | | no data |
γγγπΌ REL04-BP03 Do constant work | | | | | no data |
γγγπΌ REL04-BP04 Make mutating operations idempotent | | | | | no data |
γγπΌ Design your workload service architecture | 3 | | | | no data |
γγγπΌ REL03-BP01 Choose how to segment your workload | | | | | no data |
γγγπΌ REL03-BP02 Build services focused on specific business domains and functionality | | | | | no data |
γγγπΌ REL03-BP03 Provide service contracts per API | | | | | no data |
πΌ Security | 7 | | 1 | | no data |
γπΌ Application Security | 8 | | | | no data |
γγπΌ SEC11-BP01 Train for application security | | | | | no data |
γγπΌ SEC11-BP02 Automate testing throughout the development and release lifecycle | | | | | no data |
γγπΌ SEC11-BP03 Perform regular penetration testing | | | | | no data |
γγπΌ SEC11-BP04 Conduct code reviews | | | | | no data |
γγπΌ SEC11-BP05 Centralize services for packages and dependencies | | | | | no data |
γγπΌ SEC11-BP06 Deploy software programmatically | | | | | no data |
γγπΌ SEC11-BP07 Regularly assess security properties of the pipelines | | | | | no data |
γγπΌ SEC11-BP08 Build a program that embeds security ownership in workload teams | | | | | no data |
γπΌ Data protection | 3 | | | | no data |
γγπΌ Data Classification | 4 | | | | no data |
γγγπΌ SEC07-BP01 Understand your data classification scheme | | | | | no data |
γγγπΌ SEC07-BP02 Apply data protection controls based on data sensitivity | | | | | no data |
γγγπΌ SEC07-BP03 Automate identification and classification | | | | | no data |
γγγπΌ SEC07-BP04 Define scalable data lifecycle management | | | | | no data |
γγπΌ Protecting Data at Rest | 4 | | | | no data |
γγγπΌ SEC08-BP01 Implement secure key management | | | | | no data |
γγγπΌ SEC08-BP02 Enforce encryption at rest | | | | | no data |
γγγπΌ SEC08-BP03 Automate data at rest protection | | | | | no data |
γγγπΌ SEC08-BP04 Enforce access control | | | | | no data |
γγπΌ Protecting Data in Transit | 3 | | | | no data |
γγγπΌ SEC09-BP01 Implement secure key and certificate management | | | | | no data |
γγγπΌ SEC09-BP02 Enforce encryption in transit | | | | | no data |
γγγπΌ SEC09-BP03 Authenticate network communications | | | | | no data |
γπΌ Detection | 4 | | 1 | | no data |
γγπΌ SEC04-BP01 Configure service and application logging | | | | | no data |
γγπΌ SEC04-BP02 Capture logs, findings, and metrics in standardized locations | | | | | no data |
γγπΌ SEC04-BP03 Correlate and enrich security alerts | | | 1 | | no data |
γγπΌ SEC04-BP04 Initiate remediation for non-compliant resources | | | 1 | | no data |
γπΌ Identity and Access Management | 2 | | | | no data |
γγπΌ Identity management | 6 | | | | no data |
γγγπΌ SEC02-BP01 Use strong sign-in mechanisms | | | | | no data |
γγγπΌ SEC02-BP02 Use temporary credentials | | | | | no data |
γγγπΌ SEC02-BP03 Store and use secrets securely | | | | | no data |
γγγπΌ SEC02-BP04 Rely on a centralized identity provider | | | | | no data |
γγγπΌ SEC02-BP05 Audit and rotate credentials periodically | | | | | no data |
γγγπΌ SEC02-BP06 Employ user groups and attributes | | | | | no data |
γγπΌ Permissions management | 9 | | | | no data |
γγγπΌ SEC03-BP01 Define access requirements | | | | | no data |
γγγπΌ SEC03-BP02 Grant least privilege access | | | | | no data |
γγγπΌ SEC03-BP03 Establish emergency access process | | | | | no data |
γγγπΌ SEC03-BP04 Reduce permissions continuously | | | | | no data |
γγγπΌ SEC03-BP05 Define permission guardrails for your organization | | | | | no data |
γγγπΌ SEC03-BP06 Manage access based on lifecycle | | | | | no data |
γγγπΌ SEC03-BP07 Analyze public and cross-account access | | | | | no data |
γγγπΌ SEC03-BP08 Share resources securely within your organization | | | | | no data |
γγγπΌ SEC03-BP09 Share resources securely with a third party | | | | | no data |
γπΌ Incident Response | 1 | | | | no data |
γγπΌ Preparation | 8 | | | | no data |
γγγπΌ SEC10-BP01 Identify key personnel and external resources | | | | | no data |
γγγπΌ SEC10-BP02 Develop incident management plans | | | | | no data |
γγγπΌ SEC10-BP03 Prepare forensic capabilities | | | | | no data |
γγγπΌ SEC10-BP04 Develop and test security incident response playbooks | | | | | no data |
γγγπΌ SEC10-BP05 Pre-provision access | | | | | no data |
γγγπΌ SEC10-BP06 Pre-deploy tools | | | | | no data |
γγγπΌ SEC10-BP07 Run simulations | | | | | no data |
γγγπΌ SEC10-BP08 Establish a framework for learning from incidents | | | | | no data |
γπΌ Infrastructure protection | 2 | | 1 | | no data |
γγπΌ Protecting Compute | 5 | | | | no data |
γγγπΌ SEC06-BP01 Perform vulnerability management | | | | | no data |
γγγπΌ SEC06-BP02 Provision compute from hardened images | | | | | no data |
γγγπΌ SEC06-BP03 Reduce manual management and interactive access | | | | | no data |
γγγπΌ SEC06-BP04 Validate software integrity | | | | | no data |
γγγπΌ SEC06-BP05 Automate compute protection | | | | | no data |
γγπΌ Protecting Networks | 4 | | 1 | | no data |
γγγπΌ SEC05-BP01 Create network layers | | | | | no data |
γγγπΌ SEC05-BP02 Control traffic flow within your network layers | | | | | no data |
γγγπΌ SEC05-BP03 Implement inspection-based protection | | | 1 | | no data |
γγγπΌ SEC05-BP04 Automate network protection | | | 1 | | no data |
γπΌ Security Foundations | 1 | | | | no data |
γγπΌ Operating your workloads securely | 8 | | | | no data |
γγγπΌ SEC01-BP01 Separate workloads using accounts | | | | | no data |
γγγπΌ SEC01-BP02 Secure account root user and properties | | | | | no data |
γγγπΌ SEC01-BP03 Identify and validate control objectives | | | | | no data |
γγγπΌ SEC01-BP04 Stay up to date with security threats and recommendations | | | | | no data |
γγγπΌ SEC01-BP05 Reduce security management scope | | | | | no data |
γγγπΌ SEC01-BP06 Automate deployment of standard security controls | | | | | no data |
γγγπΌ SEC01-BP07 Identify threats and prioritize mitigations using a threat model | | | | | no data |
γγγπΌ SEC01-BP08 Evaluate and implement new security services and features regularly | | | | | no data |
πΌ Sustainability | 6 | | | | no data |
γπΌ Alignment to demand | 6 | | | | no data |
γγπΌ SUS02-BP01 Scale workload infrastructure dynamically | | | | | no data |
γγπΌ SUS02-BP02 Align SLAs with sustainability goals | | | | | no data |
γγπΌ SUS02-BP03 Stop the creation and maintenance of unused assets | | | | | no data |
γγπΌ SUS02-BP04 Optimize geographic placement of workloads based on their networking requirements | | | | | no data |
γγπΌ SUS02-BP05 Optimize team member resources for activities performed | | | | | no data |
γγπΌ SUS02-BP06 Implement buffering or throttling to flatten the demand curve | | | | | no data |
γπΌ Data management | 8 | | | | no data |
γγπΌ SUS04-BP01 Implement a data classification policy | | | | | no data |
γγπΌ SUS04-BP02 Use technologies that support data access and storage patterns | | | | | no data |
γγπΌ SUS04-BP03 Use policies to manage the lifecycle of your datasets | | | | | no data |
γγπΌ SUS04-BP04 Use elasticity and automation to expand block storage or file system | | | | | no data |
γγπΌ SUS04-BP05 Remove unneeded or redundant data | | | | | no data |
γγπΌ SUS04-BP06 Use shared file systems or storage to access common data | | | | | no data |
γγπΌ SUS04-BP07 Minimize data movement across networks | | | | | no data |
γγπΌ SUS04-BP08 Back up data only when difficult to recreate | | | | | no data |
γπΌ Hardware and services | 4 | | | | no data |
γγπΌ SUS05-BP01 Use the minimum amount of hardware to meet your needs | | | | | no data |
γγπΌ SUS05-BP02 Use instance types with the least impact | | | | | no data |
γγπΌ SUS05-BP03 Use managed services | | | | | no data |
γγπΌ SUS05-BP04 Optimize your use of hardware-based compute accelerators | | | | | no data |
γπΌ Process and culture | 5 | | | | no data |
γγπΌ SUS06-BP01 Communicate and cascade your sustainability goals | | | | | no data |
γγπΌ SUS06-BP02 Adopt methods that can rapidly introduce sustainability improvements | | | | | no data |
γγπΌ SUS06-BP03 Keep your workload up-to-date | | | | | no data |
γγπΌ SUS06-BP04 Increase utilization of build environments | | | | | no data |
γγπΌ SUS06-BP05 Use managed device farms for testing | | | | | no data |
γπΌ Region selection | 1 | | | | no data |
γγπΌ SUS01-BP01 Choose Region based on both business requirements and sustainability goals | | | | | no data |
γπΌ Software and architecture | 5 | | | | no data |
γγπΌ SUS03-BP01 Optimize software and architecture for asynchronous and scheduled jobs | | | | | no data |
γγπΌ SUS03-BP02 Remove or refactor workload components with low or no use | | | | | no data |
γγπΌ SUS03-BP03 Optimize areas of code that consume the most time or resources | | | | | no data |
γγπΌ SUS03-BP04 Optimize impact on devices and equipment | | | | | no data |
γγπΌ SUS03-BP05 Use software patterns and architectures that best support data access and storage patterns | | | | | no data |