What Is Security Governance?
When most people hear "security," they think of blocking hackers. But that is only part of the picture.
Real security includes three things: recording who did what and when, encrypting important data so it cannot be read by outsiders, and proving that your systems follow the rules and regulations your industry requires.
This guide walks you through AWS security governance services in plain language — no prior tech experience needed.
---
Think of a Building Security System
Imagine you manage a company office building. To keep it safe, you need several tools.
A visitor log (AWS CloudTrail): records who entered the building, when, and what they touched. A facilities change log (AWS Config): tracks what furniture or equipment was moved or replaced. A key management vault (AWS KMS): keeps the keys to your safes locked away securely.
These three are the backbone of AWS security governance.
---
AWS CloudTrail — Who Did What
CloudTrail records every single action that happens in your AWS account. It logs who did it, when, which service they used, and what they changed.
For example, if someone suddenly deletes an EC2 server, you can open CloudTrail and see exactly who pressed the delete button and at what time.
CloudTrail keeps logs for 90 days by default. For longer storage, you can send logs to an Amazon S3 bucket.
---
AWS Config — How Things Changed Over Time
AWS Config tracks how your AWS resources are configured and how those configurations change over time. You can set "rules," and Config will automatically alert you when something breaks a rule.
For example, you can create a rule that says "no S3 bucket should ever be publicly accessible." If someone accidentally makes a bucket public, you get an alert right away.
Think of it this way: CloudTrail answers "who did it," while Config answers "what changed and whether it should have."
---
AWS KMS — The Key to Your Locks
KMS stands for Key Management Service. It creates, stores, and rotates the encryption keys that protect your data.
Here is a simple analogy. A safe is only useful if the key is stored somewhere secure. KMS is the secure storage for your keys. Without the right key, encrypted data is completely unreadable.
KMS integrates with nearly every AWS data service — Amazon S3, Amazon EBS, Amazon RDS, and more. You can enable encryption with just a few clicks.
---
Two Kinds of Encryption
There are two main ways to encrypt data, and both appear on the exam.
Encryption at Rest protects data that is sitting still — stored on a hard drive or database. Even if someone physically steals the hardware, they cannot read the contents. AWS services like S3, EBS, and RDS support automatic at-rest encryption using KMS.
Encryption in Transit protects data that is moving — travelling across the internet from one place to another. This is the same protection you get when a website uses HTTPS. AWS Certificate Manager (ACM) lets you get free SSL/TLS certificates for your applications.
---
Compliance Services at a Glance
Large companies, hospitals, and financial institutions must prove to regulators that they follow strict security standards. AWS provides several services to help.
| Service | What It Does | |---------|-------------| | AWS Artifact | Download official AWS compliance reports (SOC 2, ISO 27001, PCI DSS, etc.) to show auditors. | | Amazon Inspector | Automatically scans EC2 instances and Lambda functions for known software vulnerabilities. | | Amazon Macie | Automatically finds sensitive data like social security numbers or credit card numbers stored in Amazon S3. | | AWS Security Hub | Collects findings from multiple security services and shows them in one central dashboard. | | AWS Audit Manager | Automatically generates audit-ready reports to simplify compliance reviews. |
---
Exam Key Points
"Track who called which API" → AWS CloudTrail "Track configuration changes to resources" → AWS Config "Create and manage encryption keys" → AWS KMS "Download AWS compliance reports" → AWS Artifact "Scan EC2/Lambda for software vulnerabilities" → Amazon Inspector "Find sensitive data in S3 automatically" → Amazon Macie "See all security findings in one place" → AWS Security Hub Encryption at Rest = data stored on disk. Encryption in Transit = data moving across a network. Both are tested frequently.