AWS AWSEC2: Minor wording updates in Windows security best practices
Summary
Removed 'in order' from least privilege guidance and changed 'utilize' to 'use' in OS features recommendation.
Security assessment
Changes are grammatical improvements without altering security meaning or addressing vulnerabilities.
Evidence
+ * Least privilege – Determine the minimum set of privileges that instances and accounts need to perform their functions. Restrict these servers and users to only allow these defined permissions. Use techniques such as Role Based Access Controls to reduce the surface area of administrative accounts, and create the most limited roles to accomplish a task. Use OS features such as Encrypting File System (EFS) within NTFS to encrypt sensitive data at rest, and control application and user access to it.
Diff
diff --git a/AWSEC2/latest/UserGuide/ec2-windows-security-best-practices.md b/AWSEC2/latest/UserGuide/ec2-windows-security-best-practices.md index 64009f648..77accfd45 100644 --- a//AWSEC2/latest/UserGuide/ec2-windows-security-best-practices.md +++ b//AWSEC2/latest/UserGuide/ec2-windows-security-best-practices.md @@ -34 +34 @@ You should adhere to the following high-level security best practices for your W - * Least privilege – Determine the minimum set of privileges that instances and accounts need in order to perform their functions. Restrict these servers and users to only allow these defined permissions. Use techniques such as Role Based Access Controls to reduce the surface area of administrative accounts, and create the most limited roles to accomplish a task. Use OS features such as Encrypting File System (EFS) within NTFS to encrypt sensitive data at rest, and control application and user access to it. + * Least privilege – Determine the minimum set of privileges that instances and accounts need to perform their functions. Restrict these servers and users to only allow these defined permissions. Use techniques such as Role Based Access Controls to reduce the surface area of administrative accounts, and create the most limited roles to accomplish a task. Use OS features such as Encrypting File System (EFS) within NTFS to encrypt sensitive data at rest, and control application and user access to it. @@ -148 +148 @@ AWS customers can also run Amazon Inspector assessments to improve the security -When securing Windows instances, we recommend that you implement Active Directory Domain Services to enable a scalable, secure, and manageable infrastructure for distributed locations. Additionally, after launching instances from the Amazon EC2 console or by using an Amazon EC2 provisioning tool, such as AWS CloudFormation, it is good practice to utilize native OS features, such as Microsoft Windows PowerShell DSC to maintain configuration state in the event that configuration drift occurs. +When securing Windows instances, we recommend that you implement Active Directory Domain Services to enable a scalable, secure, and manageable infrastructure for distributed locations. Additionally, after launching instances from the Amazon EC2 console or by using an Amazon EC2 provisioning tool, such as AWS CloudFormation, it is good practice to use native OS features, such as Microsoft Windows PowerShell DSC to maintain configuration state in the event that configuration drift occurs.