By Implementation

Service Control PoliciesConfig RulesAuto Remediation RulesConformance PacksAmazon GuardDutyAmazon InspectorAWS Security HubAWS Network FirewallRoute53 Resolver SecurityAmazon MacieS3 Bucket PoliciesCloudWatch Alarms and Event RulesAWS WAFAWS Secrets ManagerAWS Systems ManagerSecurity Groups & NACLsAWS KMSIAM PoliciesAmazon ECRRDS Event Subscriptions

By Service Protected

Configuration Packages

Strategy Guides

Other

Route53 Security Controls

A collection of AWS Security controls using AWS Route53 Configuration including Hosted Zones, DNS Firewall and DNS Logging for VPCs.

Route53

Configuration template to create a Route53 Hosted Zone (DNS domain). Both public and private hosted zones are supported.

CloudFormationTerraformAWS CLI
Route53 Resolver Firewall

Configuration templates to deploy an AWS Route53 Resolver Firewall and related settings including firewall rule groups, custom domain lists, and VPC associations. This configuration can be used to block DNS requests for malicious or unwanted domains.

CloudFormationTerraformAWS CLI
VPC

Configuration to enable logging the DNS queries that originate in an Amazon VPC using the Route53 Resolver Query Logging feature. Query logs can be sent to CloudWatch logs, S3 Buckets, or Kinesis Data Firehose.

CloudFormationAWS CLI
Route53
Route53 Resolver Firewall
VPC