In this section you will find controls and recommendations that may take some more effort to implement than QuickWins, but are very important.
| Security governance | Identify security and regulatory requirements Cloud Security Training Plan |
| Security assurance | Inventory & Configuration monitoring |
| Identity and access management | GuardRails: Organizational Policies with SCPs/RCPs Use Temporary Credentials Instance Metadata Service (IMDS) v2 |
| Threat detection | Advanced Threat Detection |
| Vulnerability management | Manage infrastructure vulnerabilities Manage application vulnerabilities |
| Infrastructure protection | Limit Network Access Secure EC2 Instances Management Network segmentation (VPCs) Multi-account management |
| Data protection | Data Encryption at rest Backups Discover sensitive data |
| Application security | Involve security teams in development No secrets in code |
| Incident response | Define incident response playbooks |
| Resiliency | Redundancy using multiple Availability Zones |