콘텐츠로 이동

AWS Network Security Manager Best Practices

Introduction

Welcome to the AWS Network Security Manager (NSM) Best Practices Guide. The purpose of this guide is to provide prescriptive guidance for using NSM to centrally manage AWS WAF and AWS Shield Advanced network security controls across your AWS accounts and resources. Publishing this guidance via GitHub will allow for quick iterations to enable timely recommendations that include service enhancements, as well as feedback from the user community.

What is AWS Network Security Manager?

NSM gives every team that contributes to network security one shared place to manage those controls. NSM manages AWS WAF and AWS Shield Advanced today, and support for AWS Network Firewall is coming soon.

You define which traffic inspection and firewall configurations apply where, and in what order of precedence, through five NSM resources. The same model applies to each firewall type that NSM manages:

  1. NSM rules define a traffic inspection or firewall configuration.
  2. NSM templates (optional) capture a set of NSM rules that you use in more than one NSM policy.
  3. NSM policies set the order of precedence in which NSM rules are inspected.
  4. NSM scopes select the resources that an NSM policy targets.
  5. NSM deployments put NSM policies into effect.

Every resource supports versioning, rollback, and drafts, so you can test version 2 of an NSM rule in development and then promote that same version to production.

If you use AWS Firewall Manager today, you no longer need to bundle every WAF rule and configuration into one Firewall Manager policy for each scope, or duplicate a Firewall Manager policy to give one business unit something different. Going forward, NSM is the recommended service for managing AWS WAF and AWS Shield.

How to use this guide

This guide is geared towards cloud architects, central security and operations teams, application teams, and threat analysts who contribute to an organization's network security posture. The first sections cover each NSM resource in depth. Later sections cover each firewall type that NSM manages and how to troubleshoot synchronization issues:

Prerequisites

To use NSM across an organization, you need AWS Organizations with a delegated administrator account for NSM, and AWS Resource Access Manager (AWS RAM). To use NSM in a single account, you don't need to set anything up. In both cases, NSM creates and manages an AWS Config service-linked recorder for you, at no customer-facing cost.