Prevent

Introduction

Readiness

You should use a consistent process (including checklists) to know when you areready to go live with your workload. This will also enable you to find any areas you will need to make plans to address. You will have runbooks that document your routine activities and playbooks that guide your processes for issue resolution. You will need to have enough team members to cover operational activities (including on-call), with training on AWS, your workload, and your operations tools. You should use a governance process to make an informed decision on launching your workload.

Awareness

When operating a workload you will need to understand what you have, where they are and what state they are in. Tagging, Configuration Management, Inventory and Patch Managment help you to understand your workload.

Telemetry

When instrumenting your workload, capture a broad set of information to enable situational awareness (for example, changes in state, user activity, privilege access, utilization counters), knowing that you can filter to select the most useful information over time. Tag your resources for organization, cost accounting, access controls, and targeting the execution of automation

Guardrails

Guardrails are preventive or detective controls that help you govern your resources and monitor compliance across groups of AWS accounts.