INDEPENDENT AWS SECURITY ASSESSMENT

Assess Your Organization's AWS Cloud Security

Use one organization, project, or AWS environment as the scope for each assessment. Select criteria you can currently verify through policies, configurations, logs, and operating records to see the completed phase and prerequisites across ten capabilities.

The result is not an official AWS assessment, certification, or security audit opinion. Exclude planned work and select only repeatably verifiable operating evidence to decide what to improve next.

Published
Version
1.0.0
Publisher
801 PLANET
Technical review
Public sources
2
Security criteria verified0 of 40 criteria verified

We use the operational evidence you select to calculate the completed phase across ten AWS security capabilities and the first priorities for the next 90 days. The response is saved when results are shown; the email report is optional.

Select only practices you can repeatedly verify through current AWS policies, configurations, logs, and operating records. A capability advances only after every criterion in all earlier phases is verified.

Security capabilitySecurity governanceThe ability to manage security accountability, standards, exceptions, and their connection to business risk.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilitySecurity assuranceThe ability to verify with evidence that controls are deployed and operating effectively.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityIdentity and access managementThe ability to limit human and workload access to the necessary scope and duration.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityThreat detectionThe ability to identify suspicious activity across accounts, workloads, and networks and turn it into investigable signals.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityVulnerability managementThe ability to discover infrastructure and software vulnerabilities and reduce them in time according to business risk.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityInfrastructure protectionThe ability to reduce network, compute, and account exposure while providing safe operational paths.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityData protectionThe ability to understand data sensitivity, location, and flow and prevent exposure or loss.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityApplication securityThe ability to reduce application risk throughout design, development, delivery, and operation.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityIncident responseThe ability to classify, contain, and recover from security events and turn lessons into control improvements.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
Security capabilityResiliencyThe ability to sustain critical services through failures and attacks and recover within objectives.Current completed phasePhase 0 · Not established
Phase 0 → 1Criteria for reaching Phase 1 · Quick Wins
Phase 1 → 2Criteria for reaching Phase 2 · Foundational
Phase 2 → 3Criteria for reaching Phase 3 · Efficient
Phase 3 → 4Criteria for reaching Phase 4 · Optimized
0 of 40 criteria verified
References and use notice

The assessment criteria reference the official public materials for AWS Security Maturity Model v2. This is an independent, unofficial 801 PLANET self-assessment informed by the public structure and guidance of AWS Security Maturity Model v2. It is not an AWS translation, document, certification, or endorsement and does not replace a security audit or compliance determination.