ocsf

2 posts

aws

AWS Security Hub Extended offers full-stack enterprise security with curated partner solutions | Amazon Web Services (opens in new tab)

AWS Security Hub Extended expands Security Hub from an AWS-focused service into a broader enterprise security platform. It combines AWS services such as GuardDuty and Inspector with curated partner solutions covering endpoints, identity, email, networks, data, cloud, AI, and security operations. The plan simplifies procurement and operations through AWS billing, normalized findings, and a unified console. ## Curated Partner Security Solutions - Includes offerings from partners such as CrowdStrike, Okta, Proofpoint, SailPoint, Splunk, Zscaler, and others. - Covers security needs across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. - Lets organizations combine AWS and partner tools to detect risks spanning multiple parts of their technology stack. ## Simplified Procurement and Billing - AWS acts as the seller of record. - Customers receive pre-negotiated pay-as-you-go pricing, one monthly bill, and no long-term commitments. - Consumption-based metering is handled automatically after onboarding. - AWS Enterprise Support customers receive unified Level 1 support. ## Unified Findings and Operations - Findings from participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF). - Security Hub automatically aggregates and normalizes findings in one location. - The unified view helps teams prioritize and respond to critical risks more quickly. ## Access and Availability - Customers can find the offerings in the Security Hub console under **Management → Extended plan**. - Partner details, subscriptions, and onboarding are available directly through the console. - The plan is generally available in all commercial AWS Regions where Security Hub operates. - Pricing supports either flexible pay-as-you-go or flat-rate options. Organizations seeking broader security coverage can use Security Hub Extended to consolidate partner procurement, billing, findings, and operations through a single AWS-managed experience.

aws

Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance (opens in new tab)

Amazon CloudWatch has evolved into a unified platform for managing operational, security, and compliance log data, significantly reducing the need for redundant data stores and complex ETL pipelines. By standardizing ingestion through industry-standard formats like OCSF and OpenTelemetry, the service enables seamless cross-source analytics while lowering operational overhead and storage costs. This update allows organizations to move away from fragmented data silos toward a centralized, Iceberg-compatible architecture for deeper technical and business insights. **Data Ingestion and Schema Normalization** * Automatically collects AWS-vended logs across accounts and regions via AWS Organizations, including CloudTrail, VPC Flow Logs, WAF access logs, and Route 53 resolver logs. * Includes pre-built connectors for a wide range of third-party sources, such as endpoint security (CrowdStrike, SentinelOne), identity providers (Okta, Entra ID), and network security (Zscaler, Palo Alto Networks). * Utilizes managed Open Cybersecurity Schema Framework (OCSF) and OpenTelemetry (OTel) conversion to ensure data consistency across disparate sources. * Provides built-in processors, such as Grok for custom parsing and field-level operations, to transform and manipulate strings during the ingestion phase. **Unified Architecture and Cost Optimization** * Consolidates log management into a single service with built-in governance, eliminating the need to store and maintain duplicate copies of data across different tools. * Introduces Apache Iceberg-compatible access via Amazon S3 Tables, allowing data to be queried in place by external tools. * Removes the requirement for complex ETL pipelines by providing a unified data store that is accessible to Amazon Athena, Amazon SageMaker Unified Studio, and other Iceberg-compatible analytics engines. **Advanced Analytics and Discovery Tools** * Supports multiple query interfaces, allowing users to interact with logs using natural language, SQL, LogsQL, or PPL (Piped Processing Language). * The new "Facets" interface enables intuitive filtering by application, account, region, and log type, featuring intelligent parameter inference for cross-account queries. * Enables the correlation of operational logs with business data from third-party tools like ServiceNow CMDB or GitHub to provide a more comprehensive view of organizational health. Organizations should leverage these unified management features to consolidate their security and operational monitoring into a single source of truth. By adopting OCSF normalization and the new S3 Tables integration, teams can reduce the technical debt associated with managing multiple log silos while improving their ability to run cross-functional analytics.