About This Architecture
Comprehensive AWS security architecture with multi-layer defense including WAF and Shield at the edge, GuardDuty for threat detection, Security Hub for centralized findings, Config for compliance rules, CloudTrail for audit logging, and IAM with Cognito for identity management. S3 serves as the central log archive with encryption via KMS. Fork this diagram on Diagrams.so to customize the compliance controls or add additional detective services for your security posture. Source: https://aws.amazon.com/architecture/