📋 Compliance & Governance Cheat Sheet

Quick-reference for Config, Security Hub standards, SCPs, conformance packs, and compliance automation patterns.

Why This Cheat Sheet Matters for SCS-C02

This cheat sheet covers the most important Compliance & Governance concepts tested on the SCS-C02 (AWS Security Specialty) certification exam. It contains 4 sections with 17 key points that you should memorize before exam day. Use this as a quick-reference guide during your final review sessions.

4Sections
17Key Points

Config Rules & Remediation

  • Managed rules: 300+ pre-built (s3-bucket-public-read-prohibited, etc.)
  • Custom rules: Lambda function evaluates resource changes
  • Remediation: SSM Automation document triggered on non-compliance
  • Auto-remediation: immediate or with manual approval step

Security Hub Standards

  • AWS Foundational Security Best Practices (FSBP)
  • CIS AWS Foundations Benchmark (v1.2, v1.4)
  • PCI DSS v3.2.1
  • NIST SP 800-53 Rev. 5
  • Security score: percentage of passed controls

SCPs (Preventive Controls)

  • Attached to OUs or accounts — limit maximum permissions
  • Do NOT grant permissions — only restrict
  • Do not affect the management account
  • Common patterns: deny region, deny service, enforce encryption, deny root usage

Multi-Account Governance

  • Control Tower: landing zone, guardrails (preventive + detective)
  • Firewall Manager: centralized WAF, Shield, SG, Network Firewall policies
  • Config aggregator: multi-account compliance dashboard
  • Delegated administrator: security account manages security services

Practice Compliance & Governance Questions

Put your knowledge to the test with practice questions.

More SCS-C02 Cheat Sheets