Home icon
How AWS built the Security Guardians program, a mechanism to distribute security ownership

Blog



This article explains how AWS created the Security Guardians program to scale security by distributing ownership between security and development teams.

  • Security teams become bottlenecks as product development scales faster than hiring
  • AWS requires independent security reviews before all product launches
  • Security is a business priority with CISO reporting directly to CEO
  • Product teams own security; central teams provide guidance and verification
  • Guardians are trained developers who champion security within product teams
  • Guardians perform initial security review submissions before AppSec engineers
  • Results: 22.5% fewer medium/high severity findings, 26.9% faster reviews
  • Program scales security expertise without hiring additional security staff

The Security Guardians program successfully distributes security ownership, enabling faster product launches while maintaining high security standards through embedded security champions.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.