Security & IAM
AWS Security Hub
AWS Security Hub Cloud Security Posture Management centralizes standards-based security controls and normalizes findings from AWS services, partner products, and custom sources into the AWS Security Finding Format.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Security Hub.
AWS Security Hub pricing and cost programs
Pricing model: Security check and finding ingestion usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Security checks · Finding ingestion · Automation rules
Programs and modes: CSPM · Security standards · Finding aggregation
Charges depend on enabled checks and ingested findings, with trial terms listed on the pricing page.
Free Tier: Available — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Security Hub?
- Provides a consolidated view of security checks and detections instead of requiring every team to query each source service independently.
- Normalizes findings into ASFF and supports cross-Region aggregation, automation rules, EventBridge response, insights, and exposure context.
- Centrally configures standards and controls across organization accounts and Regions through delegated administration and configuration policies.
How to implement AWS Security Hub
- Integrate with AWS Organizations, choose a delegated security administrator and home Region, link every required Region, and create central configuration policies for OUs and accounts.
- Enable standards and controls based on an explicit risk and applicability review, integrate detector sources, assign owners and service-level targets, and route actionable findings into response workflows.
- Tune with documented control exceptions and automation rules, remediate root causes, verify control reevaluation, export findings for retention beyond service windows, and review posture trends.
AWS Security Hub best practices
- Use central configuration to prevent account and Region drift, and explicitly account for opt-in Regions, new controls, inherited policy, and self-managed exceptions.
- Do not equate the security score or a passed standard with complete security or legal compliance; prioritize findings using exploitability, exposure, business impact, and compensating controls.
- Keep finding workflow status accurate, automate only tested reversible remediations, document suppressed or disabled controls, and export data when longer retention is required.
AWS Security Hub use cases and server impact
- Multi-account cloud security posture management
- Centralized security finding triage
- Standards-based controls and remediation tracking
Replaces much custom finding aggregation and posture dashboard infrastructure, but source coverage, risk prioritization, remediation ownership, exceptions, and compliance judgment remain customer responsibilities.
Official implementation resources
Commonly paired AWS services
- Amazon GuardDuty — Threat detection
- Amazon Inspector — Vulnerability management
- Amazon Macie — Sensitive data discovery
- Amazon Security Lake — Centralized security data lake
- AWS Config — Resource compliance
- AWS Organizations — Multi-account mgmt
- Amazon EventBridge — Event bus
- AWS CloudTrail — API audit logging
Planning guides that use AWS Security Hub
- Amazon Detective planning guide — Use Security Hub findings and workflows to centralize investigation intake and status.
- AWS Audit Manager planning guide — Security Hub findings become evidence, so control coverage depends on which standards are enabled there.
- Amazon Macie planning guide — Route Macie findings into Security Hub so sensitive-data results join the rest of the security queue.