All Services

Security & IAM

AWS Security Hub

AWS Security Hub Cloud Security Posture Management centralizes standards-based security controls and normalizes findings from AWS services, partner products, and custom sources into the AWS Security Finding Format.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Security Hub.

AWS Security Hub pricing and cost programs

Pricing model: Security check and finding ingestion usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Security checks · Finding ingestion · Automation rules

Programs and modes: CSPM · Security standards · Finding aggregation

Charges depend on enabled checks and ingested findings, with trial terms listed on the pricing page.

Free Tier: Available — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Security Hub?

  • Provides a consolidated view of security checks and detections instead of requiring every team to query each source service independently.
  • Normalizes findings into ASFF and supports cross-Region aggregation, automation rules, EventBridge response, insights, and exposure context.
  • Centrally configures standards and controls across organization accounts and Regions through delegated administration and configuration policies.

How to implement AWS Security Hub

  1. Integrate with AWS Organizations, choose a delegated security administrator and home Region, link every required Region, and create central configuration policies for OUs and accounts.
  2. Enable standards and controls based on an explicit risk and applicability review, integrate detector sources, assign owners and service-level targets, and route actionable findings into response workflows.
  3. Tune with documented control exceptions and automation rules, remediate root causes, verify control reevaluation, export findings for retention beyond service windows, and review posture trends.

AWS Security Hub best practices

  • Use central configuration to prevent account and Region drift, and explicitly account for opt-in Regions, new controls, inherited policy, and self-managed exceptions.
  • Do not equate the security score or a passed standard with complete security or legal compliance; prioritize findings using exploitability, exposure, business impact, and compensating controls.
  • Keep finding workflow status accurate, automate only tested reversible remediations, document suppressed or disabled controls, and export data when longer retention is required.

AWS Security Hub use cases and server impact

  • Multi-account cloud security posture management
  • Centralized security finding triage
  • Standards-based controls and remediation tracking

Replaces much custom finding aggregation and posture dashboard infrastructure, but source coverage, risk prioritization, remediation ownership, exceptions, and compliance judgment remain customer responsibilities.

Official implementation resources

Commonly paired AWS services

Planning guides that use AWS Security Hub