AWS Security Blog

Category: HAQM Macie

How to enhance HAQM Macie data discovery capabilities using HAQM Textract

HAQM Macie is a managed service that uses machine learning (ML) and deterministic pattern matching to help discover sensitive data that’s stored in HAQM Simple Storage Service (HAQM S3) buckets. Macie can detect sensitive data in many different formats, including commonly used compression and archive formats. However, Macie doesn’t support the discovery of sensitive data […]

HAQM Macie

How to perform a proof of concept for automated discovery using HAQM Macie

HAQM Web Services (AWS) customers of various sizes across different industries are pursuing initiatives to better classify and protect the data they store in HAQM Simple Storage Service (HAQM S3). HAQM Macie helps customers identify, discover, monitor, and protect sensitive data stored in HAQM S3. However, it’s important that customers evaluate and test the capabilities […]

Solution overview

Building sensitive data remediation workflows in multi-account AWS environments

The rapid growth of data has empowered organizations to develop better products, more personalized services, and deliver transformational outcomes for their customers. As organizations use HAQM Web Services (AWS) to modernize their data capabilities, they can sometimes find themselves with data spread across several AWS accounts, each aligned to distinct use cases and business units. […]

HAQM Macie logo

How to use HAQM Macie to preview sensitive data in S3 buckets

February 13, 2024: We’ve updated this post to show you how to configure Macie to assume an IAM role when you configure Macie to preview sensitive data in findings. Security teams use HAQM Macie to discover and protect sensitive data, such as names, payment card data, and AWS credentials, in HAQM Simple Storage Service (HAQM […]

Use HAQM Macie for automatic, continual, and cost-effective discovery of sensitive data in S3

Customers have an increasing need to collect, store, and process data within their AWS environments for application modernization, reporting, and predictive analytics. AWS Well-Architected security pillar, general data privacy and compliance regulations require that you appropriately identify and secure sensitive information. Knowing where your data is allows you to implement the appropriate security controls which […]

Enabling data classification for HAQM RDS database with Macie

Customers have been asking us about ways to use HAQM Macie data discovery on their HAQM Relational Database Service (HAQM RDS) instances. This post presents how to do so using AWS Database Migration Service (AWS DMS) to extract data from HAQM RDS, store it on HAQM Simple Storage Service (HAQM S3), and then classify the […]

Strengthen the security of sensitive data stored in HAQM S3 by using additional AWS services

October 13, 2021: We’ve added a section on redacting and transforming personally identifiable information with HAQM S3 Object Lambda. In this post, we describe the AWS services that you can use to both detect and protect your data stored in HAQM Simple Storage Service (HAQM S3). When you analyze security in depth for your HAQM […]

Creating a notification workflow from sensitive data discover with HAQM Macie, HAQM EventBridge, AWS Lambda, and Slack

Following the example of the EU in implementing the General Data Protection Regulation (GDPR), many countries are implementing similar data protection laws. In response, many companies are forming teams that are responsible for data protection. Considering the volume of information that companies maintain, it’s essential that these teams are alerted when sensitive data is at […]

Deploy an automated ChatOps solution for remediating HAQM Macie findings

The amount of data being collected, stored, and processed by HAQM Web Services (AWS) customers is growing at an exponential rate. In order to keep pace with this growth, customers are turning to scalable cloud storage services like HAQM Simple Storage Service (HAQM S3) to build data lakes at the petabyte scale. Customers are looking […]

Detecting sensitive data in DynamoDB with Macie

HAQM Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect your sensitive data in HAQM Web Services (AWS). It gives you the ability to automatically scan for sensitive data and get an inventory of your HAQM Simple Storage Service (HAQM S3) buckets. […]