AWS Open Source Security

Committed to raising standards for the broader community

Overview

At AWS, security is our top priority. We work hard to make AWS the best place for customers to build and run open source software in the cloud. We are committed to raising the bar for open source security by developing key security-related technologies in collaboration with the community and by contributing code, resources, and talent to open source software.

We actively participate in open source foundations, trade associations, standard bodies, and regulatory organizations, with a goal of improving software supply chain security to benefit our customers and improve security posture across the industry.

Security frameworks and tools as open source

We work upstream and release security frameworks and tools as open source to improve security posture across the industry.

OCSF logo

We co-founded, alongside 17 partner organizations, the Open Cybersecurity Schema Framework (OCSF) project to make it easier for security professionals to ingest and correlate telemetry data from different sources. OCSF has gained recognition as the standard for seamless tool communication, enabling interoperability across the open source security community.

Learn more »

RUST Foundation logo

AWS uses Rust, a memory-safe language, as the language of choice for multiple services, including Amazon S3, Amazon Route 53, and Amazon EC2. We contribute dedicated security and software engineering expertise to help organizations like the Rust Foundation improve their security posture, which impacts all those who consume from them.AWS uses Rust, a memory-safe language, as the language of choice for multiple services, including Amazon S3, Amazon Route 53, and Amazon EC2. We contribute dedicated security and software engineering expertise to help organizations like the Rust Foundation improve their security posture, which impacts all those who consume from them.

Learn more »

Kubernetes logo

We participate in the Kubernetes Security Response Committee to improve long-term sustainability and advise on security best practices. We have committed cloud credits to the Cloud Native Computing Foundation to run the Kubernetes project, which helps provide the community with more testing and better tools, leading to fewer bugs in project releases.

Learn more »

OpenJDK logo

We contribute to the OpenJDK project, including bug fixes that are hard to reproduce because they only occur when running at scale. Our commitment extends through Amazon Corretto, a no-cost, multiplatform, production-ready open source distribution of OpenJDK, which comes with long-term support including performance enhancements and security fixes.

Learn more »

Shared learnings

We share AWS learnings and practices on consuming open source securely that you can leverage in your organization.

Powertools for AWS Lambda (Python)

Consider adopting Powertools for AWS Lambda (Python), a developer toolkit to implement serverless best practices and increase developer velocity.

Security Leadership

Learn about our approach to the Apache Log4j (Log4Shell) vulnerability and our guidance to help customers respond.

Security Practices

Learn more about the security practices we use via the GitHub repository, such as the recent security audit completed by the OpenSearch team at AWS.

Have Questions?

Connect with AWS Support
Contact Us »

Exploring security roles?
Apply today »

Want AWS Security updates?
Follow us on X »