AWS 专题对比

Monitoring, Audit, Compliance & Governance

Monitoring, Audit, Compliance & Governance

compare监控・审计・合规・治理服务总对比AWS
Last organized

Compare AWS monitoring, audit, compliance, multi-account governance, and best-practice services.

One-line overview

  • Runtime health belongs to CloudWatch; API history to CloudTrail; configuration and compliance rules to Config.
  • AWS reports and agreements belong to Artifact; customer-environment audit evidence to Audit Manager.
  • Organizations provides multi-account foundations; Control Tower adds standardized landing-zone governance.
  • Service Catalog governs approved products; License Manager governs license consumption.
  • AWS Health reports official events; Trusted Advisor recommends improvements; Access Analyzer checks permission exposure.

Service comparison

ServiceCore questionPrimary objectExam keywords
Amazon CloudWatchHow is the system running now?Metrics, logs, alarms, dashboardsCPU, latency, error rate, threshold alarm
AWS CloudTrailWho called which API and when?Account and API activityDeleted resource, operator history, audit log
AWS ConfigHow did configuration change and does it comply?Resource configuration and rulesConfiguration drift, continuous compliance
AWS ArtifactWhere are AWS compliance materials?AWS reports and agreementsSOC/ISO/PCI report, agreement
AWS Audit ManagerHow do we prepare customer-environment audit evidence?Frameworks, controls, evidenceAutomated evidence collection, assessment
AWS OrganizationsHow are multiple accounts managed centrally?Accounts, OUs, SCPs, billingOU, SCP, consolidated billing
AWS Control TowerHow is a governed multi-account environment established?Landing zone, accounts, controlsAccount Factory, guardrails, standard accounts
AWS Service CatalogHow can users deploy approved solutions safely?Portfolios, products, constraintsApproved catalog, controlled self-service
AWS License ManagerHow are software licenses tracked and limited?License rules, quantities, BYOLBYOL, overuse, hybrid environment
AWS Health DashboardDo official AWS events affect us?Events, planned changes, notificationsAWS incident, maintenance, instance retirement
AWS Trusted AdvisorWhich best-practice improvements are recommended?Cost, performance, security, resilience, quotasIdle resources, root MFA, quota pressure
IAM Access AnalyzerWho can access from outside and are permissions too broad?Resource policies, trust policies, activityExternal account, public access, least privilege
AWS Well-Architected ToolDoes the workload follow architecture best practices?Workload and six pillarsArchitecture review, risk, milestone

High-frequency distinctions

PairHow to decide
CloudWatch vs CloudTrailPerformance, logs, and alarms → CloudWatch; API actions → CloudTrail.
CloudTrail vs ConfigActor and API → CloudTrail; before/after configuration and compliance → Config.
Artifact vs Audit ManagerAWS reports and agreements → Artifact; customer-environment evidence → Audit Manager.
Config vs Audit ManagerConfiguration records and rules → Config; multi-source evidence organized by framework → Audit Manager.
Organizations vs Control TowerAccounts, OUs, SCPs, and billing → Organizations; landing zone, Account Factory, and controls → Control Tower.
Service Catalog vs MarketplaceEnterprise-approved product catalog → Service Catalog; third-party software/data marketplace → Marketplace.
Service Catalog vs License ManagerWhat may be deployed → Service Catalog; how many licenses may be used → License Manager.
AWS Health vs CloudWatchOfficial AWS events and maintenance → Health; your resource metrics, logs, and alarms → CloudWatch.
Trusted Advisor vs Well-Architected ToolAutomated checks and account recommendations → Trusted Advisor; questionnaire-based workload review → Well-Architected Tool.
Trusted Advisor vs IAM Access AnalyzerBroad optimization recommendations → Trusted Advisor; external access and least-privilege analysis → Access Analyzer.

Scenario quick reference

  • CPU over 80% triggers notification or scaling → CloudWatch Alarm + SNS / Auto Scaling.
  • Find who deleted an EC2 instance → CloudTrail.
  • Continuously require S3 buckets to remain private → AWS Config rule.
  • An auditor requests an AWS SOC report → AWS Artifact.
  • Collect PCI audit evidence automatically → AWS Audit Manager.
  • Manage accounts centrally and set boundaries with SCPs → AWS Organizations.
  • Apply a landing zone to new accounts → AWS Control Tower.
  • Developers deploy only approved templates → AWS Service Catalog.
  • Track BYOL and prevent license overuse → AWS License Manager.
  • Confirm instance retirement or an AWS-side event → AWS Health Dashboard.
  • Find idle resources, root MFA risks, and quota pressure → AWS Trusted Advisor.
  • Detect an S3 bucket or role shared externally → IAM Access Analyzer.

Key takeaway

Watch runtime, Trail actions, Config configuration; Artifact provides AWS materials, Audit Manager collects customer evidence; Organizations manages accounts, Control Tower governs the landing zone; Catalog controls products, License Manager licenses; Health reports AWS events, Trusted Advisor recommends, and Access Analyzer checks permissions.