Get a Demo
Under Attack?
AWS Well-Architected Framework

AWS Well-Architected Framework Available in Upwind

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Sam Langrock June 12, 2026

Continuous Compliance for Cloud Security Teams

The AWS Well-Architected Framework is now available in Upwind. The framework helps organizations evaluate architectural decisions and align workloads with AWS best practices across 6 pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.

The Well-Architected Framework was designed by AWS as a consistent way for teams to evaluate their cloud workloads against proven architectural best practices. Organizations use it to identify risks early, reduce technical debt, and make more informed decisions about how their infrastructure is built and maintained.

By bringing this framework into Upwind, customers can continuously assess cloud environments against architectural best practices, better understand architectural gaps, and prioritize improvements directly within their security posture workflows.

aws-well-architected-framework-mock-a-scaled

What’s Included in Upwind?

You get full visibility into AWS Well-Architected categories, controls, compliance status, finding severity, and impacted assets, all inside Upwind’s Configurations module. 

Compliance scores per control. View the percentage of scanned resources compliant with a control, the number of compliant vs. non-compliant assets, and a breakdown of the severity of findings generated by the controls (e.g., High, Critical, and Other). 

aws-well-architected-framework-mock-b-scaled

Control-level detail. To learn more about a specific control or investigate specific issues you can click into any control to access greater detail, such as when a violation was last detected, its severity, and its risk category.

Compliance trends over time. The statistics tab shows whether you’re improving or drifting on any given control. Users can select a time frame and toggle compliance types to better match requirements. 

Violating controls. View related controls from the AWS Well-Architected Framework or others, such as NIST CSF, DORA, PCI-DSS and more, along with their respective compliance status.

aws-well-architected-framework-mock-e-scaled

Control status. Analyze your compliance status for a specific control. View counts and percentages of compliant vs non-compliant assets, and filter on non-compliant assets to investigate further. 

Finding Details. Evaluate the risk of specific security aspects for a given resource type. Findings explain why a resource is non-compliant by identifying the specific configuration leading to a security risk. 

aws-well-architected-framework-mock-d

Remediation guidance. Learn how to resolve your security issues and bring your environment into compliance with the control. Step-by-step guidance per asset type is provided. Pick the remediation method that works for your environment.

Who Benefits from Access to this Framework?

Security and platform teams get a continuously updated view of where their AWS environment stands against an AWS-authored benchmark, without waiting for a manual review cycle.

For security engineers, it means architectural gaps and security findings live in the same place. No switching tools to cross-reference a Well-Architected violation with an active misconfiguration.

For CISOs and security leaders, the framework provides a credible, structured way to report on architectural risk to leadership. Here’s where we stand, here’s what we’ve fixed, here’s what’s still open.

Upwind and AWS

Upwind is an AWS Security Competency partner, supports 100+ integrations with AWS services, and is one of a select few vendors on AWS Security Hub Extended, meaning your Well-Architected findings sit inside a broader AWS security ecosystem that’s deeply integrated with how Upwind works.

To learn more about our AWS partnership, visit our AWS partner page

Or read about how Upwind is one of the select few vendors that’s integrated into AWS Security Hub Extended.

Contents

Further Reading

KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…
Security Feed - Threat

No npm Token Required: Inside the AsyncAPI Supply Chain Attack

Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…