- Avoid using root credentials
- Turn on cloudtrail
- Turn on config recorder
- Cloudtrail data events over S3 logs
- DynamoDB over SimpleDB
- S3-IA or S3 standard over RRS. Note pricing for RRS is higher than S3 Standard in some regions
- S3-IA over S3 standard for objects > 71235 bytes and not accessed or objects > 128KB and accessed 1.5x/month or less
- ALB over ELB: ELB may still be needed for L4 balancing
- OpsWorks for Chef Automate over OpsWorks stacks: unless you have extreme cost sensitivity