AWSPlatform ChangesRetrospectives

re:Invent 2022: Amazon Security Lake and Verified Access Previews

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.

At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.

Amazon Security Lake

Security Lake automatically centralizes security data from AWS services (CloudTrail, VPC Flow Logs, Route 53 resolver logs, Security Hub findings and more), third-party sources and custom sources into a data lake in your account, stored in S3.

Its key feature was standardization on the Open Cybersecurity Schema Framework (OCSF) — an open schema developed by AWS, Splunk and other vendors so security data from different tools could be queried consistently. Analytics tools and SIEMs could subscribe to the data rather than each ingesting it separately.

It became generally available in May 2023.

AWS Verified Access

Verified Access provided secure access to corporate applications without a VPN, evaluating each request against identity (from IAM Identity Center or a third-party IdP) and device posture signals. It became generally available in 2023.

Why it mattered

Security Lake reflected a shift in security data management: instead of sending everything to an expensive SIEM, keep data in a lake you own, in an open format, and query it with the tool that fits. Verified Access brought zero trust application access natively into AWS.

In hindsight

The "security data lake" idea spread across the industry. Microsoft added a Sentinel data lake tier in 2025, and many SIEM vendors adopted OCSF. Organizations now balance hot analytics (expensive, fast) with cheaper long-term storage — a design decision that directly affects security budgets.

amazon security lakere:Invent 2022 Security Lake2022

More on this story