re:Invent 2022: Amazon Security Lake and Verified Access Previews
Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.
At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.
Amazon Security Lake
Security Lake automatically centralizes security data from AWS services (CloudTrail, VPC Flow Logs, Route 53 resolver logs, Security Hub findings and more), third-party sources and custom sources into a data lake in your account, stored in S3.
Its key feature was standardization on the Open Cybersecurity Schema Framework (OCSF) — an open schema developed by AWS, Splunk and other vendors so security data from different tools could be queried consistently. Analytics tools and SIEMs could subscribe to the data rather than each ingesting it separately.
It became generally available in May 2023.
AWS Verified Access
Verified Access provided secure access to corporate applications without a VPN, evaluating each request against identity (from IAM Identity Center or a third-party IdP) and device posture signals. It became generally available in 2023.
Why it mattered
Security Lake reflected a shift in security data management: instead of sending everything to an expensive SIEM, keep data in a lake you own, in an open format, and query it with the tool that fits. Verified Access brought zero trust application access natively into AWS.
In hindsight
The "security data lake" idea spread across the industry. Microsoft added a Sentinel data lake tier in 2025, and many SIEM vendors adopted OCSF. Organizations now balance hot analytics (expensive, fast) with cheaper long-term storage — a design decision that directly affects security budgets.
- How to Centralize AWS Security Logs With Amazon Security Lake How-To & Hardening
- Security Lake Source and Retention Planning Checklist How-To & Hardening
- CIO Brief: Owning Your Security Data — The OCSF Shift CIO Briefings