Status: OUT
AWS default configurations systematically favor ease-of-use over security across operations (console/CLI auto-scaling drift), auditing (90-day retention, no data events), and access control (legacy S3 ACLs enabled) — hardening must be applied across ALL dimensions because each has independent default gaps.