This document discusses frameworks and best practices for building a highly secure cloud environment on AWS and Azure. It covers the Cloud Adoption Framework (CAF), Well Architected Framework (WAF), game days, reference implementations, and industry organizations. It also provides details on security perspectives, pillars, principles, and recommended preventative, detective, and enforcing controls on AWS. The conclusion emphasizes iterating security controls over time, using detective controls for incident response, leveraging AWS services to supplement existing controls, and choosing from frameworks to meet an organization's specific needs.