AWS security groups act as a virtual firewall for your EC2 instances to control inbound and outbound traffic.
"Security groups act at the instance level, not the subnet level. Therefore, each instance in a subnet in your VPC could be assigned to a different set of security groups." - AWS Documentation
Trawling through your VPC flow logs helps provide visibility into your network traffic to detect anomalous traffic and provides insights, however, it still comes with its own risk of error.
Generating a visual diagram from the source of truth with automated layouts to display your network infrastructure as it is right now can eliminate the potential risk of human error.
Hava offers several ways to assist with diagnosing security within your network.