AWS Security Checks
Browse our comprehensive catalog of 577 security checks organized by category.
ACM
Imported and ACM-issued certificates should be renewed after a specified time period
Flags ACM certificates — both imported and AWS-managed — that are within 30 days of expiration and require renewal.
RSA certificates managed by ACM should use a key length of at least 2,048 bits
Verifies that RSA certificates managed by ACM use a key length of at least 2,048 bits, as shorter keys are considered cryptographically weak.
ACM certificates should be tagged
Flags ACM certificates that have no user-defined tags. Tags help with ownership, cost allocation, and incident triage; certificates without any non-sy...
APIGateway
API Gateway REST and WebSocket API execution logging should be enabled
Ensures all stages of an API Gateway REST or WebSocket API have logging enabled at the ERROR or INFO level for all methods.
API Gateway REST API stages should be configured to use SSL certificates for backend authentication
Confirms that API Gateway REST API stages have SSL certificates configured for backend authentication.
API Gateway REST API stages should have AWS X-Ray tracing enabled
Verifies that AWS X-Ray active tracing is enabled for API Gateway REST API stages.
API Gateway should be associated with a WAF Web ACL
Verifies that API Gateway stages are protected by an AWS WAF web ACL.
API Gateway REST API cache data should be encrypted at rest
Verifies that API Gateway REST API stages with caching enabled store cached data encrypted at rest.
API Gateway routes should specify an authorization type
Confirms that API Gateway routes have an authorization type specified.
Access logging should be configured for API Gateway V2 Stages
Confirms that API Gateway V2 stages have access logging configured.
API Gateway V2 integrations should use HTTPS for private connections
Flags API Gateway V2 (HTTP and WebSocket) integrations whose private VPC link connections do not have a TLS configuration. Without TLS, traffic betwee...
API Gateway domain names should use recommended security policies
Flags API Gateway custom domain names that are configured with the legacy TLS_1_0 security policy. TLS_1_0 is deprecated and exposes client traffic to...
Account
Security contact information should be provided for an AWS account
Verifies that the AWS account has security contact information configured.
AWS account should be part of an AWS Organizations organization
Confirms that the AWS account is a member of an organization managed through AWS Organizations.
Amplify
Amplify apps should be tagged
Flags AWS Amplify apps that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged apps are o...
Amplify branches should be tagged
Flags AWS Amplify branches that have no user-defined tags. Tags help with environment classification, cost allocation, and incident triage; untagged b...
AppConfig
AWS AppConfig applications should be tagged
Flags AWS AppConfig applications that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged ...
AWS AppConfig configuration profiles should be tagged
Flags AWS AppConfig configuration profiles that have no user-defined tags. Tags help associate profiles with their owning team, environment, and cost ...
AWS AppConfig environments should be tagged
Flags AWS AppConfig environments that have no user-defined tags. Tags help associate environments with their stage (prod, staging) and owning team; un...
AWS AppConfig extension associations should be tagged
Flags AWS AppConfig extension associations that have no user-defined tags. Tags help associate the extension binding with its owning team and use case...
AppFlow
Amazon AppFlow flows should be tagged
Flags Amazon AppFlow flows that have no user-defined tags. Tags help associate flows with their owning team, environment, and cost centre; untagged fl...
AppRunner
App Runner services should be tagged
Flags AWS App Runner services that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged ser...
App Runner VPC connectors should be tagged
Flags AWS App Runner VPC connectors that have no user-defined tags. Tags help associate connectors with their consuming services and owning team; unta...
AppSync
AWS AppSync API caches should be encrypted at rest
Flags AWS AppSync API caches that are not configured for encryption at rest. Encrypting cached query results protects any sensitive data the cache may...
AWS AppSync should have field-level logging enabled
Verifies that AWS AppSync APIs have both request-level and field-level logging enabled.
AWS AppSync GraphQL APIs should be tagged
Flags AWS AppSync GraphQL APIs that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged AP...
AWS AppSync GraphQL APIs should not be authenticated with API keys
Flags AppSync GraphQL APIs that use API key authentication. API keys are hard-coded values that, if compromised, expose the endpoint to unauthorized a...
AWS AppSync API caches should be encrypted in transit
Flags AWS AppSync API caches that are not configured for encryption in transit. Without transit encryption, traffic between AppSync and its cache inst...
Athena
Athena data catalogs should be tagged
Flags Amazon Athena data catalogs that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged...
Athena workgroups should be tagged
Flags Amazon Athena workgroups that have no user-defined tags. Tags help associate workgroups with their owning team, environment, and cost centre; un...
Athena workgroups should have logging enabled
Verifies that Amazon Athena workgroups have logging enabled.
AutoScaling
Auto scaling groups associated with a load balancer should use ELB health checks
Confirms that Auto Scaling groups associated with Classic Load Balancers or target groups use ELB health checks. Groups without load balancer associat...
Amazon EC2 Auto Scaling group should cover multiple Availability Zones
Ensures Auto Scaling groups span multiple Availability Zones for fault tolerance.
Auto Scaling group launch configurations should configure EC2 instances to require Instance Metadata Service Version 2 (IMDSv2)
Verifies that Auto Scaling group launch configurations require EC2 instances to use IMDSv2.
Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses
Flags Auto Scaling group launch configurations that assign public IP addresses to EC2 instances.
Auto Scaling groups should use multiple instance types in multiple Availability Zones
Ensures Auto Scaling groups are configured to use multiple instance types across multiple Availability Zones.
EC2 Auto Scaling groups should use EC2 launch templates
Verifies that Auto Scaling groups use EC2 launch templates instead of launch configurations.
EC2 Auto Scaling groups should be tagged
Flags Amazon EC2 Auto Scaling groups that have no user-defined tags. Tags help associate ASGs with their owning team, environment, and cost centre; un...
Backup
AWS Backup recovery points should be encrypted at rest
Verifies that AWS Backup recovery points are encrypted at rest.
AWS Backup recovery points should be tagged
Flags AWS Backup recovery points that have no user-defined tags. Tags help associate recovery points with the owning team, environment, and retention ...
AWS Backup vaults should be tagged
Flags AWS Backup vaults that have no user-defined tags. Tags help associate vaults with their owning team, environment, and retention policy; untagged...
AWS Backup report plans should be tagged
Flags AWS Backup report plans that have no user-defined tags. Tags help associate report plans with the owning team and compliance program; untagged r...
AWS Backup backup plans should be tagged
Flags AWS Backup backup plans that have no user-defined tags. Tags help associate backup plans with the owning team, environment, and policy lineage; ...
Batch
Batch job queues should be tagged
Flags AWS Batch job queues that have no user-defined tags. Tags help associate queues with their owning team, environment, and cost centre; untagged q...
Batch scheduling policies should be tagged
Flags AWS Batch scheduling policies that have no user-defined tags. Tags help associate policies with their owning team and use case; untagged policie...
Batch compute environments should be tagged
Flags AWS Batch compute environments that have no user-defined tags at the environment level. Tags help associate environments with their owning team,...
Compute resources properties in managed Batch compute environments should be tagged
Flags managed AWS Batch compute environments whose computeResources block has no user-defined tags. These tags are propagated to EC2 instances launche...
Bedrock
Amazon Bedrock data sources should be encrypted with customer managed AWS KMS keys
Flags Amazon Bedrock knowledge-base data sources not encrypted at rest with a customer-managed KMS key. Without a serverSideEncryptionConfiguration.km...
BedrockAgentCore
Bedrock AgentCore runtimes should be configured with VPC network mode
Flags Amazon Bedrock AgentCore runtimes whose network mode is set to PUBLIC. PUBLIC runtimes communicate over the internet and bypass VPC controls; pr...
Bedrock AgentCore Gateways should require authorization for inbound requests
Flags Amazon Bedrock AgentCore gateways that do not require authorization for inbound requests. Without inbound authorization the gateway is reachable...
Bedrock AgentCore Memory should be encrypted with customer managed AWS KMS keys
Flags Amazon Bedrock AgentCore Memory resources that are not encrypted at rest with a KMS key you manage. Without an encryptionKeyArn the memory relie...
Bedrock AgentCore Gateway should be encrypted with customer managed AWS KMS keys
Flags Amazon Bedrock AgentCore Gateways not encrypted at rest with a KMS key you manage. Without a kmsKeyArn the gateway relies on the default AWS-own...
Bedrock AgentCore custom browsers should not use public network mode
Flags Amazon Bedrock AgentCore custom browsers configured with PUBLIC network mode. Public browsers reach the internet directly and bypass VPC control...
Bedrock AgentCore custom browsers should have session recording enabled
Flags Amazon Bedrock AgentCore custom browsers without session recording to an S3 destination. Recording provides an audit trail of browser-tool activ...
Bedrock AgentCore custom code interpreters should use a private network configuration
Flags Amazon Bedrock AgentCore custom code interpreters that use PUBLIC or SANDBOX network mode instead of a private VPC configuration. Only VPC mode ...
CloudFormation
CloudFormation stacks should be tagged
Flags AWS CloudFormation stacks that have no user-defined tags. Stack tags propagate to provisioned resources and are the primary way to associate the...
CloudFormation stacks should have termination protection enabled
Flags AWS CloudFormation stacks that do not have termination protection enabled. Without termination protection, a stack can be deleted by anyone with...
CloudFormation stacks should have associated service roles
Flags AWS CloudFormation stacks that do not have a service role associated. Without an explicit service role, the stack uses the calling principal...
CloudFront
CloudFront distributions should have a default root object configured
Confirms that CloudFront distributions are configured to return a specific default root object.
CloudFront distributions should require encryption in transit
Ensures CloudFront distributions require viewers to use HTTPS for all connections.
CloudFront distributions should have origin failover configured
Confirms that CloudFront distributions have an origin group with two or more origins configured for failover.
CloudFront distributions should have logging enabled
Verifies that server access logging is enabled for CloudFront distributions.
CloudFront distributions should have WAF enabled
Confirms that CloudFront distributions are associated with an AWS WAF Classic or WAF web ACL.
CloudFront distributions should use custom SSL/TLS certificates
Verifies that CloudFront distributions use custom SSL/TLS certificates rather than the default CloudFront certificate.
CloudFront distributions should use SNI to serve HTTPS requests
Flags CloudFront distributions that use a dedicated IP address for SSL/TLS instead of SNI, which is the recommended and more cost-efficient approach.
CloudFront distributions should encrypt traffic to custom origins
Flags CloudFront distributions that do not encrypt traffic to custom origins — specifically those with an http-only origin protocol policy, or match-v...
CloudFront distributions should not use deprecated SSL protocols between edge locations and custom origins
Flags CloudFront distributions that use deprecated SSL protocols for HTTPS communication with custom origins.
CloudFront distributions should not point to non-existent S3 origins
Detects CloudFront distributions pointing to S3 origins that no longer exist.
CloudFront distributions should use origin access control
Verifies that CloudFront distributions with S3 origins use origin access control (OAC) to restrict direct S3 access.
CloudFront distributions should be tagged
Flags Amazon CloudFront distributions that have no user-defined tags. Tags help associate distributions with their owning team, environment, and cost ...
CloudFront distributions should use the recommended TLS security policy
Ensures CloudFront distributions use the recommended TLS security policy for secure viewer connections.
CloudFront distributions should use origin access control for Lambda function URL origins
Flags Amazon CloudFront distributions that use AWS Lambda function URLs as origins without origin access control (OAC) enabled. Without OAC, the Lambd...
CloudFront distributions should use trusted key groups for signed URLs and cookies
Flags Amazon CloudFront distributions that authenticate signed URLs or signed cookies using legacy trusted signers. Trusted signers rely on root accou...
CloudTrail
CloudTrail should be enabled and configured with at least one multi-Region trail that includes read and write management events
Ensures at least one multi-Region CloudTrail trail exists with the ExcludeManagementEventSources parameter empty on at least one of those trails.
CloudTrail should have encryption at-rest enabled
Verifies that CloudTrail trails use server-side encryption with an AWS KMS key.
At least one CloudTrail trail should be enabled
Verifies that at least one CloudTrail trail is enabled in the AWS account.
CloudTrail log file validation should be enabled
Ensures CloudTrail log file integrity validation is enabled, allowing detection of tampering with delivered log files.
CloudTrail trails should be integrated with Amazon CloudWatch Logs
Confirms that CloudTrail trails deliver logs to CloudWatch Logs for centralized monitoring and alerting.
Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible
Flags S3 buckets used to store CloudTrail logs that are publicly accessible.
Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
Verifies that the S3 bucket storing CloudTrail logs has server access logging enabled to capture all requests made to the bucket.
CloudTrail trails should be tagged
Flags AWS CloudTrail trails that have no user-defined tags. Tags help associate trails with their owning team, environment, and compliance program; un...
CloudTrail Lake event data stores should be encrypted with customer managed AWS KMS keys
Confirms that CloudTrail Lake event data stores are encrypted at rest with a customer managed KMS key.
CloudWatch
CloudWatch alarms should have specified actions configured
Verifies that CloudWatch alarms have an action configured for the ALARM state.
CloudWatch log groups should be retained for a specified time period
Confirms that CloudWatch log groups have a retention policy set to at least 365 days.
CloudWatch alarm actions should be enabled
Ensures CloudWatch alarms have actions enabled so they trigger the configured response when a state change occurs.
CodeArtifact
CodeArtifact repositories should be tagged
Flags AWS CodeArtifact repositories that have no user-defined tags. Tags help associate repositories with their owning team and language ecosystem; un...
CodeBuild
CodeBuild Bitbucket source repository URLs should not contain sensitive credentials
Ensures CodeBuild projects use OAuth for GitHub or Bitbucket source repository authentication rather than personal access tokens or username/password ...
CodeBuild project environment variables should not contain clear text credentials
Detects clear-text credentials (such as AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, PASSWORD, or TOKEN) stored in CodeBuild project environment variable...
CodeBuild S3 logs should be encrypted
Verifies that S3 log storage for CodeBuild projects has encryption enabled.
CodeBuild project environments should have a logging configuration
Verifies that CodeBuild project environments have at least one log destination enabled — either S3 or CloudWatch Logs.
CodeBuild report group exports should be encrypted at rest
Confirms that CodeBuild report group test results exported to S3 are encrypted at rest.
CodeGuruProfiler
CodeGuru Profiler profiling groups should be tagged
Flags Amazon CodeGuru Profiler profiling groups that have no user-defined tags. Tags help associate profiling groups with their application, owning te...
CodeGuruReviewer
CodeGuru Reviewer repository associations should be tagged
Flags Amazon CodeGuru Reviewer repository associations that have no user-defined tags. Tags help associate reviewer associations with their owning tea...
Cognito
Cognito user pools should have threat protection activated with full function enforcement mode for standard authentication
Verifies that Cognito user pools have advanced security enabled and set to full enforcement mode, not audit mode.
Cognito identity pools should not allow unauthenticated identities
Flags Cognito identity pools that allow unauthenticated (guest) identities by having AllowUnauthenticatedIdentities set to true.
Password policies for Cognito user pools should have strong configurations
Flags Amazon Cognito user pools whose password policy does not meet the recommended baseline (8+ chars, requires upper/lower case, number, symbol, and...
Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication
Flags Amazon Cognito user pools whose threat protection is not activated in full function (ENFORCED) mode for custom authentication. Audit-only mode l...
MFA should be enabled for Cognito user pools
Flags Amazon Cognito user pools that authenticate users with passwords but do not require multi-factor authentication. The control is in scope when th...
Cognito user pools should have deletion protection enabled
Flags Amazon Cognito user pools that do not have deletion protection enabled. Without deletion protection, a single DeleteUserPool call removes the po...
Connect
Amazon Connect Customer Profiles object types should be tagged
Flags Amazon Connect Customer Profiles object types that have no user-defined tags. Tags help associate object types with their owning team and integr...
Amazon Connect instances should have CloudWatch logging enabled
Confirms that Amazon Connect instances store flow logs in a CloudWatch log group. Flow logs provide real-time details about events in Connect flows, a...
DMS
Database Migration Service replication instances should not be public
Flags DMS replication instances that are publicly accessible. Replication instances should have private IP addresses and not be reachable outside the ...
DMS certificates should be tagged
Flags AWS DMS certificates that have no user-defined tags. Tags help associate certificates with their owning team and use case; untagged certificates...
DMS event subscriptions should be tagged
Flags AWS DMS event subscriptions that have no user-defined tags. Tags help associate subscriptions with their owning team and downstream pager; untag...
DMS replication instances should be tagged
Flags AWS DMS replication instances that have no user-defined tags. Tags help associate replication instances with their owning team and migration pro...
DMS replication subnet groups should be tagged
Flags AWS DMS replication subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; untagged...
DMS replication instances should have automatic minor version upgrade enabled
Ensures automatic minor version upgrade is enabled for DMS replication instances, keeping them current with bug fixes, security patches, and performan...
DMS replication tasks for the target database should have logging enabled
Confirms that DMS replication tasks have logging enabled at LOGGER_SEVERITY_DEFAULT or higher for TARGET_APPLY and TARGET_LOAD operations.
DMS replication tasks for the source database should have logging enabled
Verifies that DMS replication tasks have logging enabled at LOGGER_SEVERITY_DEFAULT or higher for SOURCE_CAPTURE and SOURCE_UNLOAD components.
DMS endpoints should use SSL
Confirms that AWS DMS endpoints use SSL connections, encrypting data in transit and validating the target database's server certificate during mi...
DMS endpoints for Neptune databases should have IAM authorization enabled
Verifies that AWS DMS endpoints for Neptune databases use IAM authorization, enabling fine-grained access control through a service access role.
DMS endpoints for MongoDB should have an authentication mechanism enabled
Confirms that AWS DMS endpoints for MongoDB have an authentication mechanism enabled. Without authentication, unauthorized users could access data dur...
DMS endpoints for Redis OSS should have TLS enabled
Ensures AWS DMS endpoints for Redis OSS use TLS connections, encrypting data in transit to prevent eavesdropping during migration.
DMS replication instances should be configured to use multiple Availability Zones
Flags AWS DMS replication instances that are not deployed in a Multi-AZ configuration. Single-AZ replication instances interrupt migrations during AZ-...
DataSync
DataSync tasks should have logging enabled
Verifies that AWS DataSync tasks have logging enabled. Audit logs record system activity, support incident investigation, and help meet regulatory com...
DataSync tasks should be tagged
Flags AWS DataSync tasks that have no user-defined tags. Tags help associate tasks with their owning team, environment, and data lineage; untagged tas...
Detective
Detective behavior graphs should be tagged
Flags Amazon Detective behavior graphs that have no user-defined tags. Tags help associate graphs with their owning team and incident-response program...
DocumentDB
Amazon DocumentDB clusters should be encrypted at rest
Verifies that DocumentDB clusters are encrypted at rest using AES-256 with encryption keys managed by AWS KMS.
Amazon DocumentDB clusters should have an adequate backup retention period
Ensures DocumentDB clusters have a backup retention period of at least 7 days, supporting recovery from accidental deletion, corruption, and other dat...
Amazon DocumentDB manual cluster snapshots should not be public
Flags DocumentDB manual cluster snapshots that are publicly accessible, which exposes data to all AWS accounts.
Amazon DocumentDB clusters should publish audit logs to CloudWatch Logs
Verifies that DocumentDB clusters publish audit logs to CloudWatch Logs. Audit logging captures authentication attempts, collection drops, index creat...
Amazon DocumentDB clusters should have deletion protection enabled
Confirms that DocumentDB clusters have deletion protection enabled, preventing accidental or unauthorized deletion.
Amazon DocumentDB clusters should be encrypted in transit
Ensures DocumentDB clusters require TLS for all client connections. Non-TLS connections are not permitted, protecting data in transit from interceptio...
DynamoDB
DynamoDB tables should automatically scale capacity with demand
Verifies that DynamoDB tables can scale read and write capacity automatically, either through on-demand mode or provisioned mode with auto scaling con...
DynamoDB tables should have point-in-time recovery enabled
Confirms that point-in-time recovery (PITR) is enabled for DynamoDB tables, providing automated backups and the ability to recover from accidental wri...
DynamoDB Accelerator (DAX) clusters should be encrypted at rest
Verifies that DAX clusters are encrypted at rest, reducing the risk of unauthorized access to data stored on disk.
DynamoDB tables should be present in a backup plan
Verifies that DynamoDB tables are included in an AWS Backup plan.
DynamoDB tables should be tagged
Flags Amazon DynamoDB tables that have no user-defined tags. Tags help associate tables with their owning team, environment, and cost centre; untagged...
DynamoDB tables should have deletion protection enabled
Ensures DynamoDB tables have deletion protection enabled to prevent accidental removal during regular table management operations.
DynamoDB Accelerator clusters should be encrypted in transit
Confirms that DynamoDB Accelerator (DAX) clusters use TLS endpoint encryption, protecting data in transit against interception.
EC2
EBS snapshots should not be configured to be publicly restorable
Flags EBS snapshots that are configured to be publicly restorable.
VPC default security groups should not allow inbound or outbound traffic
Confirms that the default VPC security group does not allow any inbound or outbound traffic.
Attached EBS volumes should be encrypted at-rest
Confirms that attached EBS volumes are encrypted at rest.
Stopped EC2 instances should be removed after a specified time period
Flags stopped EC2 instances that have remained stopped beyond the allowed time period.
VPC flow logging should be enabled in all VPCs
Verifies that VPC flow logging is enabled in all VPCs.
EBS default encryption should be enabled
Verifies that EBS default encryption is enabled for the account.
EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)
Verifies that EC2 instances use IMDSv2, which requires session-oriented authentication for instance metadata requests.
EC2 instances should not have a public IPv4 address
Flags EC2 instances that have a public IPv4 address assigned.
Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service
Confirms that EC2 instances use VPC endpoints for the EC2 service, keeping traffic within the AWS network.
Unused EC2 EIPs should be removed
Flags Elastic IP addresses that are unassociated and no longer in use.
Security groups should not allow ingress from 0.0.0.0/0 or ::/0 to port 22
Flags security groups that allow unrestricted SSH access (port 22) from 0.0.0.0/0.
Security groups should not allow ingress from 0.0.0.0/0 or ::/0 to port 3389
Flags security groups that allow unrestricted RDP access (port 3389) from 0.0.0.0/0.
EC2 subnets should not automatically assign public IP addresses
Flags EC2 subnets configured to automatically assign public IPv4 addresses or IPv6 addresses to instances at launch.
Unused Network Access Control Lists should be removed
Flags Network ACLs that are not associated with any subnet.
EC2 instances should not use multiple ENIs
Flags EC2 instances using multiple Elastic Network Interfaces, which can create complex network configurations and unintended routing.
Security groups should only allow unrestricted incoming traffic for authorized ports
Verifies that security groups only permit unrestricted inbound traffic on explicitly authorized ports.
Security groups should not allow unrestricted access to ports with high risk
Flags security groups that allow unrestricted inbound access to high-risk ports.
Both VPN tunnels for an AWS Site-to-Site VPN connection should be up
Verifies that both tunnels for AWS Site-to-Site VPN connections are up.
Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 3389
Flags Network ACLs that allow unrestricted ingress from 0.0.0.0/0 to SSH (port 22) or RDP (port 3389).
Unused EC2 security groups should be removed
Flags security groups not attached to any EC2 instance or elastic network interface.
EC2 Transit Gateways should not automatically accept VPC attachment requests
Confirms that EC2 Transit Gateways do not automatically accept VPC attachment requests.
EC2 paravirtual instance types should not be used
Detects EC2 instances using paravirtual (PV) virtualization, a legacy type with fewer features and security controls than HVM.
EC2 launch templates should not assign public IPs to network interfaces
Flags EC2 launch templates configured to assign public IP addresses to network interfaces.
EBS volumes should be in a backup plan
Confirms that EBS volumes are covered by an AWS Backup plan.
EC2 transit gateway attachments should be tagged
Flags transit gateway attachments that have no user-defined tags. Tags help associate them with their owning team and use case; untagged transit gatew...
EC2 transit gateway route tables should be tagged
Flags transit gateway route tables that have no user-defined tags. Tags help associate them with their owning team and use case; untagged transit gate...
EC2 network interfaces should be tagged
Flags EC2 network interface that have no user-defined tags. Tags help associate network interfaces with their owning team and use case; untagged netwo...
EC2 customer gateways should be tagged
Flags customer gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged customer gateways are o...
EC2 Elastic IP addresses should be tagged
Flags EC2 Elastic IP address that have no user-defined tags. Tags help associate Elastic IP addresses with their owning team and use case; untagged El...
EC2 instances should be tagged
Flags EC2 instance that have no user-defined tags. Tags help associate instances with their owning team and use case; untagged instances are operation...
EC2 internet gateways should be tagged
Flags internet gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged internet gateways are o...
EC2 NAT gateways should be tagged
Flags NAT gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged NAT gateways are operational...
EC2 network ACLs should be tagged
Flags EC2 network ACL that have no user-defined tags. Tags help associate network ACLs with their owning team and use case; untagged network ACLs are ...
EC2 route tables should be tagged
Flags EC2 route table that have no user-defined tags. Tags help associate route tables with their owning team and use case; untagged route tables are ...
EC2 security groups should be tagged
Flags EC2 security group that have no user-defined tags. Tags help associate security groups with their owning team and use case; untagged security gr...
EC2 subnets should be tagged
Flags EC2 subnet that have no user-defined tags. Tags help associate subnets with their owning team and use case; untagged subnets are operationally o...
EC2 volumes should be tagged
Flags EC2 volume that have no user-defined tags. Tags help associate volumes with their owning team and use case; untagged volumes are operationally o...
Amazon VPCs should be tagged
Flags VPC that have no user-defined tags. Tags help associate VPCs with their owning team and use case; untagged VPCs are operationally opaque.
Amazon VPC endpoint services should be tagged
Flags VPC endpoint services that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPC endpoint servic...
Amazon VPC flow logs should be tagged
Flags VPC flow log that have no user-defined tags. Tags help associate VPC flow logs with their owning team and use case; untagged VPC flow logs are o...
Amazon VPC peering connections should be tagged
Flags VPC peering connections that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPC peering conne...
EC2 VPN gateways should be tagged
Flags VPN gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPN gateways are operational...
EC2 Client VPN endpoints should have client connection logging enabled
Ensures Client VPN endpoints have client connection logging enabled.
EC2 transit gateways should be tagged
Flags EC2 transit gateway that have no user-defined tags. Tags help associate transit gateways with their owning team and use case; untagged transit g...
EC2 security groups should not allow ingress from 0.0.0.0/0 to remote server administration ports
Flags EC2 security groups that allow inbound traffic from 0.0.0.0/0 to the SSH (22) or RDP (3389) remote-administration ports. Public exposure of thes...
EC2 security groups should not allow ingress from ::/0 to remote server administration ports
Flags EC2 security groups that allow inbound traffic from ::/0 to the SSH (22) or RDP (3389) remote-administration ports. Public IPv6 exposure of thes...
VPCs should be configured with an interface endpoint for ECR API
Verifies that VPC interface endpoints are available for the Amazon ECR API.
VPCs should be configured with an interface endpoint for Docker Registry
Confirms that VPC interface endpoints are available for the Amazon ECR Docker registry.
VPCs should be configured with an interface endpoint for Systems Manager
Verifies that VPC interface endpoints are available for AWS Systems Manager.
VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts
Confirms that VPC interface endpoints are available for SSM Incident Manager Contacts.
VPCs should be configured with an interface endpoint for Systems Manager Incident Manager
Verifies that VPC interface endpoints are available for SSM Incident Manager.
EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)
Confirms that the default version of EC2 launch templates requires IMDSv2 for instance metadata access.
EC2 VPN connections should have logging enabled
Ensures EC2 VPN connections have logging configured.
EC2 VPC Block Public Access settings should block internet gateway traffic
Verifies that VPC Block Public Access settings are configured to block internet gateway traffic.
EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes
Confirms that EC2 Spot Fleet requests with launch parameters have encryption enabled on all attached EBS volumes.
EC2 DHCP option sets should be tagged
Flags DHCP option sets that have no user-defined tags. Tags help associate them with their owning team and use case; untagged DHCP option sets are ope...
EC2 launch templates should be tagged
Flags EC2 launch template that have no user-defined tags. Tags help associate launch templates with their owning team and use case; untagged launch te...
EC2 prefix lists should be tagged
Flags EC2 prefix list that have no user-defined tags. Tags help associate prefix lists with their owning team and use case; untagged prefix lists are ...
EC2 traffic mirror sessions should be tagged
Flags traffic mirror sessions that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror se...
EC2 traffic mirror filters should be tagged
Flags traffic mirror filters that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror fil...
EC2 traffic mirror targets should be tagged
Flags traffic mirror targets that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror tar...
EC2 network interfaces should have source/destination checking enabled
Verifies that source/destination checking is enabled for EC2 elastic network interfaces.
EC2 launch templates should enable encryption for attached EBS volumes
Flags EC2 launch templates whose latest version defines block device mappings without enabling EBS encryption. Templates that launch unencrypted EBS v...
Block public access settings should be enabled for Amazon EBS snapshots
Flags accounts/regions where EBS snapshot block public access is set to 'unblocked'. Without BPA, any snapshot can be made public (intention...
EC2 VPN connections should use IKEv2 protocol
Flags AWS Site-to-Site VPN connections whose tunnels do not support IKEv2. IKEv1 is the legacy keying protocol; tunnels should support IKEv2 at minimu...
ECR
ECR private repositories should have image scanning configured
Verifies that private ECR repositories have image scanning configured.
ECR private repositories should have tag immutability configured
Confirms that private ECR repositories have tag immutability enabled, preventing image tags from being overwritten.
ECR repositories should have at least one lifecycle policy configured
Ensures ECR repositories have at least one lifecycle policy configured to manage image retention.
ECR public repositories should be tagged
Flags Amazon ECR Public repositories that have no user-defined tags. Tags help associate repositories with their owning team and product; untagged pub...
ECR repositories should be encrypted with customer managed AWS KMS keys
Verifies that ECR repositories are encrypted at rest with a customer managed KMS key.
ECS
ECS services should not have public IP addresses assigned to them automatically
Flags ECS services configured to automatically assign public IP addresses (AssignPublicIP set to ENABLED).
ECS task definitions should not share the host's process namespace
Flags ECS task definitions configured to share the host's process namespace with their containers.
ECS containers should run as non-privileged
Flags ECS task definitions with containers that have the privileged parameter set to true.
ECS task definitions should configure containers to be limited to read-only access to root filesystems
Verifies that ECS task definitions configure containers with read-only access to their root filesystems. Task definitions targeting Windows containers...
Secrets should not be passed as container environment variables
Detects ECS containers that pass secrets (such as AWS_ACCESS_KEY_ID, PASSWORD, or TOKEN) as plain-text environment variables.
ECS task definitions should have a logging configuration
Confirms that the latest active ECS task definition has a logging configuration with a valid logDriver specified for all container definitions.
ECS Fargate services should run on the latest Fargate platform version
Verifies that ECS Fargate services are running the latest Fargate platform version.
ECS clusters should use Container Insights
Confirms that ECS clusters have Container Insights enabled for performance and operational monitoring.
ECS services should be tagged
Flags Amazon ECS services that have no user-defined tags. Tags help associate services with their owning team, environment, and cost centre; untagged ...
ECS clusters should be tagged
Flags Amazon ECS clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagged ...
ECS task definitions should be tagged
Flags Amazon ECS task definitions that have no user-defined tags. Tags help associate task definitions with their owning team, environment, and applic...
ECS task sets should not automatically assign public IP addresses
Flags ECS task sets configured to automatically assign public IP addresses (AssignPublicIP set to ENABLED).
ECS task definitions should not use host network mode
Flags the latest active revision of ECS task definitions that use host network mode, which shares the host's network namespace with the container
ECS Task Definitions should use in-transit encryption for EFS volumes
Flags Amazon ECS task definitions whose EFS volume configurations do not enable in-transit encryption. Without TLS, EFS traffic between the task and t...
ECS capacity providers should have managed termination protection enabled
Flags ECS capacity providers backed by Auto Scaling groups that do not have managed termination protection enabled. Without it, the ASG can terminate ...
ECS task definitions should configure non-root users in Linux container definitions
Flags Amazon ECS Linux task definitions whose container definitions do not set an explicit non-root user. Running containers as root grants the worklo...
ECS task definitions should configure non-administrator users in Windows container definitions
Flags Amazon ECS Windows task definitions whose container definitions do not set an explicit non-administrator user. Running as the default administra...
EFS
Elastic File System should be configured to encrypt file data at-rest using AWS KMS
Verifies that Amazon EFS file systems are configured to encrypt data at rest using AWS KMS.
Amazon EFS volumes should be in backup plans
Verifies that EFS file systems are included in an AWS Backup plan.
EFS access points should enforce a root directory
Verifies that EFS access points enforce a non-root directory path, preventing clients from accessing the entire file system root.
EFS access points should enforce a user identity
Confirms that EFS access points enforce a POSIX user identity, ensuring consistent user-level permissions for all file system operations.
EFS access points should be tagged
Flags Amazon EFS access points that have no user-defined tags. Tags help associate access points with their owning team and application; untagged acce...
EFS mount targets should not be associated with subnets that assign public IP addresses on launch
Flags EFS mount targets associated with subnets that automatically assign public IP addresses on instance launch.
EFS file systems should have automatic backups enabled
Ensures EFS file systems have automatic backups enabled.
EFS file systems should be encrypted at rest
Confirms that EFS file systems encrypt stored data at rest with AWS KMS.
EKS
EKS cluster endpoints should not be publicly accessible
Flags EKS cluster API server endpoints that are publicly accessible.
EKS clusters should run on a supported Kubernetes version
Confirms that EKS clusters run a supported Kubernetes version.
EKS clusters should use encrypted Kubernetes secrets
Verifies that EKS clusters use AWS KMS to encrypt Kubernetes secrets stored in etcd.
EKS clusters should be tagged
Flags Amazon EKS clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagged ...
EKS identity provider configurations should be tagged
Flags Amazon EKS identity provider configurations that have no user-defined tags. Tags help associate IdP bindings with their owning team and downstre...
EKS clusters should have audit logging enabled
Ensures EKS clusters have audit logging enabled to record API server activity.
EKS node groups should run on a supported Kubernetes version
Flags Amazon EKS node groups that run on a Kubernetes version older than the current AWS EKS standard support window. Extended-support versions miss b...
ELB
Application Load Balancer should be configured to redirect all HTTP requests to HTTPS
Ensures Application Load Balancers redirect all HTTP requests to HTTPS, enforcing encrypted connections.
Classic Load Balancers with SSL/HTTPS listeners should use a certificate provided by AWS Certificate Manager
Verifies that Classic Load Balancers with SSL/HTTPS listeners use certificates from AWS Certificate Manager, simplifying certificate management and re...
Classic Load Balancer listeners should be configured with HTTPS or TLS termination
Verifies that Classic Load Balancer listeners use HTTPS or TLS termination to encrypt traffic between clients and the load balancer.
Application load balancer should be configured to drop invalid http headers
Verifies that Application Load Balancers drop invalid HTTP headers, reducing the risk of header injection and malformed request issues.
Application and Classic Load Balancers logging should be enabled
Confirms that access logging is enabled for Application and Classic Load Balancers to capture detailed request information for audit and troubleshooti...
Application, Gateway, and Network Load Balancers should have deletion protection enabled
Confirms that deletion protection is enabled on Application Load Balancers, preventing accidental or unauthorized deletion.
Classic Load Balancers should have connection draining enabled
Verifies that connection draining is enabled on Classic Load Balancers, allowing in-flight requests to complete before instances are deregistered.
Classic Load Balancers with SSL listeners should use a predefined security policy that has strong configuration
Confirms that Classic Load Balancers with SSL listeners use a predefined security policy with strong cipher and protocol configurations.
Classic Load Balancers should have cross-zone load balancing enabled
Confirms that cross-zone load balancing is enabled for Classic Load Balancers, distributing traffic evenly across all registered instances in all enab...
Classic Load Balancer should span multiple Availability Zones
Ensures Classic Load Balancers span multiple Availability Zones for increased fault tolerance.
Application Load Balancer should be configured with defensive or strictest desync mitigation mode
Ensures Application Load Balancers use defensive or strictest desync mitigation mode to protect against HTTP desync attacks.
Application, Network and Gateway Load Balancers should span multiple Availability Zones
Ensures Application, Network, and Gateway Load Balancers span multiple Availability Zones for fault tolerance.
Classic Load Balancer should be configured with defensive or strictest desync mitigation mode
Ensures Classic Load Balancers with SSL/HTTPS listeners use defensive or strictest desync mitigation mode to protect against HTTP desync attacks.
Application Load Balancers should be associated with an AWS WAF web ACL
Confirms that Application Load Balancers are associated with an AWS WAF web ACL to protect against web exploits that could affect availability or cons...
Application and Network Load Balancers with listeners should use recommended security policies
Verifies that HTTPS listeners on ALBs and TLS listeners on NLBs use a recommended security policy for encrypting data in transit.
Application and Network Load Balancer listeners should use secure protocols to encrypt data in transit
Confirms that ALB listeners use HTTPS and NLB listeners use TLS for encrypted data transmission.
Application and Network Load Balancer target groups should use encrypted health check protocols
Flags ALB and NLB target groups whose health check protocol is not HTTPS. Health-check traffic sent over HTTP exposes endpoint paths and response bodi...
ELB target groups should use encrypted transport protocols
Flags Elastic Load Balancing target groups whose transport protocol is not encrypted. Pass criteria: HTTPS, TLS, or QUIC. Target types of Lambda or AL...
EMR
Amazon EMR cluster primary nodes should not have public IP addresses
Flags EMR cluster master nodes that have public IP addresses assigned.
Amazon EMR block public access setting should be enabled
Confirms that Amazon EMR Block Public Access is enabled for the account, and that no ports other than 22 are open to the public.
Amazon EMR security configurations should have encryption at rest enabled
Verifies that EMR security configurations have encryption at rest enabled.
Amazon EMR security configurations should have encryption in transit enabled
Ensures EMR security configurations have encryption in transit enabled.
ES
Elasticsearch domains should be tagged
Flags Amazon Elasticsearch Service domains that have no user-defined tags. Tags help associate domains with their owning team and use case; untagged d...
ElastiCache
ElastiCache (Redis OSS) clusters should have automatic backups enabled
Verifies that ElastiCache (Redis OSS) cache clusters and ElastiCache (Redis OSS or Valkey) replication groups have automatic backups scheduled with a ...
ElastiCache clusters should have automatic minor version upgrades enabled
Confirms that ElastiCache for Redis clusters automatically apply minor version upgrades.
ElastiCache replication groups should have automatic failover enabled
Ensures ElastiCache Redis replication groups have automatic failover enabled.
ElastiCache replication groups should be encrypted at rest
Verifies that ElastiCache Redis replication groups are encrypted at rest.
ElastiCache replication groups should be encrypted in transit
Verifies that ElastiCache Redis replication groups are encrypted in transit.
ElastiCache (Redis OSS) replication groups of earlier versions should have Redis OSS AUTH enabled
Confirms that ElastiCache Redis replication groups running versions below 6.0 have Redis AUTH enabled.
ElastiCache clusters should not use the default subnet group
Flags ElastiCache clusters using the default subnet group instead of a custom one.
ElasticBeanstalk
Elastic Beanstalk environments should have enhanced health reporting enabled
Verifies that enhanced health reporting is enabled for Elastic Beanstalk environments.
Elastic Beanstalk managed platform updates should be enabled
Ensures managed platform updates are enabled for Elastic Beanstalk environments.
Elastic Beanstalk should stream logs to CloudWatch
Confirms that Elastic Beanstalk environments stream logs to CloudWatch Logs.
Elasticsearch
Elasticsearch domains should have encryption at-rest enabled
Verifies that Elasticsearch domains have encryption at rest enabled on persistent volumes.
Elasticsearch domains should not be publicly accessible
Confirms that Elasticsearch domains are deployed within a VPC rather than publicly accessible.
Elasticsearch domains should encrypt data sent between nodes
Ensures Elasticsearch domains have node-to-node encryption enabled, securing data in transit within the cluster.
Elasticsearch domain error logging to CloudWatch Logs should be enabled
Verifies that Elasticsearch domains have error logging to CloudWatch Logs enabled.
Elasticsearch domains should have audit logging enabled
Confirms that Elasticsearch domains have audit logging enabled for security and compliance purposes.
Elasticsearch domains should have at least three data nodes
Ensures Elasticsearch domains are configured with at least three data nodes for high availability.
Elasticsearch domains should be configured with at least three dedicated master nodes
Verifies that Elasticsearch domains have at least three dedicated master nodes configured for cluster stability.
Connections to Elasticsearch domains should be encrypted using the latest TLS security policy
Ensures connections to Elasticsearch domains use the latest TLS protocol for secure data transmission.
EventBridge
EventBridge event buses should be tagged
Flags Amazon EventBridge event buses that have no user-defined tags. Tags help associate event buses with their owning team and integration; untagged ...
EventBridge custom event buses should have a resource-based policy attached
Confirms that custom EventBridge event buses have a resource-based policy attached to control access.
EventBridge global endpoints should have event replication enabled
Verifies that event replication is enabled for EventBridge global endpoints.
FSx
FSx for OpenZFS file systems should be configured to copy tags to backups and volumes
Confirms that FSx for OpenZFS file systems copy tags to backups and volumes, supporting resource categorization and governance.
FSx for Lustre file systems should be configured to copy tags to backups
Confirms that FSx for Lustre file systems copy tags to backups and volumes, supporting resource identification and governance.
FSx for OpenZFS file systems should be configured for Multi-AZ deployment
Verifies that FSx for OpenZFS file systems use the Multi-AZ deployment type for high availability across Availability Zones.
FSx for NetApp ONTAP file systems should be configured for Multi-AZ deployment
Ensures FSx for NetApp ONTAP file systems use a Multi-AZ deployment type for continuous availability even when an Availability Zone is unavailable.
FSx for Windows File Server file systems should be configured for Multi-AZ deployment
Ensures FSx for Windows File Server file systems use Multi-AZ deployment, distributing file servers across two Availability Zones for high availabilit...
FraudDetector
Amazon Fraud Detector entity types should be tagged
Flags Amazon Fraud Detector entity type that have no user-defined tags. Tags help associate Amazon Fraud Detector entity type with their owning team a...
Amazon Fraud Detector labels should be tagged
Flags Amazon Fraud Detector label that have no user-defined tags. Tags help associate Amazon Fraud Detector label with their owning team and use case;...
Amazon Fraud Detector outcomes should be tagged
Flags Amazon Fraud Detector outcome that have no user-defined tags. Tags help associate Amazon Fraud Detector outcome with their owning team and use c...
Amazon Fraud Detector variables should be tagged
Flags Amazon Fraud Detector variable that have no user-defined tags. Tags help associate Amazon Fraud Detector variable with their owning team and use...
GlobalAccelerator
Global Accelerator accelerators should be tagged
Flags AWS Global Accelerator accelerators that have no user-defined tags. Tags help associate accelerators with their owning team and downstream endpo...
Glue
AWS Glue jobs should be tagged
Flags AWS Glue jobs that have no user-defined tags. Tags help associate jobs with their owning team and data pipeline; untagged jobs are operationally...
AWS Glue machine learning transforms should be encrypted at rest
Verifies that AWS Glue machine learning transforms are encrypted at rest.
AWS Glue Spark jobs should run on supported versions of AWS Glue
Confirms that AWS Glue for Spark jobs run on a supported version of AWS Glue.
GuardDuty
GuardDuty should be enabled
Confirms that Amazon GuardDuty is enabled in the account and region.
GuardDuty filters should be tagged
Flags Amazon GuardDuty filters that have no user-defined tags. Tags help associate filters with their owning team and rationale; untagged filters are ...
GuardDuty IPSets should be tagged
Flags Amazon GuardDuty IPSets that have no user-defined tags. Tags help associate IPSets with their owning team and threat intelligence feed lineage; ...
GuardDuty detectors should be tagged
Flags Amazon GuardDuty detectors that have no user-defined tags. Tags help associate detectors with their owning team and account-organisation lineage...
GuardDuty EKS Audit Log Monitoring should be enabled
Confirms that GuardDuty EKS Audit Log Monitoring is enabled across all accounts. This feature analyzes Kubernetes audit logs to detect suspicious acti...
GuardDuty Lambda Protection should be enabled
Verifies that GuardDuty Lambda Protection is enabled across all accounts. Lambda Protection monitors network activity logs for Lambda invocations to i...
GuardDuty EKS Runtime Monitoring should be enabled
Ensures GuardDuty EKS Runtime Monitoring with automated agent management is enabled across all accounts, providing threat detection coverage for EKS w...
GuardDuty Malware Protection for EC2 should be enabled
Ensures GuardDuty Malware Protection is enabled across all accounts to detect malware on EBS volumes attached to EC2 instances and container workloads...
GuardDuty RDS Protection should be enabled
Confirms that GuardDuty RDS Protection is enabled across all accounts to analyze and profile RDS login activity for access threats to Aurora databases...
GuardDuty S3 Protection should be enabled
Ensures GuardDuty S3 Protection is enabled across all accounts to monitor object-level API operations and identify potential security risks in S3 buck...
GuardDuty Runtime Monitoring should be enabled
Verifies that GuardDuty Runtime Monitoring is enabled across all accounts, providing OS-level, network, and file event analysis to detect threats in A...
GuardDuty ECS Runtime Monitoring should be enabled
Verifies that the GuardDuty automated security agent is enabled for runtime monitoring of ECS clusters on AWS Fargate in all accounts.
GuardDuty EC2 Runtime Monitoring should be enabled
Ensures the GuardDuty automated security agent is enabled for EC2 runtime monitoring in all accounts. GuardDuty Runtime Monitoring observes OS-level, ...
IAM
IAM policies should not allow full "*" administrative privileges
Flags IAM policies that grant full administrative privileges by allowing all actions (Action: *) on all resources (Resource: *) with Effect: Allow.
IAM users should not have IAM policies attached
Flags IAM users with policies attached directly rather than through groups or roles.
IAM users' access keys should be rotated every 90 days or less
Verifies that IAM user access keys have been rotated within the last 90 days.
IAM root user access key should not exist
Confirms that no access keys exist for the IAM root user.
MFA should be enabled for all IAM users that have a console password
Verifies that MFA is enabled for all IAM users with a console password.
Hardware MFA should be enabled for the root user
Verifies that hardware MFA is enabled for the root user.
Password policies for IAM users should have strong configurations
Verifies that the IAM account password policy enforces strong password requirements.
Unused IAM user credentials should be removed
Flags IAM users whose passwords or access keys have not been used for 90 days. Removing unused credentials reduces the attack surface from abandoned o...
MFA should be enabled for the root user
Confirms that virtual MFA is enabled for the root user.
Ensure IAM password policy expires passwords within 90 days or less
Verifies that the IAM account password policy is configured to expire passwords within 90 days or fewer.
Ensure a support role has been created to manage incidents with AWS Support
Ensures a support role exists in the account for managing incidents with AWS Support.
IAM customer managed policies that you create should not allow wildcard actions for services
Flags IAM customer managed policies containing statements that allow Service:* or use NotAction: Service:* with Effect: Allow.
IAM user credentials unused for 45 days should be removed
Flags IAM users whose passwords or access keys have not been used in 45 or more days.
IAM Access Analyzer analyzers should be tagged
Flags IAM Access Analyzer analyzers that have no user-defined tags. Tags help associate analyzers with their owning team and scope; untagged analyzers...
IAM roles should be tagged
Flags IAM roles that have no user-defined tags. Tags help associate roles with their owning team and cost-attribution lineage; untagged roles are oper...
IAM users should be tagged
Flags IAM users that have no user-defined tags. Tags help associate users with their owning team and cost-attribution lineage; untagged users are oper...
Expired SSL/TLS certificates managed in IAM should be removed
Flags expired SSL/TLS server certificates still present and active in IAM.
IAM identities should not have the AWSCloudShellFullAccess policy attached
Flags IAM identities (users, roles, or groups) that have the AWSCloudShellFullAccess managed policy attached.
IAM Access Analyzer external access analyzer should be enabled
Confirms that the AWS account has an IAM Access Analyzer external access analyzer enabled in the current region.
IVS
IVS playback key pairs should be tagged
Flags Amazon IVS playback key pair that have no user-defined tags. Tags help associate Amazon IVS playback key pair with their owning team and use cas...
IVS recording configurations should be tagged
Flags Amazon IVS recording configuration that have no user-defined tags. Tags help associate Amazon IVS recording configuration with their owning team...
IVS channels should be tagged
Flags Amazon IVS channel that have no user-defined tags. Tags help associate Amazon IVS channel with their owning team and use case; untagged channels...
Identify
ActiveMQ brokers should stream audit logs to CloudWatch
Verifies that Amazon MQ ActiveMQ brokers stream audit logs to CloudWatch Logs, enabling alarm creation and increased visibility into security-related ...
MSK connectors should have logging enabled
Ensures logging is enabled for Amazon MSK connectors via at least one of CloudWatch Logs, S3, or Firehose.
Inspector
Amazon Inspector EC2 scanning should be enabled
Confirms that Amazon Inspector EC2 scanning is enabled in the account.
Amazon Inspector ECR scanning should be enabled
Verifies that Amazon Inspector ECR scanning is enabled in the account to detect software vulnerabilities in container images stored in ECR.
Amazon Inspector Lambda code scanning should be enabled
Ensures Amazon Inspector Lambda code scanning is enabled in the account.
Amazon Inspector Lambda standard scanning should be enabled
Confirms that Amazon Inspector Lambda standard scanning is enabled in the account.
IoT
AWS IoT Device Defender security profiles should be tagged
Flags IoT Device Defender security profile that have no user-defined tags. Tags help associate IoT Device Defender security profile with their owning ...
AWS IoT Core mitigation actions should be tagged
Flags IoT Core mitigation action that have no user-defined tags. Tags help associate IoT Core mitigation action with their owning team and use case; u...
AWS IoT Core dimensions should be tagged
Flags IoT Core dimension that have no user-defined tags. Tags help associate IoT Core dimension with their owning team and use case; untagged dimensio...
AWS IoT Core authorizers should be tagged
Flags IoT Core authorizer that have no user-defined tags. Tags help associate IoT Core authorizer with their owning team and use case; untagged author...
AWS IoT Core role aliases should be tagged
Flags IoT Core role alias that have no user-defined tags. Tags help associate IoT Core role alias with their owning team and use case; untagged role a...
AWS IoT Core policies should be tagged
Flags IoT Core policy that have no user-defined tags. Tags help associate IoT Core policy with their owning team and use case; untagged policies are o...
IoTEvents
AWS IoT Events inputs should be tagged
Flags IoT Events input that have no user-defined tags. Tags help associate IoT Events input with their owning team and use case; untagged inputs are o...
AWS IoT Events detector models should be tagged
Flags IoT Events detector model that have no user-defined tags. Tags help associate IoT Events detector model with their owning team and use case; unt...
AWS IoT Events alarm models should be tagged
Flags IoT Events alarm model that have no user-defined tags. Tags help associate IoT Events alarm model with their owning team and use case; untagged ...
IoTSiteWise
AWS IoT SiteWise asset models should be tagged
Flags IoT SiteWise asset model that have no user-defined tags. Tags help associate IoT SiteWise asset model with their owning team and use case; untag...
AWS IoT SiteWise dashboards should be tagged
Flags IoT SiteWise dashboard that have no user-defined tags. Tags help associate IoT SiteWise dashboard with their owning team and use case; untagged ...
AWS IoT SiteWise gateways should be tagged
Flags IoT SiteWise gateway that have no user-defined tags. Tags help associate IoT SiteWise gateway with their owning team and use case; untagged gate...
AWS IoT SiteWise portals should be tagged
Flags IoT SiteWise portal that have no user-defined tags. Tags help associate IoT SiteWise portal with their owning team and use case; untagged portal...
AWS IoT SiteWise projects should be tagged
Flags IoT SiteWise project that have no user-defined tags. Tags help associate IoT SiteWise project with their owning team and use case; untagged proj...
IoTTwinMaker
AWS IoT TwinMaker sync jobs should be tagged
Flags IoT TwinMaker sync job that have no user-defined tags. Tags help associate IoT TwinMaker sync job with their owning team and use case; untagged ...
AWS IoT TwinMaker workspaces should be tagged
Flags IoT TwinMaker workspace that have no user-defined tags. Tags help associate IoT TwinMaker workspace with their owning team and use case; untagge...
AWS IoT TwinMaker scenes should be tagged
Flags IoT TwinMaker scene that have no user-defined tags. Tags help associate IoT TwinMaker scene with their owning team and use case; untagged scenes...
AWS IoT TwinMaker entities should be tagged
Flags IoT TwinMaker entity that have no user-defined tags. Tags help associate IoT TwinMaker entity with their owning team and use case; untagged enti...
IoTWireless
AWS IoT Wireless multicast groups should be tagged
Flags IoT Wireless multicast group that have no user-defined tags. Tags help associate IoT Wireless multicast group with their owning team and use cas...
AWS IoT Wireless service profiles should be tagged
Flags IoT Wireless service profile that have no user-defined tags. Tags help associate IoT Wireless service profile with their owning team and use cas...
AWS IoT Wireless FUOTA tasks should be tagged
Flags IoT Wireless FUOTA task that have no user-defined tags. Tags help associate IoT Wireless FUOTA task with their owning team and use case; untagge...
KMS
IAM customer managed policies should not allow decryption actions on all KMS keys
Flags IAM customer managed policies that allow decrypt actions on all KMS keys, which could permit unauthorized decryption of sensitive data.
IAM principals should not have IAM inline policies that allow decryption actions on all KMS keys
Detects IAM customer managed policies that allow decryption on all KMS keys without restriction, which can lead to unauthorized access to encrypted da...
AWS KMS keys should not be deleted unintentionally
Flags AWS KMS keys scheduled for deletion, which may be unintentional.
AWS KMS key rotation should be enabled
Verifies that AWS KMS keys have automatic key rotation enabled.
Keyspaces
Amazon Keyspaces keyspaces should be tagged
Flags Amazon Keyspaces keyspaces that have no user-defined tags. Tags help associate keyspaces with their owning team and application; untagged keyspa...
Kinesis
Firehose delivery streams should be encrypted at rest
Ensures Firehose delivery streams are encrypted at rest using AWS KMS. Data is encrypted before being written to the stream's storage layer and d...
Kinesis streams should be encrypted at rest
Confirms that Kinesis Data Streams are encrypted at rest with server-side encryption.
Kinesis streams should be tagged
Flags Amazon Kinesis data streams that have no user-defined tags. Tags help associate streams with their owning team, environment, and producers/consu...
Kinesis streams should have an adequate data retention period
Verifies that Kinesis data streams have a data retention period of at least 168 hours (7 days).
Lambda
Lambda function policies should prohibit public access
Verifies that Lambda function resource-based policies do not grant public access from outside the account.
Lambda functions should use supported runtimes
Ensures Lambda functions use supported runtime versions for each language.
Lambda functions should be in a VPC
Confirms that Lambda functions are deployed within a VPC. Note: this check verifies VPC attachment only and does not evaluate subnet routing or public...
VPC Lambda functions should operate in multiple Availability Zones
Verifies that Lambda functions connected to a VPC are associated with subnets in more than one Availability Zone.
Lambda functions should be tagged
Flags AWS Lambda functions that have no user-defined tags. Tags help associate functions with their owning team, application, and cost centre; untagge...
Lambda functions should have AWS X-Ray active tracing enabled
Ensures active AWS X-Ray tracing is enabled for Lambda functions.
MQ
Amazon MQ brokers should be tagged
Flags Amazon MQ brokers that have no user-defined tags. Tags help associate brokers with their owning team and message consumers; untagged brokers are...
ActiveMQ brokers should use active/standby deployment mode
Ensures Amazon MQ ActiveMQ brokers use active/standby deployment mode for high availability. This configuration places two broker instances across two...
RabbitMQ brokers should use cluster deployment mode
Verifies that Amazon MQ RabbitMQ brokers use cluster deployment mode rather than single-instance deployment.
MSK
MSK clusters should have enhanced monitoring configured
Verifies that Amazon MSK clusters have enhanced monitoring enabled at PER_TOPIC_PER_BROKER level or higher.
Macie
Macie automated sensitive data discovery should be enabled
Verifies that automated sensitive data discovery is enabled for the Amazon Macie administrator account.
Neptune
Neptune DB clusters should be encrypted at rest
Confirms that Neptune DB clusters are encrypted at rest.
Neptune DB clusters should publish audit logs to CloudWatch Logs
Verifies that Neptune DB clusters publish audit logs to CloudWatch Logs.
Neptune DB cluster snapshots should not be public
Flags Neptune DB cluster snapshots that are publicly accessible.
Neptune DB clusters should have deletion protection enabled
Verifies that Neptune DB clusters have deletion protection enabled.
Neptune DB clusters should have automated backups enabled
Confirms that Neptune DB clusters have automated backups enabled with a retention period of at least 7 days.
Neptune DB cluster snapshots should be encrypted at rest
Confirms that Neptune DB cluster snapshots are encrypted at rest.
Neptune DB clusters should have IAM database authentication enabled
Verifies that Neptune DB clusters have IAM database authentication enabled.
Neptune DB clusters should be configured to copy tags to snapshots
Ensures Neptune DB clusters are configured to copy tags to snapshots.
Neptune DB clusters should be deployed across multiple Availability Zones
Ensures Neptune DB clusters are deployed across multiple Availability Zones.
NetworkFirewall
Network Firewall firewalls should be deployed across multiple Availability Zones
Ensures AWS Network Firewall firewalls are deployed across multiple Availability Zones.
Network Firewall logging should be enabled
Confirms that logging is enabled for AWS Network Firewall with at least one log destination configured.
Network Firewall firewalls should be tagged
Flags AWS Network Firewall firewalls that have no user-defined tags. Tags help associate firewalls with their owning team and VPC topology; untagged f...
Network Firewall firewall policies should be tagged
Flags AWS Network Firewall firewall policies that have no user-defined tags. Tags help associate policies with their owning team and intended traffic ...
Opensearch
OpenSearch domains should have encryption at rest enabled
Verifies that OpenSearch domains have encryption at rest enabled.
OpenSearch domains should not be publicly accessible
Confirms that OpenSearch domains are deployed within a VPC rather than exposed to the public internet.
OpenSearch domains should encrypt data sent between nodes
Confirms that OpenSearch domains have node-to-node encryption enabled to protect data in transit within the cluster.
OpenSearch domain error logging to CloudWatch Logs should be enabled
Verifies that OpenSearch domains have error logging to CloudWatch Logs enabled.
OpenSearch domains should have audit logging enabled
Ensures OpenSearch domains have audit logging enabled to record and track changes for security and compliance.
OpenSearch domains should have at least three data nodes
Verifies that OpenSearch domains are configured with at least three data nodes for high availability and resilience.
OpenSearch domains should have fine-grained access control enabled
Ensures OpenSearch domains have fine-grained access control enabled to restrict access to domain data and configurations.
Connections to OpenSearch domains should be encrypted using the latest TLS security policy
Ensures connections to OpenSearch domains use TLS for secure data transmission.
OpenSearch domains should be tagged
Flags Amazon OpenSearch Service domains that have no user-defined tags. Tags help associate domains with their owning team and data lineage; untagged ...
OpenSearch domains should have the latest software update installed
Confirms that OpenSearch Service domains have the latest available software update installed.
OpenSearch domains should have at least three dedicated primary nodes
Verifies that OpenSearch Service domains have at least three dedicated primary nodes configured for cluster stability.
PCA
AWS Private CA certificate authorities should be tagged
Flags AWS Private CA certificate authorities that have no user-defined tags. Tags help associate CAs with their owning team and trust hierarchy; untag...
PrivateCA
AWS Private CA root certificate authority should be disabled
Flags enabled root certificate authorities in AWS Private CA. Root CAs should remain disabled except when issuing certificates to subordinate CAs, to ...
Protect
MSK clusters should be encrypted in transit among broker nodes
Confirms that Amazon MSK clusters encrypt data in transit between broker nodes using TLS, with no plain-text connections permitted.
MSK Connect connectors should be encrypted in transit
Verifies that Amazon MSK Connect connectors encrypt data in transit.
Network Firewall policies should have at least one rule group associated
Verifies that Network Firewall policies have at least one stateful or stateless rule group associated.
Amazon MSK clusters should have public access disabled
Flags Amazon MSK clusters with public access enabled.
The default stateless action for Network Firewall policies should be drop or forward for full packets
Confirms that the default stateless action for full packets in Network Firewall policies is drop or forward, not pass.
The default stateless action for Network Firewall policies should be drop or forward for fragmented packets
Verifies that the default stateless action for fragmented packets in Network Firewall policies is drop or forward, not pass.
MSK clusters should disable unauthenticated access
Confirms that unauthenticated access is disabled for Amazon MSK clusters.
Stateless network firewall rule group should not be empty
Flags Network Firewall stateless rule groups that contain no rules.
Network Firewall firewalls should have deletion protection enabled
Verifies that AWS Network Firewall firewalls have deletion protection enabled.
Network Firewall firewalls should have subnet change protection enabled
Confirms that AWS Network Firewall firewalls have subnet change protection enabled.
RDS
RDS snapshot should be private
Confirms that RDS snapshots are private and not publicly shared.
RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration
Flags RDS DB instances that are publicly accessible.
RDS DB instances should have encryption at-rest enabled
Verifies that RDS DB instances have encryption at rest enabled.
RDS cluster snapshots and database snapshots should be encrypted at rest
Verifies that RDS cluster and database snapshots are encrypted at rest.
RDS DB instances should be configured with multiple Availability Zones
Confirms that RDS instances are configured with multiple Availability Zones.
Enhanced monitoring should be configured for RDS DB instances
Confirms that RDS instances have enhanced monitoring configured.
RDS clusters should have deletion protection enabled
Confirms that RDS clusters have deletion protection enabled.
RDS DB instances should have deletion protection enabled
Confirms that RDS instances have deletion protection enabled.
RDS DB instances should publish logs to CloudWatch Logs
Verifies that RDS instances have database logging to CloudWatch Logs enabled.
IAM authentication should be configured for RDS instances
Verifies that RDS instances have IAM authentication configured.
RDS instances should have automatic backups enabled
Ensures RDS instances have automatic backups enabled with a retention period of at least 7 days.
IAM authentication should be configured for RDS clusters
Confirms that RDS clusters have IAM database authentication enabled.
RDS automatic minor version upgrades should be enabled
Confirms that RDS instances have automatic minor version upgrades enabled.
Amazon Aurora clusters should have backtracking enabled
Confirms that Amazon Aurora clusters have backtracking enabled.
RDS DB clusters should be configured for multiple Availability Zones
Confirms that RDS DB clusters are configured across multiple Availability Zones.
Aurora DB clusters should be configured to copy tags to DB snapshots
Ensures RDS DB clusters are configured to copy tags to snapshots.
RDS DB instances should be configured to copy tags to snapshots
Verifies that RDS instances are configured to copy tags to snapshots.
Existing RDS event notification subscriptions should be configured for critical cluster events
Verifies that an RDS event subscription for DB clusters has notifications enabled for both maintenance and failure event categories.
Existing RDS event notification subscriptions should be configured for critical database instance events
Confirms that an RDS event subscription for DB instances has notifications enabled for maintenance, configuration change, and failure event categories...
An RDS event notifications subscription should be configured for critical database parameter group events
Verifies that an RDS event subscription is configured for critical database parameter group events.
An RDS event notifications subscription should be configured for critical database security group events
Confirms that an RDS event subscription is configured for critical database security group events.
RDS instances should not use a database engine default port
Flags standalone RDS instances (not cluster members) that use the default port for their database engine instead of a custom port.
RDS Database Clusters should use a custom administrator username
Flags RDS database clusters using default admin usernames such as admin, root, sa, oracle, or postgres.
RDS database instances should use a custom administrator username
Flags RDS database instances using default admin usernames such as admin, root, sa, oracle, or postgres.
RDS DB instances should be protected by a backup plan
Verifies that RDS DB instances have a backup retention period greater than zero.
RDS DB clusters should be encrypted at rest
Verifies that RDS DB clusters are encrypted at rest.
RDS DB clusters should be tagged
Flags Amazon RDS DB clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagg...
RDS DB cluster snapshots should be tagged
Flags Amazon RDS DB cluster snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; untag...
RDS DB instances should be tagged
Flags Amazon RDS DB instances that have no user-defined tags. Tags help associate instances with their owning team, environment, and cost centre; unta...
RDS DB security groups should be tagged
Flags legacy EC2-Classic RDS DB security groups that have no user-defined tags. EC2-Classic was retired in 2022; this control only emits findings in a...
RDS DB snapshots should be tagged
Flags Amazon RDS DB snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; untagged snap...
RDS DB subnet groups should be tagged
Flags Amazon RDS DB subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; untagged subne...
Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs
Verifies that Aurora MySQL DB clusters are configured to publish audit logs to CloudWatch Logs.
RDS DB clusters should have automatic minor version upgrade enabled
Ensures automatic minor version upgrade is enabled for RDS Multi-AZ DB clusters.
RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs
Verifies that RDS for PostgreSQL instances publish postgresql logs to CloudWatch Logs.
Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs
Verifies that Aurora PostgreSQL DB clusters publish postgresql logs to CloudWatch Logs.
RDS for PostgreSQL DB instances should be encrypted in transit
Ensures RDS for PostgreSQL instances enforce SSL connections via the rds.force_ssl parameter.
RDS for MySQL DB instances should be encrypted in transit
Confirms that RDS for MySQL instances require SSL connections via the require_ssl parameter.
RDS for SQL Server DB instances should publish logs to CloudWatch Logs
Verifies that RDS for SQL Server instances publish error logs to CloudWatch Logs.
RDS for SQL Server DB instances should be encrypted in transit
Confirms that RDS for SQL Server instances require SSL connections via the require_ssl parameter.
RDS for MariaDB DB instances should publish logs to CloudWatch Logs
Verifies that RDS for MariaDB instances publish error logs to CloudWatch Logs.
RDS DB proxies should require TLS encryption for connections
Flags Amazon RDS DB proxies that do not require TLS for client connections. Without RequireTLS, traffic between the client and the proxy traverses the...
RDS for MariaDB DB instances should be encrypted in transit
Confirms that RDS for MariaDB instances require SSL connections via the require_ssl parameter.
Aurora MySQL DB clusters should have audit logging enabled
Confirms that Aurora MySQL DB clusters have audit logging enabled via the server_audit_logs parameter.
RDS DB instances should not be deployed in public subnets with routes to internet gateways
Flags Amazon RDS DB instances whose subnet group includes at least one subnet with a default route to an Internet Gateway. Public subnets give the ins...
RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots
Flags PostgreSQL-engine RDS DB clusters whose CopyTagsToSnapshot is disabled. Without this setting, snapshots taken from the cluster lose ownership/co...
RDS for MySQL DB clusters should be configured to copy tags to DB snapshots
Flags MySQL-engine RDS DB clusters whose CopyTagsToSnapshot is disabled. Without this setting, snapshots taken from the cluster lose ownership/cost-al...
RDS DB clusters should have enough backup retention period set
Flags Amazon RDS DB clusters whose backup retention period is shorter than 7 days. A short retention window narrows the recovery point objective and r...
RDS global clusters should run on a supported Aurora MySQL version
Flags Amazon RDS global clusters running on an Aurora MySQL minor version older than the current AWS standard-support window. Extended-support version...
Redshift
Redshift Serverless workgroups should prohibit public access
Flags Redshift Serverless workgroups configured to allow public access.
Amazon Redshift clusters should prohibit public access
Flags Redshift clusters that are publicly accessible.
Connections to Amazon Redshift clusters should be encrypted in transit
Ensures connections to Redshift clusters require encryption in transit.
Connections to Redshift Serverless workgroups should be required to use SSL
Verifies that Redshift Serverless workgroups require SSL for all connections.
Amazon Redshift clusters should have automatic snapshots enabled
Confirms that Redshift clusters have automated snapshots enabled and retained for at least seven days.
Amazon Redshift Serverless workgroups should use enhanced VPC routing
Verifies that Redshift Serverless workgroups have enhanced VPC routing enabled.
Amazon Redshift clusters should have audit logging enabled
Verifies that Redshift clusters have audit logging enabled.
Amazon Redshift should have automatic upgrades to major versions enabled
Ensures automatic major version upgrades are enabled for Redshift clusters.
Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys
Confirms that Redshift Serverless namespaces use customer managed KMS keys for encryption.
Redshift clusters should use enhanced VPC routing
Confirms that Redshift clusters have Enhanced VPC Routing enabled to route COPY and UNLOAD traffic through the VPC.
Redshift Serverless namespaces should not use the default admin username
Confirms that Redshift Serverless namespaces use a non-default admin username.
Amazon Redshift clusters should not use the default Admin username
Flags Redshift clusters using the default admin username.
Redshift Serverless namespaces should export logs to CloudWatch Logs
Ensures Redshift Serverless namespaces export logs to CloudWatch Logs.
Redshift clusters should be encrypted at rest
Verifies that Redshift clusters are encrypted at rest.
Redshift clusters should be tagged
Flags Amazon Redshift clusters that have no user-defined tags. Tags help associate clusters with their owning team and data lineage; untagged clusters...
Redshift event notification subscriptions should be tagged
Flags Amazon Redshift event notification subscriptions that have no user-defined tags. Tags help associate subscriptions with their owning team and do...
Redshift cluster snapshots should be tagged
Flags Amazon Redshift cluster snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; unt...
Redshift cluster subnet groups should be tagged
Flags Amazon Redshift cluster subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; unta...
Redshift security groups should allow ingress on the cluster port only from restricted origins
Flags Redshift cluster security groups that allow unrestricted ingress (0.0.0.0/0 or ::/0) to the cluster port.
Redshift cluster subnet groups should have subnets from multiple Availability Zones
Verifies that Redshift cluster subnet groups contain subnets from at least two Availability Zones.
Redshift cluster parameter groups should be tagged
Flags Amazon Redshift cluster parameter groups that have no user-defined tags. Tags help associate parameter groups with their owning team and policy ...
Redshift clusters should have Multi-AZ deployments enabled
Confirms that Multi-AZ deployment is enabled for Redshift clusters.
RedshiftServerless
Amazon Redshift Serverless workgroups should use enhanced VPC routing
Flags Amazon Redshift Serverless workgroups that do not have enhanced VPC routing enabled. Without it, COPY/UNLOAD traffic between the workgroup and o...
Redshift Serverless workgroups should prohibit public access
Flags Amazon Redshift Serverless workgroups whose publiclyAccessible setting is true. Public workgroups receive a public IP address and are reachable ...
Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys
Flags Amazon Redshift Serverless namespaces that are not encrypted with a customer-managed KMS key. AWS-owned and AWS-managed keys cannot be audited v...
Redshift Serverless namespaces should not use the default admin username
Flags Amazon Redshift Serverless namespaces whose admin username matches the AWS default. The default is well known and removing it reduces the value ...
Redshift Serverless namespaces should export logs to CloudWatch Logs
Flags Amazon Redshift Serverless namespaces that do not export user, connection, and user-activity logs to CloudWatch. Without these exports, detectio...
Route53
Route 53 health checks should be tagged
Flags Amazon Route 53 health checks that have no user-defined tags. Tags help associate health checks with their owning team and dependent application...
Route 53 public hosted zones should log DNS queries
Confirms that DNS query logging is enabled for Route 53 public hosted zones.
S3
S3 general purpose buckets should have block public access settings enabled
Confirms that the S3 Block Public Access setting is enabled at the account level.
S3 general purpose buckets should block public read access
Verifies that S3 buckets block public read access through both ACLs and bucket policies, including policies granting s3:GetObject or wildcard actions ...
S3 general purpose buckets should block public write access
Confirms that S3 buckets block public write access through both ACLs and bucket policies.
S3 general purpose buckets should require requests to use SSL
Ensures S3 buckets require all requests to use SSL.
S3 general purpose bucket policies should restrict access to other AWS accounts
Flags S3 bucket policies that grant overly permissive access to other AWS accounts.
S3 general purpose buckets should use cross-Region replication
Verifies that S3 buckets have cross-Region replication enabled.
S3 general purpose buckets should block public access
Ensures Block Public Access settings are enabled at the individual S3 bucket level.
S3 general purpose buckets should have server access logging enabled
Verifies that S3 bucket server access logging is enabled.
S3 general purpose buckets with versioning enabled should have Lifecycle configurations
Confirms that versioned S3 buckets have a lifecycle configuration to manage non-current object versions.
S3 general purpose buckets should have event notifications enabled
Verifies that S3 general purpose buckets have event notifications enabled.
ACLs should not be used to manage user access to S3 general purpose buckets
Flags S3 buckets that use ACLs to manage user access, which should be replaced with bucket policies.
S3 general purpose buckets should have Lifecycle configurations
Confirms that S3 buckets have lifecycle policies configured for object management.
S3 general purpose buckets should have versioning enabled
Verifies that S3 buckets have versioning enabled.
S3 general purpose buckets should have Object Lock enabled
Confirms that S3 buckets are configured to use Object Lock for immutable storage.
S3 general purpose buckets should be encrypted at rest with AWS KMS keys
Confirms that S3 buckets are encrypted at rest using AWS KMS keys.
S3 access points should have block public access settings enabled
Verifies that S3 access points have all Block Public Access settings enabled.
S3 general purpose buckets should have MFA delete enabled
Verifies that MFA delete is enabled for S3 general purpose buckets, requiring multi-factor authentication for object deletion.
S3 general purpose buckets should log object-level write events
Confirms that at least one CloudTrail multi-Region trail is configured to log all S3 object write events.
S3 general purpose buckets should log object-level read events
Verifies that at least one CloudTrail multi-Region trail is configured to log all S3 object read events.
S3 Multi-Region Access Points should have block public access settings enabled
Verifies that S3 Multi-Region Access Points have Block Public Access settings enabled.
S3 directory buckets should have lifecycle configurations
Ensures S3 directory buckets have lifecycle rules configured.
SES
SES contact lists should be tagged
Flags Amazon SES contact lists that have no user-defined tags. Tags help associate contact lists with their owning team and campaign; untagged contact...
SES configuration sets should be tagged
Flags Amazon SES configuration sets that have no user-defined tags. Tags help associate configuration sets with their owning team and use case; untagg...
SES configuration sets should have TLS enabled for sending emails
Flags Amazon SES configuration sets whose delivery options do not require TLS. When TLS is optional, SES falls back to unencrypted SMTP whenever the r...
SNS
SNS topics should be encrypted at-rest using AWS KMS
Verifies that SNS topics are encrypted at rest using a KMS key.
SNS topics should be tagged
Flags Amazon SNS topics that have no user-defined tags. Tags help associate topics with their owning team and downstream subscribers; untagged topics ...
SNS topic access policies should not allow public access
Flags SNS topic access policies that allow public access.
SQS
Amazon SQS queues should be encrypted at rest
Confirms that SQS queues are encrypted at rest using SSE-SQS or an AWS KMS key.
SQS queues should be tagged
Flags Amazon SQS queues that have no user-defined tags. Tags help associate queues with their owning team and message producers/consumers; untagged qu...
SQS queue access policies should not allow public access
Flags SQS queue access policies that allow public access.
SSM
EC2 instances should be managed by AWS Systems Manager
Confirms that EC2 instances are managed by AWS Systems Manager.
EC2 instances managed by Systems Manager should have a patch compliance status of COMPLIANT after a patch installation
Verifies that Systems Manager patch compliance on EC2 instances shows a compliant status.
EC2 instances managed by Systems Manager should have an association compliance status of COMPLIANT
Verifies that Systems Manager associations on EC2 instances are in a compliant state.
SSM documents should not be public
Flags account-owned SSM documents that are publicly shared, which may expose sensitive configuration information.
SSM documents should be tagged
Flags AWS Systems Manager documents that have no user-defined tags. Tags help associate documents with their owning team and use case; untagged docume...
SSM Automation should have CloudWatch logging enabled
Verifies that CloudWatch logging is enabled for AWS Systems Manager Automation.
SSM documents should have the block public sharing setting enabled
Ensures the block public sharing setting is enabled for SSM documents.
SageMaker
Amazon SageMaker notebook instances should not have direct internet access
Confirms that direct internet access is disabled for SageMaker notebook instances.
SageMaker notebook instances should be launched in a custom VPC
Ensures SageMaker notebook instances are launched within a custom VPC.
Users should not have root access to SageMaker notebook instances
Flags SageMaker notebook instances that have root access enabled.
SageMaker endpoint production variants should have an initial instance count greater than 1
Confirms that SageMaker endpoint production variants are configured with more than one initial instance to avoid single points of failure.
SageMaker models should have network isolation enabled
Verifies that SageMaker hosted models have network isolation enabled, preventing the model container from making outbound network calls.
SageMaker app image configurations should be tagged
Flags SageMaker app image configuration that have no user-defined tags. Tags help associate SageMaker app image configuration with their owning team a...
SageMaker images should be tagged
Flags SageMaker image that have no user-defined tags. Tags help associate SageMaker image with their owning team and use case; untagged images are ope...
SageMaker notebook instances should run on supported platforms
Verifies that SageMaker notebook instances are configured to run on a supported platform version.
SageMaker data quality job definitions should have inter-container traffic encryption enabled
Flags Amazon SageMaker data quality monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled. Without it, traf...
SageMaker model explainability job definitions should have inter-container traffic encryption enabled
Flags Amazon SageMaker model-explainability monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.
SageMaker data quality job definitions should have network isolation enabled
Flags Amazon SageMaker data quality monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the container...
SageMaker model bias job definitions should have network isolation enabled
Flags Amazon SageMaker model-bias monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled.
SageMaker model quality job definitions should have inter-container traffic encryption enabled
Flags Amazon SageMaker model-quality monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.
SageMaker monitoring schedules should have network isolation enabled
Flags Amazon SageMaker monitoring schedules whose underlying job definition has NetworkConfig.EnableNetworkIsolation disabled. The schedule inherits t...
SageMaker model bias job definitions should have inter-container traffic encryption enabled
Flags Amazon SageMaker model-bias monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.
SageMaker models should use private registry in VPC for primary containers
Flags SageMaker models whose PrimaryContainer pulls images via the public ECR endpoint rather than a private-VPC registry. Setting ImageConfig.Reposit...
SageMaker feature group offline stores should be encrypted with AWS KMS keys
Flags Amazon SageMaker feature groups whose offline store does not specify a KMS key. Without an explicit KmsKeyId, the underlying S3 storage relies o...
SageMaker feature group online stores with standard storage should be encrypted with AWS KMS keys
Flags Amazon SageMaker feature groups whose online store uses standard storage without a KMS key. Without an explicit KmsKeyId the online store relies...
SageMaker models should use private registry in VPC for multi-container inference pipelines
Flags SageMaker inference-pipeline models whose Containers[] pull images via the public ECR endpoint. Every container in the pipeline must set ImageCo...
SageMaker model explainability job definitions should have network isolation enabled
Flags Amazon SageMaker model explainability monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the c...
SageMaker notebook instances should be encrypted with customer managed AWS KMS keys
Flags Amazon SageMaker notebook instances that have no KMS key configured for storage-volume encryption. Without a KmsKeyId the volume is encrypted wi...
SageMaker monitoring schedules should have inter-container traffic encryption enabled
Flags Amazon SageMaker monitoring schedules whose underlying job definition does not enable inter-container traffic encryption. Traffic between distri...
SageMaker inference experiments should have instance storage volume encrypted with customer managed AWS KMS keys
Flags Amazon SageMaker inference experiments with no KMS key for instance-storage-volume encryption. Without a key the ML storage volume relies on the...
SageMaker inference experiments should have data storage encrypted with customer managed AWS KMS keys
Flags Amazon SageMaker inference experiments that capture data but specify no KMS key for the captured data at rest. Applies only when data storage ca...
SageMaker model quality job definitions should have network isolation enabled
Flags Amazon SageMaker model quality monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the containe...
SecretsManager
Secrets Manager secrets should have automatic rotation enabled
Verifies that secrets stored in Secrets Manager are configured for automatic rotation.
Secrets Manager secrets configured with automatic rotation should rotate successfully
Confirms that Secrets Manager secrets have rotated successfully according to their rotation schedule.
Remove unused Secrets Manager secrets
Flags secrets that have not been accessed within 90 days, indicating they may be stale or unused.
Secrets Manager secrets should be rotated within a specified number of days
Flags secrets that have not been rotated within the last 90 days.
Secrets Manager secrets should be tagged
Flags AWS Secrets Manager secrets that have no user-defined tags. Tags help associate secrets with their owning team and consuming application; untagg...
ServiceCatalog
Service Catalog portfolios should be shared within an AWS organization only
Confirms that Service Catalog portfolios are shared only within the AWS organization when Organizations integration is enabled.
StepFunctions
Step Functions state machines should have logging turned on
Confirms that Step Functions state machines have logging enabled.
Step Functions activities should be tagged
Flags AWS Step Functions activities that have no user-defined tags. Tags help associate activities with their owning team and consuming state machine;...
Transfer
Transfer Family workflows should be tagged
Flags AWS Transfer Family workflows that have no user-defined tags. Tags help associate workflows with their owning team and trading partner; untagged...
Transfer Family servers should not use FTP protocol for endpoint connection
Flags Transfer Family servers that use FTP for endpoint connections. FTP transmits data in plaintext and should be replaced with SFTP or FTPS.
Transfer Family connectors should have logging enabled
Verifies that CloudWatch logging is enabled for AWS Transfer Family connectors.
Transfer Family agreements should be tagged
Flags AWS Transfer Family agreements that have no user-defined tags. Tags help associate AS2 agreements with their owning team and trading partner; un...
Transfer Family certificates should be tagged
Flags AWS Transfer Family certificates that have no user-defined tags. Tags help associate certificates with their owning team and trading partner; un...
Transfer Family connectors should be tagged
Flags AWS Transfer Family connectors that have no user-defined tags. Tags help associate connectors with their owning team and trading partner; untagg...
Transfer Family profiles should be tagged
Flags AWS Transfer Family profiles that have no user-defined tags. Tags help associate AS2 profiles (local and partner) with their owning team and tra...
WAF
AWS WAF Classic Global Web ACL logging should be enabled
Verifies that logging is enabled for AWS WAF global web ACLs.
AWS WAF Classic Regional rules should have at least one condition
Verifies that AWS WAF Regional rules contain at least one condition.
AWS WAF Classic Regional rule groups should have at least one rule
Confirms that AWS WAF Regional rule groups contain at least one rule.
AWS WAF Classic Regional web ACLs should have at least one rule or rule group
Confirms that AWS WAF Regional web ACLs contain at least one rule or rule group.
AWS WAF Classic global rules should have at least one condition
Confirms that AWS WAF global rules contain at least one condition.
AWS WAF Classic global rule groups should have at least one rule
Verifies that AWS WAF global rule groups contain at least one rule.
AWS WAF Classic global web ACLs should have at least one rule or rule group
Confirms that AWS WAF global web ACLs contain at least one rule or rule group.
AWS WAF web ACLs should have at least one rule or rule group
Confirms that WAFv2 web ACLs contain at least one rule or rule group.
AWS WAF rules should have CloudWatch metrics enabled
Ensures CloudWatch metrics are enabled for AWS WAF rules and rule groups.
WorkSpaces
WorkSpaces user volumes should be encrypted at rest
Verifies that WorkSpaces user volumes are encrypted at rest.
WorkSpaces root volumes should be encrypted at rest
Confirms that WorkSpaces root volumes are encrypted at rest.