Security Checks

AWS Security Checks

Browse our comprehensive catalog of 577 security checks organized by category.

ACM

Medium
Imported and ACM-issued certificates should be renewed after a specified time period

Flags ACM certificates — both imported and AWS-managed — that are within 30 days of expiration and require renewal.

High
RSA certificates managed by ACM should use a key length of at least 2,048 bits

Verifies that RSA certificates managed by ACM use a key length of at least 2,048 bits, as shorter keys are considered cryptographically weak.

Low
ACM certificates should be tagged

Flags ACM certificates that have no user-defined tags. Tags help with ownership, cost allocation, and incident triage; certificates without any non-sy...

APIGateway

Medium
API Gateway REST and WebSocket API execution logging should be enabled

Ensures all stages of an API Gateway REST or WebSocket API have logging enabled at the ERROR or INFO level for all methods.

Medium
API Gateway REST API stages should be configured to use SSL certificates for backend authentication

Confirms that API Gateway REST API stages have SSL certificates configured for backend authentication.

Low
API Gateway REST API stages should have AWS X-Ray tracing enabled

Verifies that AWS X-Ray active tracing is enabled for API Gateway REST API stages.

Medium
API Gateway should be associated with a WAF Web ACL

Verifies that API Gateway stages are protected by an AWS WAF web ACL.

Medium
API Gateway REST API cache data should be encrypted at rest

Verifies that API Gateway REST API stages with caching enabled store cached data encrypted at rest.

Medium
API Gateway routes should specify an authorization type

Confirms that API Gateway routes have an authorization type specified.

Medium
Access logging should be configured for API Gateway V2 Stages

Confirms that API Gateway V2 stages have access logging configured.

Medium
API Gateway V2 integrations should use HTTPS for private connections

Flags API Gateway V2 (HTTP and WebSocket) integrations whose private VPC link connections do not have a TLS configuration. Without TLS, traffic betwee...

Medium
API Gateway domain names should use recommended security policies

Flags API Gateway custom domain names that are configured with the legacy TLS_1_0 security policy. TLS_1_0 is deprecated and exposes client traffic to...

Account

Medium
Security contact information should be provided for an AWS account

Verifies that the AWS account has security contact information configured.

High
AWS account should be part of an AWS Organizations organization

Confirms that the AWS account is a member of an organization managed through AWS Organizations.

Amplify

Low
Amplify apps should be tagged

Flags AWS Amplify apps that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged apps are o...

Low
Amplify branches should be tagged

Flags AWS Amplify branches that have no user-defined tags. Tags help with environment classification, cost allocation, and incident triage; untagged b...

AppConfig

Low
AWS AppConfig applications should be tagged

Flags AWS AppConfig applications that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged ...

Low
AWS AppConfig configuration profiles should be tagged

Flags AWS AppConfig configuration profiles that have no user-defined tags. Tags help associate profiles with their owning team, environment, and cost ...

Low
AWS AppConfig environments should be tagged

Flags AWS AppConfig environments that have no user-defined tags. Tags help associate environments with their stage (prod, staging) and owning team; un...

Low
AWS AppConfig extension associations should be tagged

Flags AWS AppConfig extension associations that have no user-defined tags. Tags help associate the extension binding with its owning team and use case...

AppFlow

Low
Amazon AppFlow flows should be tagged

Flags Amazon AppFlow flows that have no user-defined tags. Tags help associate flows with their owning team, environment, and cost centre; untagged fl...

AppRunner

Low
App Runner services should be tagged

Flags AWS App Runner services that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged ser...

Low
App Runner VPC connectors should be tagged

Flags AWS App Runner VPC connectors that have no user-defined tags. Tags help associate connectors with their consuming services and owning team; unta...

AppSync

Medium
AWS AppSync API caches should be encrypted at rest

Flags AWS AppSync API caches that are not configured for encryption at rest. Encrypting cached query results protects any sensitive data the cache may...

Medium
AWS AppSync should have field-level logging enabled

Verifies that AWS AppSync APIs have both request-level and field-level logging enabled.

Low
AWS AppSync GraphQL APIs should be tagged

Flags AWS AppSync GraphQL APIs that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged AP...

High
AWS AppSync GraphQL APIs should not be authenticated with API keys

Flags AppSync GraphQL APIs that use API key authentication. API keys are hard-coded values that, if compromised, expose the endpoint to unauthorized a...

Medium
AWS AppSync API caches should be encrypted in transit

Flags AWS AppSync API caches that are not configured for encryption in transit. Without transit encryption, traffic between AppSync and its cache inst...

Athena

Low
Athena data catalogs should be tagged

Flags Amazon Athena data catalogs that have no user-defined tags. Tags help with ownership attribution, cost allocation, and incident triage; untagged...

Low
Athena workgroups should be tagged

Flags Amazon Athena workgroups that have no user-defined tags. Tags help associate workgroups with their owning team, environment, and cost centre; un...

Medium
Athena workgroups should have logging enabled

Verifies that Amazon Athena workgroups have logging enabled.

AutoScaling

Low
Auto scaling groups associated with a load balancer should use ELB health checks

Confirms that Auto Scaling groups associated with Classic Load Balancers or target groups use ELB health checks. Groups without load balancer associat...

Medium
Amazon EC2 Auto Scaling group should cover multiple Availability Zones

Ensures Auto Scaling groups span multiple Availability Zones for fault tolerance.

High
Auto Scaling group launch configurations should configure EC2 instances to require Instance Metadata Service Version 2 (IMDSv2)

Verifies that Auto Scaling group launch configurations require EC2 instances to use IMDSv2.

High
Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses

Flags Auto Scaling group launch configurations that assign public IP addresses to EC2 instances.

Medium
Auto Scaling groups should use multiple instance types in multiple Availability Zones

Ensures Auto Scaling groups are configured to use multiple instance types across multiple Availability Zones.

Medium
EC2 Auto Scaling groups should use EC2 launch templates

Verifies that Auto Scaling groups use EC2 launch templates instead of launch configurations.

Low
EC2 Auto Scaling groups should be tagged

Flags Amazon EC2 Auto Scaling groups that have no user-defined tags. Tags help associate ASGs with their owning team, environment, and cost centre; un...

Backup

Medium
AWS Backup recovery points should be encrypted at rest

Verifies that AWS Backup recovery points are encrypted at rest.

Low
AWS Backup recovery points should be tagged

Flags AWS Backup recovery points that have no user-defined tags. Tags help associate recovery points with the owning team, environment, and retention ...

Low
AWS Backup vaults should be tagged

Flags AWS Backup vaults that have no user-defined tags. Tags help associate vaults with their owning team, environment, and retention policy; untagged...

Low
AWS Backup report plans should be tagged

Flags AWS Backup report plans that have no user-defined tags. Tags help associate report plans with the owning team and compliance program; untagged r...

Low
AWS Backup backup plans should be tagged

Flags AWS Backup backup plans that have no user-defined tags. Tags help associate backup plans with the owning team, environment, and policy lineage; ...

Batch

Low
Batch job queues should be tagged

Flags AWS Batch job queues that have no user-defined tags. Tags help associate queues with their owning team, environment, and cost centre; untagged q...

Low
Batch scheduling policies should be tagged

Flags AWS Batch scheduling policies that have no user-defined tags. Tags help associate policies with their owning team and use case; untagged policie...

Low
Batch compute environments should be tagged

Flags AWS Batch compute environments that have no user-defined tags at the environment level. Tags help associate environments with their owning team,...

Low
Compute resources properties in managed Batch compute environments should be tagged

Flags managed AWS Batch compute environments whose computeResources block has no user-defined tags. These tags are propagated to EC2 instances launche...

Bedrock

Medium
Amazon Bedrock data sources should be encrypted with customer managed AWS KMS keys

Flags Amazon Bedrock knowledge-base data sources not encrypted at rest with a customer-managed KMS key. Without a serverSideEncryptionConfiguration.km...

BedrockAgentCore

High
Bedrock AgentCore runtimes should be configured with VPC network mode

Flags Amazon Bedrock AgentCore runtimes whose network mode is set to PUBLIC. PUBLIC runtimes communicate over the internet and bypass VPC controls; pr...

High
Bedrock AgentCore Gateways should require authorization for inbound requests

Flags Amazon Bedrock AgentCore gateways that do not require authorization for inbound requests. Without inbound authorization the gateway is reachable...

Medium
Bedrock AgentCore Memory should be encrypted with customer managed AWS KMS keys

Flags Amazon Bedrock AgentCore Memory resources that are not encrypted at rest with a KMS key you manage. Without an encryptionKeyArn the memory relie...

Medium
Bedrock AgentCore Gateway should be encrypted with customer managed AWS KMS keys

Flags Amazon Bedrock AgentCore Gateways not encrypted at rest with a KMS key you manage. Without a kmsKeyArn the gateway relies on the default AWS-own...

High
Bedrock AgentCore custom browsers should not use public network mode

Flags Amazon Bedrock AgentCore custom browsers configured with PUBLIC network mode. Public browsers reach the internet directly and bypass VPC control...

Medium
Bedrock AgentCore custom browsers should have session recording enabled

Flags Amazon Bedrock AgentCore custom browsers without session recording to an S3 destination. Recording provides an audit trail of browser-tool activ...

High
Bedrock AgentCore custom code interpreters should use a private network configuration

Flags Amazon Bedrock AgentCore custom code interpreters that use PUBLIC or SANDBOX network mode instead of a private VPC configuration. Only VPC mode ...

CloudFormation

Low
CloudFormation stacks should be tagged

Flags AWS CloudFormation stacks that have no user-defined tags. Stack tags propagate to provisioned resources and are the primary way to associate the...

Medium
CloudFormation stacks should have termination protection enabled

Flags AWS CloudFormation stacks that do not have termination protection enabled. Without termination protection, a stack can be deleted by anyone with...

Medium
CloudFormation stacks should have associated service roles

Flags AWS CloudFormation stacks that do not have a service role associated. Without an explicit service role, the stack uses the calling principal...

CloudFront

High
CloudFront distributions should have a default root object configured

Confirms that CloudFront distributions are configured to return a specific default root object.

Medium
CloudFront distributions should require encryption in transit

Ensures CloudFront distributions require viewers to use HTTPS for all connections.

Low
CloudFront distributions should have origin failover configured

Confirms that CloudFront distributions have an origin group with two or more origins configured for failover.

Medium
CloudFront distributions should have logging enabled

Verifies that server access logging is enabled for CloudFront distributions.

Medium
CloudFront distributions should have WAF enabled

Confirms that CloudFront distributions are associated with an AWS WAF Classic or WAF web ACL.

Low
CloudFront distributions should use custom SSL/TLS certificates

Verifies that CloudFront distributions use custom SSL/TLS certificates rather than the default CloudFront certificate.

Low
CloudFront distributions should use SNI to serve HTTPS requests

Flags CloudFront distributions that use a dedicated IP address for SSL/TLS instead of SNI, which is the recommended and more cost-efficient approach.

Medium
CloudFront distributions should encrypt traffic to custom origins

Flags CloudFront distributions that do not encrypt traffic to custom origins — specifically those with an http-only origin protocol policy, or match-v...

Medium
CloudFront distributions should not use deprecated SSL protocols between edge locations and custom origins

Flags CloudFront distributions that use deprecated SSL protocols for HTTPS communication with custom origins.

High
CloudFront distributions should not point to non-existent S3 origins

Detects CloudFront distributions pointing to S3 origins that no longer exist.

Medium
CloudFront distributions should use origin access control

Verifies that CloudFront distributions with S3 origins use origin access control (OAC) to restrict direct S3 access.

Low
CloudFront distributions should be tagged

Flags Amazon CloudFront distributions that have no user-defined tags. Tags help associate distributions with their owning team, environment, and cost ...

Medium
CloudFront distributions should use the recommended TLS security policy

Ensures CloudFront distributions use the recommended TLS security policy for secure viewer connections.

Medium
CloudFront distributions should use origin access control for Lambda function URL origins

Flags Amazon CloudFront distributions that use AWS Lambda function URLs as origins without origin access control (OAC) enabled. Without OAC, the Lambd...

Medium
CloudFront distributions should use trusted key groups for signed URLs and cookies

Flags Amazon CloudFront distributions that authenticate signed URLs or signed cookies using legacy trusted signers. Trusted signers rely on root accou...

CloudTrail

High
CloudTrail should be enabled and configured with at least one multi-Region trail that includes read and write management events

Ensures at least one multi-Region CloudTrail trail exists with the ExcludeManagementEventSources parameter empty on at least one of those trails.

Medium
CloudTrail should have encryption at-rest enabled

Verifies that CloudTrail trails use server-side encryption with an AWS KMS key.

High
At least one CloudTrail trail should be enabled

Verifies that at least one CloudTrail trail is enabled in the AWS account.

Low
CloudTrail log file validation should be enabled

Ensures CloudTrail log file integrity validation is enabled, allowing detection of tampering with delivered log files.

Medium
CloudTrail trails should be integrated with Amazon CloudWatch Logs

Confirms that CloudTrail trails deliver logs to CloudWatch Logs for centralized monitoring and alerting.

Critical
Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible

Flags S3 buckets used to store CloudTrail logs that are publicly accessible.

Low
Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket

Verifies that the S3 bucket storing CloudTrail logs has server access logging enabled to capture all requests made to the bucket.

Low
CloudTrail trails should be tagged

Flags AWS CloudTrail trails that have no user-defined tags. Tags help associate trails with their owning team, environment, and compliance program; un...

Medium
CloudTrail Lake event data stores should be encrypted with customer managed AWS KMS keys

Confirms that CloudTrail Lake event data stores are encrypted at rest with a customer managed KMS key.

CloudWatch

High
CloudWatch alarms should have specified actions configured

Verifies that CloudWatch alarms have an action configured for the ALARM state.

Medium
CloudWatch log groups should be retained for a specified time period

Confirms that CloudWatch log groups have a retention policy set to at least 365 days.

High
CloudWatch alarm actions should be enabled

Ensures CloudWatch alarms have actions enabled so they trigger the configured response when a state change occurs.

CodeArtifact

Low
CodeArtifact repositories should be tagged

Flags AWS CodeArtifact repositories that have no user-defined tags. Tags help associate repositories with their owning team and language ecosystem; un...

CodeBuild

Critical
CodeBuild Bitbucket source repository URLs should not contain sensitive credentials

Ensures CodeBuild projects use OAuth for GitHub or Bitbucket source repository authentication rather than personal access tokens or username/password ...

Critical
CodeBuild project environment variables should not contain clear text credentials

Detects clear-text credentials (such as AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, PASSWORD, or TOKEN) stored in CodeBuild project environment variable...

Low
CodeBuild S3 logs should be encrypted

Verifies that S3 log storage for CodeBuild projects has encryption enabled.

Medium
CodeBuild project environments should have a logging configuration

Verifies that CodeBuild project environments have at least one log destination enabled — either S3 or CloudWatch Logs.

Medium
CodeBuild report group exports should be encrypted at rest

Confirms that CodeBuild report group test results exported to S3 are encrypted at rest.

CodeGuruProfiler

Low
CodeGuru Profiler profiling groups should be tagged

Flags Amazon CodeGuru Profiler profiling groups that have no user-defined tags. Tags help associate profiling groups with their application, owning te...

CodeGuruReviewer

Low
CodeGuru Reviewer repository associations should be tagged

Flags Amazon CodeGuru Reviewer repository associations that have no user-defined tags. Tags help associate reviewer associations with their owning tea...

Cognito

Medium
Cognito user pools should have threat protection activated with full function enforcement mode for standard authentication

Verifies that Cognito user pools have advanced security enabled and set to full enforcement mode, not audit mode.

Medium
Cognito identity pools should not allow unauthenticated identities

Flags Cognito identity pools that allow unauthenticated (guest) identities by having AllowUnauthenticatedIdentities set to true.

Medium
Password policies for Cognito user pools should have strong configurations

Flags Amazon Cognito user pools whose password policy does not meet the recommended baseline (8+ chars, requires upper/lower case, number, symbol, and...

Medium
Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication

Flags Amazon Cognito user pools whose threat protection is not activated in full function (ENFORCED) mode for custom authentication. Audit-only mode l...

Medium
MFA should be enabled for Cognito user pools

Flags Amazon Cognito user pools that authenticate users with passwords but do not require multi-factor authentication. The control is in scope when th...

Medium
Cognito user pools should have deletion protection enabled

Flags Amazon Cognito user pools that do not have deletion protection enabled. Without deletion protection, a single DeleteUserPool call removes the po...

Connect

Low
Amazon Connect Customer Profiles object types should be tagged

Flags Amazon Connect Customer Profiles object types that have no user-defined tags. Tags help associate object types with their owning team and integr...

Medium
Amazon Connect instances should have CloudWatch logging enabled

Confirms that Amazon Connect instances store flow logs in a CloudWatch log group. Flow logs provide real-time details about events in Connect flows, a...

DMS

Critical
Database Migration Service replication instances should not be public

Flags DMS replication instances that are publicly accessible. Replication instances should have private IP addresses and not be reachable outside the ...

Low
DMS certificates should be tagged

Flags AWS DMS certificates that have no user-defined tags. Tags help associate certificates with their owning team and use case; untagged certificates...

Low
DMS event subscriptions should be tagged

Flags AWS DMS event subscriptions that have no user-defined tags. Tags help associate subscriptions with their owning team and downstream pager; untag...

Low
DMS replication instances should be tagged

Flags AWS DMS replication instances that have no user-defined tags. Tags help associate replication instances with their owning team and migration pro...

Low
DMS replication subnet groups should be tagged

Flags AWS DMS replication subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; untagged...

Medium
DMS replication instances should have automatic minor version upgrade enabled

Ensures automatic minor version upgrade is enabled for DMS replication instances, keeping them current with bug fixes, security patches, and performan...

Medium
DMS replication tasks for the target database should have logging enabled

Confirms that DMS replication tasks have logging enabled at LOGGER_SEVERITY_DEFAULT or higher for TARGET_APPLY and TARGET_LOAD operations.

Medium
DMS replication tasks for the source database should have logging enabled

Verifies that DMS replication tasks have logging enabled at LOGGER_SEVERITY_DEFAULT or higher for SOURCE_CAPTURE and SOURCE_UNLOAD components.

Medium
DMS endpoints should use SSL

Confirms that AWS DMS endpoints use SSL connections, encrypting data in transit and validating the target database's server certificate during mi...

Medium
DMS endpoints for Neptune databases should have IAM authorization enabled

Verifies that AWS DMS endpoints for Neptune databases use IAM authorization, enabling fine-grained access control through a service access role.

Medium
DMS endpoints for MongoDB should have an authentication mechanism enabled

Confirms that AWS DMS endpoints for MongoDB have an authentication mechanism enabled. Without authentication, unauthorized users could access data dur...

Medium
DMS endpoints for Redis OSS should have TLS enabled

Ensures AWS DMS endpoints for Redis OSS use TLS connections, encrypting data in transit to prevent eavesdropping during migration.

Medium
DMS replication instances should be configured to use multiple Availability Zones

Flags AWS DMS replication instances that are not deployed in a Multi-AZ configuration. Single-AZ replication instances interrupt migrations during AZ-...

DataSync

Medium
DataSync tasks should have logging enabled

Verifies that AWS DataSync tasks have logging enabled. Audit logs record system activity, support incident investigation, and help meet regulatory com...

Low
DataSync tasks should be tagged

Flags AWS DataSync tasks that have no user-defined tags. Tags help associate tasks with their owning team, environment, and data lineage; untagged tas...

Detective

Low
Detective behavior graphs should be tagged

Flags Amazon Detective behavior graphs that have no user-defined tags. Tags help associate graphs with their owning team and incident-response program...

DocumentDB

Medium
Amazon DocumentDB clusters should be encrypted at rest

Verifies that DocumentDB clusters are encrypted at rest using AES-256 with encryption keys managed by AWS KMS.

Medium
Amazon DocumentDB clusters should have an adequate backup retention period

Ensures DocumentDB clusters have a backup retention period of at least 7 days, supporting recovery from accidental deletion, corruption, and other dat...

Critical
Amazon DocumentDB manual cluster snapshots should not be public

Flags DocumentDB manual cluster snapshots that are publicly accessible, which exposes data to all AWS accounts.

Medium
Amazon DocumentDB clusters should publish audit logs to CloudWatch Logs

Verifies that DocumentDB clusters publish audit logs to CloudWatch Logs. Audit logging captures authentication attempts, collection drops, index creat...

Medium
Amazon DocumentDB clusters should have deletion protection enabled

Confirms that DocumentDB clusters have deletion protection enabled, preventing accidental or unauthorized deletion.

Medium
Amazon DocumentDB clusters should be encrypted in transit

Ensures DocumentDB clusters require TLS for all client connections. Non-TLS connections are not permitted, protecting data in transit from interceptio...

DynamoDB

Medium
DynamoDB tables should automatically scale capacity with demand

Verifies that DynamoDB tables can scale read and write capacity automatically, either through on-demand mode or provisioned mode with auto scaling con...

Medium
DynamoDB tables should have point-in-time recovery enabled

Confirms that point-in-time recovery (PITR) is enabled for DynamoDB tables, providing automated backups and the ability to recover from accidental wri...

Medium
DynamoDB Accelerator (DAX) clusters should be encrypted at rest

Verifies that DAX clusters are encrypted at rest, reducing the risk of unauthorized access to data stored on disk.

Medium
DynamoDB tables should be present in a backup plan

Verifies that DynamoDB tables are included in an AWS Backup plan.

Low
DynamoDB tables should be tagged

Flags Amazon DynamoDB tables that have no user-defined tags. Tags help associate tables with their owning team, environment, and cost centre; untagged...

Medium
DynamoDB tables should have deletion protection enabled

Ensures DynamoDB tables have deletion protection enabled to prevent accidental removal during regular table management operations.

Medium
DynamoDB Accelerator clusters should be encrypted in transit

Confirms that DynamoDB Accelerator (DAX) clusters use TLS endpoint encryption, protecting data in transit against interception.

EC2

Critical
EBS snapshots should not be configured to be publicly restorable

Flags EBS snapshots that are configured to be publicly restorable.

High
VPC default security groups should not allow inbound or outbound traffic

Confirms that the default VPC security group does not allow any inbound or outbound traffic.

Medium
Attached EBS volumes should be encrypted at-rest

Confirms that attached EBS volumes are encrypted at rest.

Medium
Stopped EC2 instances should be removed after a specified time period

Flags stopped EC2 instances that have remained stopped beyond the allowed time period.

Medium
VPC flow logging should be enabled in all VPCs

Verifies that VPC flow logging is enabled in all VPCs.

Medium
EBS default encryption should be enabled

Verifies that EBS default encryption is enabled for the account.

High
EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)

Verifies that EC2 instances use IMDSv2, which requires session-oriented authentication for instance metadata requests.

High
EC2 instances should not have a public IPv4 address

Flags EC2 instances that have a public IPv4 address assigned.

Medium
Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service

Confirms that EC2 instances use VPC endpoints for the EC2 service, keeping traffic within the AWS network.

Low
Unused EC2 EIPs should be removed

Flags Elastic IP addresses that are unassociated and no longer in use.

High
Security groups should not allow ingress from 0.0.0.0/0 or ::/0 to port 22

Flags security groups that allow unrestricted SSH access (port 22) from 0.0.0.0/0.

High
Security groups should not allow ingress from 0.0.0.0/0 or ::/0 to port 3389

Flags security groups that allow unrestricted RDP access (port 3389) from 0.0.0.0/0.

Medium
EC2 subnets should not automatically assign public IP addresses

Flags EC2 subnets configured to automatically assign public IPv4 addresses or IPv6 addresses to instances at launch.

Low
Unused Network Access Control Lists should be removed

Flags Network ACLs that are not associated with any subnet.

Low
EC2 instances should not use multiple ENIs

Flags EC2 instances using multiple Elastic Network Interfaces, which can create complex network configurations and unintended routing.

High
Security groups should only allow unrestricted incoming traffic for authorized ports

Verifies that security groups only permit unrestricted inbound traffic on explicitly authorized ports.

Critical
Security groups should not allow unrestricted access to ports with high risk

Flags security groups that allow unrestricted inbound access to high-risk ports.

Medium
Both VPN tunnels for an AWS Site-to-Site VPN connection should be up

Verifies that both tunnels for AWS Site-to-Site VPN connections are up.

Medium
Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 3389

Flags Network ACLs that allow unrestricted ingress from 0.0.0.0/0 to SSH (port 22) or RDP (port 3389).

Medium
Unused EC2 security groups should be removed

Flags security groups not attached to any EC2 instance or elastic network interface.

High
EC2 Transit Gateways should not automatically accept VPC attachment requests

Confirms that EC2 Transit Gateways do not automatically accept VPC attachment requests.

Medium
EC2 paravirtual instance types should not be used

Detects EC2 instances using paravirtual (PV) virtualization, a legacy type with fewer features and security controls than HVM.

High
EC2 launch templates should not assign public IPs to network interfaces

Flags EC2 launch templates configured to assign public IP addresses to network interfaces.

Low
EBS volumes should be in a backup plan

Confirms that EBS volumes are covered by an AWS Backup plan.

Low
EC2 transit gateway attachments should be tagged

Flags transit gateway attachments that have no user-defined tags. Tags help associate them with their owning team and use case; untagged transit gatew...

Low
EC2 transit gateway route tables should be tagged

Flags transit gateway route tables that have no user-defined tags. Tags help associate them with their owning team and use case; untagged transit gate...

Low
EC2 network interfaces should be tagged

Flags EC2 network interface that have no user-defined tags. Tags help associate network interfaces with their owning team and use case; untagged netwo...

Low
EC2 customer gateways should be tagged

Flags customer gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged customer gateways are o...

Low
EC2 Elastic IP addresses should be tagged

Flags EC2 Elastic IP address that have no user-defined tags. Tags help associate Elastic IP addresses with their owning team and use case; untagged El...

Low
EC2 instances should be tagged

Flags EC2 instance that have no user-defined tags. Tags help associate instances with their owning team and use case; untagged instances are operation...

Low
EC2 internet gateways should be tagged

Flags internet gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged internet gateways are o...

Low
EC2 NAT gateways should be tagged

Flags NAT gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged NAT gateways are operational...

Low
EC2 network ACLs should be tagged

Flags EC2 network ACL that have no user-defined tags. Tags help associate network ACLs with their owning team and use case; untagged network ACLs are ...

Low
EC2 route tables should be tagged

Flags EC2 route table that have no user-defined tags. Tags help associate route tables with their owning team and use case; untagged route tables are ...

Low
EC2 security groups should be tagged

Flags EC2 security group that have no user-defined tags. Tags help associate security groups with their owning team and use case; untagged security gr...

Low
EC2 subnets should be tagged

Flags EC2 subnet that have no user-defined tags. Tags help associate subnets with their owning team and use case; untagged subnets are operationally o...

Low
EC2 volumes should be tagged

Flags EC2 volume that have no user-defined tags. Tags help associate volumes with their owning team and use case; untagged volumes are operationally o...

Low
Amazon VPCs should be tagged

Flags VPC that have no user-defined tags. Tags help associate VPCs with their owning team and use case; untagged VPCs are operationally opaque.

Low
Amazon VPC endpoint services should be tagged

Flags VPC endpoint services that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPC endpoint servic...

Low
Amazon VPC flow logs should be tagged

Flags VPC flow log that have no user-defined tags. Tags help associate VPC flow logs with their owning team and use case; untagged VPC flow logs are o...

Low
Amazon VPC peering connections should be tagged

Flags VPC peering connections that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPC peering conne...

Low
EC2 VPN gateways should be tagged

Flags VPN gateways that have no user-defined tags. Tags help associate them with their owning team and use case; untagged VPN gateways are operational...

Low
EC2 Client VPN endpoints should have client connection logging enabled

Ensures Client VPN endpoints have client connection logging enabled.

Low
EC2 transit gateways should be tagged

Flags EC2 transit gateway that have no user-defined tags. Tags help associate transit gateways with their owning team and use case; untagged transit g...

High
EC2 security groups should not allow ingress from 0.0.0.0/0 to remote server administration ports

Flags EC2 security groups that allow inbound traffic from 0.0.0.0/0 to the SSH (22) or RDP (3389) remote-administration ports. Public exposure of thes...

High
EC2 security groups should not allow ingress from ::/0 to remote server administration ports

Flags EC2 security groups that allow inbound traffic from ::/0 to the SSH (22) or RDP (3389) remote-administration ports. Public IPv6 exposure of thes...

Medium
VPCs should be configured with an interface endpoint for ECR API

Verifies that VPC interface endpoints are available for the Amazon ECR API.

Medium
VPCs should be configured with an interface endpoint for Docker Registry

Confirms that VPC interface endpoints are available for the Amazon ECR Docker registry.

Medium
VPCs should be configured with an interface endpoint for Systems Manager

Verifies that VPC interface endpoints are available for AWS Systems Manager.

Medium
VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts

Confirms that VPC interface endpoints are available for SSM Incident Manager Contacts.

Medium
VPCs should be configured with an interface endpoint for Systems Manager Incident Manager

Verifies that VPC interface endpoints are available for SSM Incident Manager.

Low
EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)

Confirms that the default version of EC2 launch templates requires IMDSv2 for instance metadata access.

Medium
EC2 VPN connections should have logging enabled

Ensures EC2 VPN connections have logging configured.

Medium
EC2 VPC Block Public Access settings should block internet gateway traffic

Verifies that VPC Block Public Access settings are configured to block internet gateway traffic.

Medium
EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes

Confirms that EC2 Spot Fleet requests with launch parameters have encryption enabled on all attached EBS volumes.

Low
EC2 DHCP option sets should be tagged

Flags DHCP option sets that have no user-defined tags. Tags help associate them with their owning team and use case; untagged DHCP option sets are ope...

Low
EC2 launch templates should be tagged

Flags EC2 launch template that have no user-defined tags. Tags help associate launch templates with their owning team and use case; untagged launch te...

Low
EC2 prefix lists should be tagged

Flags EC2 prefix list that have no user-defined tags. Tags help associate prefix lists with their owning team and use case; untagged prefix lists are ...

Low
EC2 traffic mirror sessions should be tagged

Flags traffic mirror sessions that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror se...

Low
EC2 traffic mirror filters should be tagged

Flags traffic mirror filters that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror fil...

Low
EC2 traffic mirror targets should be tagged

Flags traffic mirror targets that have no user-defined tags. Tags help associate them with their owning team and use case; untagged traffic mirror tar...

Medium
EC2 network interfaces should have source/destination checking enabled

Verifies that source/destination checking is enabled for EC2 elastic network interfaces.

Medium
EC2 launch templates should enable encryption for attached EBS volumes

Flags EC2 launch templates whose latest version defines block device mappings without enabling EBS encryption. Templates that launch unencrypted EBS v...

High
Block public access settings should be enabled for Amazon EBS snapshots

Flags accounts/regions where EBS snapshot block public access is set to 'unblocked'. Without BPA, any snapshot can be made public (intention...

Medium
EC2 VPN connections should use IKEv2 protocol

Flags AWS Site-to-Site VPN connections whose tunnels do not support IKEv2. IKEv1 is the legacy keying protocol; tunnels should support IKEv2 at minimu...

ECR

High
ECR private repositories should have image scanning configured

Verifies that private ECR repositories have image scanning configured.

Medium
ECR private repositories should have tag immutability configured

Confirms that private ECR repositories have tag immutability enabled, preventing image tags from being overwritten.

Medium
ECR repositories should have at least one lifecycle policy configured

Ensures ECR repositories have at least one lifecycle policy configured to manage image retention.

Low
ECR public repositories should be tagged

Flags Amazon ECR Public repositories that have no user-defined tags. Tags help associate repositories with their owning team and product; untagged pub...

Medium
ECR repositories should be encrypted with customer managed AWS KMS keys

Verifies that ECR repositories are encrypted at rest with a customer managed KMS key.

ECS

High
ECS services should not have public IP addresses assigned to them automatically

Flags ECS services configured to automatically assign public IP addresses (AssignPublicIP set to ENABLED).

High
ECS task definitions should not share the host's process namespace

Flags ECS task definitions configured to share the host's process namespace with their containers.

High
ECS containers should run as non-privileged

Flags ECS task definitions with containers that have the privileged parameter set to true.

High
ECS task definitions should configure containers to be limited to read-only access to root filesystems

Verifies that ECS task definitions configure containers with read-only access to their root filesystems. Task definitions targeting Windows containers...

High
Secrets should not be passed as container environment variables

Detects ECS containers that pass secrets (such as AWS_ACCESS_KEY_ID, PASSWORD, or TOKEN) as plain-text environment variables.

High
ECS task definitions should have a logging configuration

Confirms that the latest active ECS task definition has a logging configuration with a valid logDriver specified for all container definitions.

Medium
ECS Fargate services should run on the latest Fargate platform version

Verifies that ECS Fargate services are running the latest Fargate platform version.

Medium
ECS clusters should use Container Insights

Confirms that ECS clusters have Container Insights enabled for performance and operational monitoring.

Low
ECS services should be tagged

Flags Amazon ECS services that have no user-defined tags. Tags help associate services with their owning team, environment, and cost centre; untagged ...

Low
ECS clusters should be tagged

Flags Amazon ECS clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagged ...

Low
ECS task definitions should be tagged

Flags Amazon ECS task definitions that have no user-defined tags. Tags help associate task definitions with their owning team, environment, and applic...

High
ECS task sets should not automatically assign public IP addresses

Flags ECS task sets configured to automatically assign public IP addresses (AssignPublicIP set to ENABLED).

Medium
ECS task definitions should not use host network mode

Flags the latest active revision of ECS task definitions that use host network mode, which shares the host's network namespace with the container

Medium
ECS Task Definitions should use in-transit encryption for EFS volumes

Flags Amazon ECS task definitions whose EFS volume configurations do not enable in-transit encryption. Without TLS, EFS traffic between the task and t...

Medium
ECS capacity providers should have managed termination protection enabled

Flags ECS capacity providers backed by Auto Scaling groups that do not have managed termination protection enabled. Without it, the ASG can terminate ...

Medium
ECS task definitions should configure non-root users in Linux container definitions

Flags Amazon ECS Linux task definitions whose container definitions do not set an explicit non-root user. Running containers as root grants the worklo...

Medium
ECS task definitions should configure non-administrator users in Windows container definitions

Flags Amazon ECS Windows task definitions whose container definitions do not set an explicit non-administrator user. Running as the default administra...

EFS

Medium
Elastic File System should be configured to encrypt file data at-rest using AWS KMS

Verifies that Amazon EFS file systems are configured to encrypt data at rest using AWS KMS.

Medium
Amazon EFS volumes should be in backup plans

Verifies that EFS file systems are included in an AWS Backup plan.

Medium
EFS access points should enforce a root directory

Verifies that EFS access points enforce a non-root directory path, preventing clients from accessing the entire file system root.

Medium
EFS access points should enforce a user identity

Confirms that EFS access points enforce a POSIX user identity, ensuring consistent user-level permissions for all file system operations.

Low
EFS access points should be tagged

Flags Amazon EFS access points that have no user-defined tags. Tags help associate access points with their owning team and application; untagged acce...

Medium
EFS mount targets should not be associated with subnets that assign public IP addresses on launch

Flags EFS mount targets associated with subnets that automatically assign public IP addresses on instance launch.

Medium
EFS file systems should have automatic backups enabled

Ensures EFS file systems have automatic backups enabled.

Medium
EFS file systems should be encrypted at rest

Confirms that EFS file systems encrypt stored data at rest with AWS KMS.

EKS

High
EKS cluster endpoints should not be publicly accessible

Flags EKS cluster API server endpoints that are publicly accessible.

High
EKS clusters should run on a supported Kubernetes version

Confirms that EKS clusters run a supported Kubernetes version.

Medium
EKS clusters should use encrypted Kubernetes secrets

Verifies that EKS clusters use AWS KMS to encrypt Kubernetes secrets stored in etcd.

Low
EKS clusters should be tagged

Flags Amazon EKS clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagged ...

Low
EKS identity provider configurations should be tagged

Flags Amazon EKS identity provider configurations that have no user-defined tags. Tags help associate IdP bindings with their owning team and downstre...

Medium
EKS clusters should have audit logging enabled

Ensures EKS clusters have audit logging enabled to record API server activity.

High
EKS node groups should run on a supported Kubernetes version

Flags Amazon EKS node groups that run on a Kubernetes version older than the current AWS EKS standard support window. Extended-support versions miss b...

ELB

Medium
Application Load Balancer should be configured to redirect all HTTP requests to HTTPS

Ensures Application Load Balancers redirect all HTTP requests to HTTPS, enforcing encrypted connections.

Medium
Classic Load Balancers with SSL/HTTPS listeners should use a certificate provided by AWS Certificate Manager

Verifies that Classic Load Balancers with SSL/HTTPS listeners use certificates from AWS Certificate Manager, simplifying certificate management and re...

Medium
Classic Load Balancer listeners should be configured with HTTPS or TLS termination

Verifies that Classic Load Balancer listeners use HTTPS or TLS termination to encrypt traffic between clients and the load balancer.

Medium
Application load balancer should be configured to drop invalid http headers

Verifies that Application Load Balancers drop invalid HTTP headers, reducing the risk of header injection and malformed request issues.

Medium
Application and Classic Load Balancers logging should be enabled

Confirms that access logging is enabled for Application and Classic Load Balancers to capture detailed request information for audit and troubleshooti...

Medium
Application, Gateway, and Network Load Balancers should have deletion protection enabled

Confirms that deletion protection is enabled on Application Load Balancers, preventing accidental or unauthorized deletion.

Low
Classic Load Balancers should have connection draining enabled

Verifies that connection draining is enabled on Classic Load Balancers, allowing in-flight requests to complete before instances are deregistered.

Medium
Classic Load Balancers with SSL listeners should use a predefined security policy that has strong configuration

Confirms that Classic Load Balancers with SSL listeners use a predefined security policy with strong cipher and protocol configurations.

Medium
Classic Load Balancers should have cross-zone load balancing enabled

Confirms that cross-zone load balancing is enabled for Classic Load Balancers, distributing traffic evenly across all registered instances in all enab...

Medium
Classic Load Balancer should span multiple Availability Zones

Ensures Classic Load Balancers span multiple Availability Zones for increased fault tolerance.

Medium
Application Load Balancer should be configured with defensive or strictest desync mitigation mode

Ensures Application Load Balancers use defensive or strictest desync mitigation mode to protect against HTTP desync attacks.

Medium
Application, Network and Gateway Load Balancers should span multiple Availability Zones

Ensures Application, Network, and Gateway Load Balancers span multiple Availability Zones for fault tolerance.

Medium
Classic Load Balancer should be configured with defensive or strictest desync mitigation mode

Ensures Classic Load Balancers with SSL/HTTPS listeners use defensive or strictest desync mitigation mode to protect against HTTP desync attacks.

Medium
Application Load Balancers should be associated with an AWS WAF web ACL

Confirms that Application Load Balancers are associated with an AWS WAF web ACL to protect against web exploits that could affect availability or cons...

Medium
Application and Network Load Balancers with listeners should use recommended security policies

Verifies that HTTPS listeners on ALBs and TLS listeners on NLBs use a recommended security policy for encrypting data in transit.

Medium
Application and Network Load Balancer listeners should use secure protocols to encrypt data in transit

Confirms that ALB listeners use HTTPS and NLB listeners use TLS for encrypted data transmission.

Medium
Application and Network Load Balancer target groups should use encrypted health check protocols

Flags ALB and NLB target groups whose health check protocol is not HTTPS. Health-check traffic sent over HTTP exposes endpoint paths and response bodi...

Medium
ELB target groups should use encrypted transport protocols

Flags Elastic Load Balancing target groups whose transport protocol is not encrypted. Pass criteria: HTTPS, TLS, or QUIC. Target types of Lambda or AL...

EMR

High
Amazon EMR cluster primary nodes should not have public IP addresses

Flags EMR cluster master nodes that have public IP addresses assigned.

Critical
Amazon EMR block public access setting should be enabled

Confirms that Amazon EMR Block Public Access is enabled for the account, and that no ports other than 22 are open to the public.

Medium
Amazon EMR security configurations should have encryption at rest enabled

Verifies that EMR security configurations have encryption at rest enabled.

Medium
Amazon EMR security configurations should have encryption in transit enabled

Ensures EMR security configurations have encryption in transit enabled.

ES

Low
Elasticsearch domains should be tagged

Flags Amazon Elasticsearch Service domains that have no user-defined tags. Tags help associate domains with their owning team and use case; untagged d...

ElastiCache

High
ElastiCache (Redis OSS) clusters should have automatic backups enabled

Verifies that ElastiCache (Redis OSS) cache clusters and ElastiCache (Redis OSS or Valkey) replication groups have automatic backups scheduled with a ...

High
ElastiCache clusters should have automatic minor version upgrades enabled

Confirms that ElastiCache for Redis clusters automatically apply minor version upgrades.

Medium
ElastiCache replication groups should have automatic failover enabled

Ensures ElastiCache Redis replication groups have automatic failover enabled.

Medium
ElastiCache replication groups should be encrypted at rest

Verifies that ElastiCache Redis replication groups are encrypted at rest.

Medium
ElastiCache replication groups should be encrypted in transit

Verifies that ElastiCache Redis replication groups are encrypted in transit.

Medium
ElastiCache (Redis OSS) replication groups of earlier versions should have Redis OSS AUTH enabled

Confirms that ElastiCache Redis replication groups running versions below 6.0 have Redis AUTH enabled.

High
ElastiCache clusters should not use the default subnet group

Flags ElastiCache clusters using the default subnet group instead of a custom one.

ElasticBeanstalk

Low
Elastic Beanstalk environments should have enhanced health reporting enabled

Verifies that enhanced health reporting is enabled for Elastic Beanstalk environments.

High
Elastic Beanstalk managed platform updates should be enabled

Ensures managed platform updates are enabled for Elastic Beanstalk environments.

High
Elastic Beanstalk should stream logs to CloudWatch

Confirms that Elastic Beanstalk environments stream logs to CloudWatch Logs.

Elasticsearch

Medium
Elasticsearch domains should have encryption at-rest enabled

Verifies that Elasticsearch domains have encryption at rest enabled on persistent volumes.

Critical
Elasticsearch domains should not be publicly accessible

Confirms that Elasticsearch domains are deployed within a VPC rather than publicly accessible.

Medium
Elasticsearch domains should encrypt data sent between nodes

Ensures Elasticsearch domains have node-to-node encryption enabled, securing data in transit within the cluster.

Medium
Elasticsearch domain error logging to CloudWatch Logs should be enabled

Verifies that Elasticsearch domains have error logging to CloudWatch Logs enabled.

Medium
Elasticsearch domains should have audit logging enabled

Confirms that Elasticsearch domains have audit logging enabled for security and compliance purposes.

Medium
Elasticsearch domains should have at least three data nodes

Ensures Elasticsearch domains are configured with at least three data nodes for high availability.

Medium
Elasticsearch domains should be configured with at least three dedicated master nodes

Verifies that Elasticsearch domains have at least three dedicated master nodes configured for cluster stability.

Medium
Connections to Elasticsearch domains should be encrypted using the latest TLS security policy

Ensures connections to Elasticsearch domains use the latest TLS protocol for secure data transmission.

EventBridge

Low
EventBridge event buses should be tagged

Flags Amazon EventBridge event buses that have no user-defined tags. Tags help associate event buses with their owning team and integration; untagged ...

Low
EventBridge custom event buses should have a resource-based policy attached

Confirms that custom EventBridge event buses have a resource-based policy attached to control access.

Medium
EventBridge global endpoints should have event replication enabled

Verifies that event replication is enabled for EventBridge global endpoints.

FSx

Low
FSx for OpenZFS file systems should be configured to copy tags to backups and volumes

Confirms that FSx for OpenZFS file systems copy tags to backups and volumes, supporting resource categorization and governance.

Low
FSx for Lustre file systems should be configured to copy tags to backups

Confirms that FSx for Lustre file systems copy tags to backups and volumes, supporting resource identification and governance.

Medium
FSx for OpenZFS file systems should be configured for Multi-AZ deployment

Verifies that FSx for OpenZFS file systems use the Multi-AZ deployment type for high availability across Availability Zones.

Medium
FSx for NetApp ONTAP file systems should be configured for Multi-AZ deployment

Ensures FSx for NetApp ONTAP file systems use a Multi-AZ deployment type for continuous availability even when an Availability Zone is unavailable.

Medium
FSx for Windows File Server file systems should be configured for Multi-AZ deployment

Ensures FSx for Windows File Server file systems use Multi-AZ deployment, distributing file servers across two Availability Zones for high availabilit...

FraudDetector

Low
Amazon Fraud Detector entity types should be tagged

Flags Amazon Fraud Detector entity type that have no user-defined tags. Tags help associate Amazon Fraud Detector entity type with their owning team a...

Low
Amazon Fraud Detector labels should be tagged

Flags Amazon Fraud Detector label that have no user-defined tags. Tags help associate Amazon Fraud Detector label with their owning team and use case;...

Low
Amazon Fraud Detector outcomes should be tagged

Flags Amazon Fraud Detector outcome that have no user-defined tags. Tags help associate Amazon Fraud Detector outcome with their owning team and use c...

Low
Amazon Fraud Detector variables should be tagged

Flags Amazon Fraud Detector variable that have no user-defined tags. Tags help associate Amazon Fraud Detector variable with their owning team and use...

GlobalAccelerator

Low
Global Accelerator accelerators should be tagged

Flags AWS Global Accelerator accelerators that have no user-defined tags. Tags help associate accelerators with their owning team and downstream endpo...

Glue

Low
AWS Glue jobs should be tagged

Flags AWS Glue jobs that have no user-defined tags. Tags help associate jobs with their owning team and data pipeline; untagged jobs are operationally...

Medium
AWS Glue machine learning transforms should be encrypted at rest

Verifies that AWS Glue machine learning transforms are encrypted at rest.

Medium
AWS Glue Spark jobs should run on supported versions of AWS Glue

Confirms that AWS Glue for Spark jobs run on a supported version of AWS Glue.

GuardDuty

High
GuardDuty should be enabled

Confirms that Amazon GuardDuty is enabled in the account and region.

Low
GuardDuty filters should be tagged

Flags Amazon GuardDuty filters that have no user-defined tags. Tags help associate filters with their owning team and rationale; untagged filters are ...

Low
GuardDuty IPSets should be tagged

Flags Amazon GuardDuty IPSets that have no user-defined tags. Tags help associate IPSets with their owning team and threat intelligence feed lineage; ...

Low
GuardDuty detectors should be tagged

Flags Amazon GuardDuty detectors that have no user-defined tags. Tags help associate detectors with their owning team and account-organisation lineage...

High
GuardDuty EKS Audit Log Monitoring should be enabled

Confirms that GuardDuty EKS Audit Log Monitoring is enabled across all accounts. This feature analyzes Kubernetes audit logs to detect suspicious acti...

High
GuardDuty Lambda Protection should be enabled

Verifies that GuardDuty Lambda Protection is enabled across all accounts. Lambda Protection monitors network activity logs for Lambda invocations to i...

High
GuardDuty EKS Runtime Monitoring should be enabled

Ensures GuardDuty EKS Runtime Monitoring with automated agent management is enabled across all accounts, providing threat detection coverage for EKS w...

High
GuardDuty Malware Protection for EC2 should be enabled

Ensures GuardDuty Malware Protection is enabled across all accounts to detect malware on EBS volumes attached to EC2 instances and container workloads...

High
GuardDuty RDS Protection should be enabled

Confirms that GuardDuty RDS Protection is enabled across all accounts to analyze and profile RDS login activity for access threats to Aurora databases...

High
GuardDuty S3 Protection should be enabled

Ensures GuardDuty S3 Protection is enabled across all accounts to monitor object-level API operations and identify potential security risks in S3 buck...

High
GuardDuty Runtime Monitoring should be enabled

Verifies that GuardDuty Runtime Monitoring is enabled across all accounts, providing OS-level, network, and file event analysis to detect threats in A...

Medium
GuardDuty ECS Runtime Monitoring should be enabled

Verifies that the GuardDuty automated security agent is enabled for runtime monitoring of ECS clusters on AWS Fargate in all accounts.

Medium
GuardDuty EC2 Runtime Monitoring should be enabled

Ensures the GuardDuty automated security agent is enabled for EC2 runtime monitoring in all accounts. GuardDuty Runtime Monitoring observes OS-level, ...

IAM

High
IAM policies should not allow full "*" administrative privileges

Flags IAM policies that grant full administrative privileges by allowing all actions (Action: *) on all resources (Resource: *) with Effect: Allow.

Low
IAM users should not have IAM policies attached

Flags IAM users with policies attached directly rather than through groups or roles.

Medium
IAM users' access keys should be rotated every 90 days or less

Verifies that IAM user access keys have been rotated within the last 90 days.

Critical
IAM root user access key should not exist

Confirms that no access keys exist for the IAM root user.

Medium
MFA should be enabled for all IAM users that have a console password

Verifies that MFA is enabled for all IAM users with a console password.

Critical
Hardware MFA should be enabled for the root user

Verifies that hardware MFA is enabled for the root user.

Medium
Password policies for IAM users should have strong configurations

Verifies that the IAM account password policy enforces strong password requirements.

Medium
Unused IAM user credentials should be removed

Flags IAM users whose passwords or access keys have not been used for 90 days. Removing unused credentials reduces the attack surface from abandoned o...

Critical
MFA should be enabled for the root user

Confirms that virtual MFA is enabled for the root user.

Low
Ensure IAM password policy expires passwords within 90 days or less

Verifies that the IAM account password policy is configured to expire passwords within 90 days or fewer.

Low
Ensure a support role has been created to manage incidents with AWS Support

Ensures a support role exists in the account for managing incidents with AWS Support.

Medium
MFA should be enabled for all IAM users

Ensures MFA is enabled for all IAM users.

Low
IAM customer managed policies that you create should not allow wildcard actions for services

Flags IAM customer managed policies containing statements that allow Service:* or use NotAction: Service:* with Effect: Allow.

Medium
IAM user credentials unused for 45 days should be removed

Flags IAM users whose passwords or access keys have not been used in 45 or more days.

Low
IAM Access Analyzer analyzers should be tagged

Flags IAM Access Analyzer analyzers that have no user-defined tags. Tags help associate analyzers with their owning team and scope; untagged analyzers...

Low
IAM roles should be tagged

Flags IAM roles that have no user-defined tags. Tags help associate roles with their owning team and cost-attribution lineage; untagged roles are oper...

Low
IAM users should be tagged

Flags IAM users that have no user-defined tags. Tags help associate users with their owning team and cost-attribution lineage; untagged users are oper...

Medium
Expired SSL/TLS certificates managed in IAM should be removed

Flags expired SSL/TLS server certificates still present and active in IAM.

Medium
IAM identities should not have the AWSCloudShellFullAccess policy attached

Flags IAM identities (users, roles, or groups) that have the AWSCloudShellFullAccess managed policy attached.

High
IAM Access Analyzer external access analyzer should be enabled

Confirms that the AWS account has an IAM Access Analyzer external access analyzer enabled in the current region.

IVS

Low
IVS playback key pairs should be tagged

Flags Amazon IVS playback key pair that have no user-defined tags. Tags help associate Amazon IVS playback key pair with their owning team and use cas...

Low
IVS recording configurations should be tagged

Flags Amazon IVS recording configuration that have no user-defined tags. Tags help associate Amazon IVS recording configuration with their owning team...

Low
IVS channels should be tagged

Flags Amazon IVS channel that have no user-defined tags. Tags help associate Amazon IVS channel with their owning team and use case; untagged channels...

Identify

Medium
ActiveMQ brokers should stream audit logs to CloudWatch

Verifies that Amazon MQ ActiveMQ brokers stream audit logs to CloudWatch Logs, enabling alarm creation and increased visibility into security-related ...

Medium
MSK connectors should have logging enabled

Ensures logging is enabled for Amazon MSK connectors via at least one of CloudWatch Logs, S3, or Firehose.

Inspector

High
Amazon Inspector EC2 scanning should be enabled

Confirms that Amazon Inspector EC2 scanning is enabled in the account.

High
Amazon Inspector ECR scanning should be enabled

Verifies that Amazon Inspector ECR scanning is enabled in the account to detect software vulnerabilities in container images stored in ECR.

High
Amazon Inspector Lambda code scanning should be enabled

Ensures Amazon Inspector Lambda code scanning is enabled in the account.

High
Amazon Inspector Lambda standard scanning should be enabled

Confirms that Amazon Inspector Lambda standard scanning is enabled in the account.

IoT

Low
AWS IoT Device Defender security profiles should be tagged

Flags IoT Device Defender security profile that have no user-defined tags. Tags help associate IoT Device Defender security profile with their owning ...

Low
AWS IoT Core mitigation actions should be tagged

Flags IoT Core mitigation action that have no user-defined tags. Tags help associate IoT Core mitigation action with their owning team and use case; u...

Low
AWS IoT Core dimensions should be tagged

Flags IoT Core dimension that have no user-defined tags. Tags help associate IoT Core dimension with their owning team and use case; untagged dimensio...

Low
AWS IoT Core authorizers should be tagged

Flags IoT Core authorizer that have no user-defined tags. Tags help associate IoT Core authorizer with their owning team and use case; untagged author...

Low
AWS IoT Core role aliases should be tagged

Flags IoT Core role alias that have no user-defined tags. Tags help associate IoT Core role alias with their owning team and use case; untagged role a...

Low
AWS IoT Core policies should be tagged

Flags IoT Core policy that have no user-defined tags. Tags help associate IoT Core policy with their owning team and use case; untagged policies are o...

IoTEvents

Low
AWS IoT Events inputs should be tagged

Flags IoT Events input that have no user-defined tags. Tags help associate IoT Events input with their owning team and use case; untagged inputs are o...

Low
AWS IoT Events detector models should be tagged

Flags IoT Events detector model that have no user-defined tags. Tags help associate IoT Events detector model with their owning team and use case; unt...

Low
AWS IoT Events alarm models should be tagged

Flags IoT Events alarm model that have no user-defined tags. Tags help associate IoT Events alarm model with their owning team and use case; untagged ...

IoTSiteWise

Low
AWS IoT SiteWise asset models should be tagged

Flags IoT SiteWise asset model that have no user-defined tags. Tags help associate IoT SiteWise asset model with their owning team and use case; untag...

Low
AWS IoT SiteWise dashboards should be tagged

Flags IoT SiteWise dashboard that have no user-defined tags. Tags help associate IoT SiteWise dashboard with their owning team and use case; untagged ...

Low
AWS IoT SiteWise gateways should be tagged

Flags IoT SiteWise gateway that have no user-defined tags. Tags help associate IoT SiteWise gateway with their owning team and use case; untagged gate...

Low
AWS IoT SiteWise portals should be tagged

Flags IoT SiteWise portal that have no user-defined tags. Tags help associate IoT SiteWise portal with their owning team and use case; untagged portal...

Low
AWS IoT SiteWise projects should be tagged

Flags IoT SiteWise project that have no user-defined tags. Tags help associate IoT SiteWise project with their owning team and use case; untagged proj...

IoTTwinMaker

Low
AWS IoT TwinMaker sync jobs should be tagged

Flags IoT TwinMaker sync job that have no user-defined tags. Tags help associate IoT TwinMaker sync job with their owning team and use case; untagged ...

Low
AWS IoT TwinMaker workspaces should be tagged

Flags IoT TwinMaker workspace that have no user-defined tags. Tags help associate IoT TwinMaker workspace with their owning team and use case; untagge...

Low
AWS IoT TwinMaker scenes should be tagged

Flags IoT TwinMaker scene that have no user-defined tags. Tags help associate IoT TwinMaker scene with their owning team and use case; untagged scenes...

Low
AWS IoT TwinMaker entities should be tagged

Flags IoT TwinMaker entity that have no user-defined tags. Tags help associate IoT TwinMaker entity with their owning team and use case; untagged enti...

IoTWireless

Low
AWS IoT Wireless multicast groups should be tagged

Flags IoT Wireless multicast group that have no user-defined tags. Tags help associate IoT Wireless multicast group with their owning team and use cas...

Low
AWS IoT Wireless service profiles should be tagged

Flags IoT Wireless service profile that have no user-defined tags. Tags help associate IoT Wireless service profile with their owning team and use cas...

Low
AWS IoT Wireless FUOTA tasks should be tagged

Flags IoT Wireless FUOTA task that have no user-defined tags. Tags help associate IoT Wireless FUOTA task with their owning team and use case; untagge...

KMS

Medium
IAM customer managed policies should not allow decryption actions on all KMS keys

Flags IAM customer managed policies that allow decrypt actions on all KMS keys, which could permit unauthorized decryption of sensitive data.

Medium
IAM principals should not have IAM inline policies that allow decryption actions on all KMS keys

Detects IAM customer managed policies that allow decryption on all KMS keys without restriction, which can lead to unauthorized access to encrypted da...

Critical
AWS KMS keys should not be deleted unintentionally

Flags AWS KMS keys scheduled for deletion, which may be unintentional.

Medium
AWS KMS key rotation should be enabled

Verifies that AWS KMS keys have automatic key rotation enabled.

Critical
KMS keys should not be publicly accessible

Flags KMS keys that are publicly accessible.

Keyspaces

Low
Amazon Keyspaces keyspaces should be tagged

Flags Amazon Keyspaces keyspaces that have no user-defined tags. Tags help associate keyspaces with their owning team and application; untagged keyspa...

Kinesis

Medium
Firehose delivery streams should be encrypted at rest

Ensures Firehose delivery streams are encrypted at rest using AWS KMS. Data is encrypted before being written to the stream's storage layer and d...

Medium
Kinesis streams should be encrypted at rest

Confirms that Kinesis Data Streams are encrypted at rest with server-side encryption.

Low
Kinesis streams should be tagged

Flags Amazon Kinesis data streams that have no user-defined tags. Tags help associate streams with their owning team, environment, and producers/consu...

Medium
Kinesis streams should have an adequate data retention period

Verifies that Kinesis data streams have a data retention period of at least 168 hours (7 days).

Lambda

Critical
Lambda function policies should prohibit public access

Verifies that Lambda function resource-based policies do not grant public access from outside the account.

Medium
Lambda functions should use supported runtimes

Ensures Lambda functions use supported runtime versions for each language.

Low
Lambda functions should be in a VPC

Confirms that Lambda functions are deployed within a VPC. Note: this check verifies VPC attachment only and does not evaluate subnet routing or public...

Medium
VPC Lambda functions should operate in multiple Availability Zones

Verifies that Lambda functions connected to a VPC are associated with subnets in more than one Availability Zone.

Low
Lambda functions should be tagged

Flags AWS Lambda functions that have no user-defined tags. Tags help associate functions with their owning team, application, and cost centre; untagge...

Low
Lambda functions should have AWS X-Ray active tracing enabled

Ensures active AWS X-Ray tracing is enabled for Lambda functions.

MQ

Low
Amazon MQ brokers should be tagged

Flags Amazon MQ brokers that have no user-defined tags. Tags help associate brokers with their owning team and message consumers; untagged brokers are...

Low
ActiveMQ brokers should use active/standby deployment mode

Ensures Amazon MQ ActiveMQ brokers use active/standby deployment mode for high availability. This configuration places two broker instances across two...

Low
RabbitMQ brokers should use cluster deployment mode

Verifies that Amazon MQ RabbitMQ brokers use cluster deployment mode rather than single-instance deployment.

MSK

Low
MSK clusters should have enhanced monitoring configured

Verifies that Amazon MSK clusters have enhanced monitoring enabled at PER_TOPIC_PER_BROKER level or higher.

Macie

Medium
Macie should be enabled

Confirms that Amazon Macie is enabled for the account.

High
Macie automated sensitive data discovery should be enabled

Verifies that automated sensitive data discovery is enabled for the Amazon Macie administrator account.

Neptune

Medium
Neptune DB clusters should be encrypted at rest

Confirms that Neptune DB clusters are encrypted at rest.

Medium
Neptune DB clusters should publish audit logs to CloudWatch Logs

Verifies that Neptune DB clusters publish audit logs to CloudWatch Logs.

Critical
Neptune DB cluster snapshots should not be public

Flags Neptune DB cluster snapshots that are publicly accessible.

Low
Neptune DB clusters should have deletion protection enabled

Verifies that Neptune DB clusters have deletion protection enabled.

Medium
Neptune DB clusters should have automated backups enabled

Confirms that Neptune DB clusters have automated backups enabled with a retention period of at least 7 days.

Medium
Neptune DB cluster snapshots should be encrypted at rest

Confirms that Neptune DB cluster snapshots are encrypted at rest.

Medium
Neptune DB clusters should have IAM database authentication enabled

Verifies that Neptune DB clusters have IAM database authentication enabled.

Low
Neptune DB clusters should be configured to copy tags to snapshots

Ensures Neptune DB clusters are configured to copy tags to snapshots.

Medium
Neptune DB clusters should be deployed across multiple Availability Zones

Ensures Neptune DB clusters are deployed across multiple Availability Zones.

NetworkFirewall

Medium
Network Firewall firewalls should be deployed across multiple Availability Zones

Ensures AWS Network Firewall firewalls are deployed across multiple Availability Zones.

Medium
Network Firewall logging should be enabled

Confirms that logging is enabled for AWS Network Firewall with at least one log destination configured.

Low
Network Firewall firewalls should be tagged

Flags AWS Network Firewall firewalls that have no user-defined tags. Tags help associate firewalls with their owning team and VPC topology; untagged f...

Low
Network Firewall firewall policies should be tagged

Flags AWS Network Firewall firewall policies that have no user-defined tags. Tags help associate policies with their owning team and intended traffic ...

Opensearch

Medium
OpenSearch domains should have encryption at rest enabled

Verifies that OpenSearch domains have encryption at rest enabled.

Critical
OpenSearch domains should not be publicly accessible

Confirms that OpenSearch domains are deployed within a VPC rather than exposed to the public internet.

Medium
OpenSearch domains should encrypt data sent between nodes

Confirms that OpenSearch domains have node-to-node encryption enabled to protect data in transit within the cluster.

Medium
OpenSearch domain error logging to CloudWatch Logs should be enabled

Verifies that OpenSearch domains have error logging to CloudWatch Logs enabled.

Medium
OpenSearch domains should have audit logging enabled

Ensures OpenSearch domains have audit logging enabled to record and track changes for security and compliance.

Medium
OpenSearch domains should have at least three data nodes

Verifies that OpenSearch domains are configured with at least three data nodes for high availability and resilience.

High
OpenSearch domains should have fine-grained access control enabled

Ensures OpenSearch domains have fine-grained access control enabled to restrict access to domain data and configurations.

Medium
Connections to OpenSearch domains should be encrypted using the latest TLS security policy

Ensures connections to OpenSearch domains use TLS for secure data transmission.

Low
OpenSearch domains should be tagged

Flags Amazon OpenSearch Service domains that have no user-defined tags. Tags help associate domains with their owning team and data lineage; untagged ...

Medium
OpenSearch domains should have the latest software update installed

Confirms that OpenSearch Service domains have the latest available software update installed.

Low
OpenSearch domains should have at least three dedicated primary nodes

Verifies that OpenSearch Service domains have at least three dedicated primary nodes configured for cluster stability.

PCA

Low
AWS Private CA certificate authorities should be tagged

Flags AWS Private CA certificate authorities that have no user-defined tags. Tags help associate CAs with their owning team and trust hierarchy; untag...

PrivateCA

Low
AWS Private CA root certificate authority should be disabled

Flags enabled root certificate authorities in AWS Private CA. Root CAs should remain disabled except when issuing certificates to subordinate CAs, to ...

Protect

Medium
MSK clusters should be encrypted in transit among broker nodes

Confirms that Amazon MSK clusters encrypt data in transit between broker nodes using TLS, with no plain-text connections permitted.

Medium
MSK Connect connectors should be encrypted in transit

Verifies that Amazon MSK Connect connectors encrypt data in transit.

Medium
Network Firewall policies should have at least one rule group associated

Verifies that Network Firewall policies have at least one stateful or stateless rule group associated.

Critical
Amazon MSK clusters should have public access disabled

Flags Amazon MSK clusters with public access enabled.

Medium
The default stateless action for Network Firewall policies should be drop or forward for full packets

Confirms that the default stateless action for full packets in Network Firewall policies is drop or forward, not pass.

Medium
The default stateless action for Network Firewall policies should be drop or forward for fragmented packets

Verifies that the default stateless action for fragmented packets in Network Firewall policies is drop or forward, not pass.

Medium
MSK clusters should disable unauthenticated access

Confirms that unauthenticated access is disabled for Amazon MSK clusters.

Medium
Stateless network firewall rule group should not be empty

Flags Network Firewall stateless rule groups that contain no rules.

Medium
Network Firewall firewalls should have deletion protection enabled

Verifies that AWS Network Firewall firewalls have deletion protection enabled.

Medium
Network Firewall firewalls should have subnet change protection enabled

Confirms that AWS Network Firewall firewalls have subnet change protection enabled.

RDS

Critical
RDS snapshot should be private

Confirms that RDS snapshots are private and not publicly shared.

Medium
RDS DB instances should have encryption at-rest enabled

Verifies that RDS DB instances have encryption at rest enabled.

Medium
RDS cluster snapshots and database snapshots should be encrypted at rest

Verifies that RDS cluster and database snapshots are encrypted at rest.

Medium
RDS DB instances should be configured with multiple Availability Zones

Confirms that RDS instances are configured with multiple Availability Zones.

Low
Enhanced monitoring should be configured for RDS DB instances

Confirms that RDS instances have enhanced monitoring configured.

Medium
RDS clusters should have deletion protection enabled

Confirms that RDS clusters have deletion protection enabled.

Low
RDS DB instances should have deletion protection enabled

Confirms that RDS instances have deletion protection enabled.

Medium
RDS DB instances should publish logs to CloudWatch Logs

Verifies that RDS instances have database logging to CloudWatch Logs enabled.

Medium
IAM authentication should be configured for RDS instances

Verifies that RDS instances have IAM authentication configured.

Medium
RDS instances should have automatic backups enabled

Ensures RDS instances have automatic backups enabled with a retention period of at least 7 days.

Medium
IAM authentication should be configured for RDS clusters

Confirms that RDS clusters have IAM database authentication enabled.

High
RDS automatic minor version upgrades should be enabled

Confirms that RDS instances have automatic minor version upgrades enabled.

Medium
Amazon Aurora clusters should have backtracking enabled

Confirms that Amazon Aurora clusters have backtracking enabled.

Medium
RDS DB clusters should be configured for multiple Availability Zones

Confirms that RDS DB clusters are configured across multiple Availability Zones.

Low
Aurora DB clusters should be configured to copy tags to DB snapshots

Ensures RDS DB clusters are configured to copy tags to snapshots.

Low
RDS DB instances should be configured to copy tags to snapshots

Verifies that RDS instances are configured to copy tags to snapshots.

Low
Existing RDS event notification subscriptions should be configured for critical cluster events

Verifies that an RDS event subscription for DB clusters has notifications enabled for both maintenance and failure event categories.

Low
Existing RDS event notification subscriptions should be configured for critical database instance events

Confirms that an RDS event subscription for DB instances has notifications enabled for maintenance, configuration change, and failure event categories...

Low
An RDS event notifications subscription should be configured for critical database parameter group events

Verifies that an RDS event subscription is configured for critical database parameter group events.

Low
An RDS event notifications subscription should be configured for critical database security group events

Confirms that an RDS event subscription is configured for critical database security group events.

Low
RDS instances should not use a database engine default port

Flags standalone RDS instances (not cluster members) that use the default port for their database engine instead of a custom port.

Medium
RDS Database Clusters should use a custom administrator username

Flags RDS database clusters using default admin usernames such as admin, root, sa, oracle, or postgres.

Medium
RDS database instances should use a custom administrator username

Flags RDS database instances using default admin usernames such as admin, root, sa, oracle, or postgres.

Medium
RDS DB instances should be protected by a backup plan

Verifies that RDS DB instances have a backup retention period greater than zero.

Medium
RDS DB clusters should be encrypted at rest

Verifies that RDS DB clusters are encrypted at rest.

Low
RDS DB clusters should be tagged

Flags Amazon RDS DB clusters that have no user-defined tags. Tags help associate clusters with their owning team, environment, and cost centre; untagg...

Low
RDS DB cluster snapshots should be tagged

Flags Amazon RDS DB cluster snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; untag...

Low
RDS DB instances should be tagged

Flags Amazon RDS DB instances that have no user-defined tags. Tags help associate instances with their owning team, environment, and cost centre; unta...

Low
RDS DB security groups should be tagged

Flags legacy EC2-Classic RDS DB security groups that have no user-defined tags. EC2-Classic was retired in 2022; this control only emits findings in a...

Low
RDS DB snapshots should be tagged

Flags Amazon RDS DB snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; untagged snap...

Low
RDS DB subnet groups should be tagged

Flags Amazon RDS DB subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; untagged subne...

Medium
Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs

Verifies that Aurora MySQL DB clusters are configured to publish audit logs to CloudWatch Logs.

Medium
RDS DB clusters should have automatic minor version upgrade enabled

Ensures automatic minor version upgrade is enabled for RDS Multi-AZ DB clusters.

Medium
RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs

Verifies that RDS for PostgreSQL instances publish postgresql logs to CloudWatch Logs.

Medium
Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs

Verifies that Aurora PostgreSQL DB clusters publish postgresql logs to CloudWatch Logs.

Medium
RDS for PostgreSQL DB instances should be encrypted in transit

Ensures RDS for PostgreSQL instances enforce SSL connections via the rds.force_ssl parameter.

Medium
RDS for MySQL DB instances should be encrypted in transit

Confirms that RDS for MySQL instances require SSL connections via the require_ssl parameter.

Medium
RDS for SQL Server DB instances should publish logs to CloudWatch Logs

Verifies that RDS for SQL Server instances publish error logs to CloudWatch Logs.

Medium
RDS for SQL Server DB instances should be encrypted in transit

Confirms that RDS for SQL Server instances require SSL connections via the require_ssl parameter.

Medium
RDS for MariaDB DB instances should publish logs to CloudWatch Logs

Verifies that RDS for MariaDB instances publish error logs to CloudWatch Logs.

Medium
RDS DB proxies should require TLS encryption for connections

Flags Amazon RDS DB proxies that do not require TLS for client connections. Without RequireTLS, traffic between the client and the proxy traverses the...

Medium
RDS for MariaDB DB instances should be encrypted in transit

Confirms that RDS for MariaDB instances require SSL connections via the require_ssl parameter.

Medium
Aurora MySQL DB clusters should have audit logging enabled

Confirms that Aurora MySQL DB clusters have audit logging enabled via the server_audit_logs parameter.

High
RDS DB instances should not be deployed in public subnets with routes to internet gateways

Flags Amazon RDS DB instances whose subnet group includes at least one subnet with a default route to an Internet Gateway. Public subnets give the ins...

Low
RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots

Flags PostgreSQL-engine RDS DB clusters whose CopyTagsToSnapshot is disabled. Without this setting, snapshots taken from the cluster lose ownership/co...

Low
RDS for MySQL DB clusters should be configured to copy tags to DB snapshots

Flags MySQL-engine RDS DB clusters whose CopyTagsToSnapshot is disabled. Without this setting, snapshots taken from the cluster lose ownership/cost-al...

Medium
RDS DB clusters should have enough backup retention period set

Flags Amazon RDS DB clusters whose backup retention period is shorter than 7 days. A short retention window narrows the recovery point objective and r...

High
RDS global clusters should run on a supported Aurora MySQL version

Flags Amazon RDS global clusters running on an Aurora MySQL minor version older than the current AWS standard-support window. Extended-support version...

Redshift

High
Redshift Serverless workgroups should prohibit public access

Flags Redshift Serverless workgroups configured to allow public access.

Critical
Amazon Redshift clusters should prohibit public access

Flags Redshift clusters that are publicly accessible.

Medium
Connections to Amazon Redshift clusters should be encrypted in transit

Ensures connections to Redshift clusters require encryption in transit.

Medium
Connections to Redshift Serverless workgroups should be required to use SSL

Verifies that Redshift Serverless workgroups require SSL for all connections.

Medium
Amazon Redshift clusters should have automatic snapshots enabled

Confirms that Redshift clusters have automated snapshots enabled and retained for at least seven days.

Medium
Amazon Redshift Serverless workgroups should use enhanced VPC routing

Verifies that Redshift Serverless workgroups have enhanced VPC routing enabled.

Medium
Amazon Redshift clusters should have audit logging enabled

Verifies that Redshift clusters have audit logging enabled.

Medium
Amazon Redshift should have automatic upgrades to major versions enabled

Ensures automatic major version upgrades are enabled for Redshift clusters.

Medium
Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys

Confirms that Redshift Serverless namespaces use customer managed KMS keys for encryption.

Medium
Redshift clusters should use enhanced VPC routing

Confirms that Redshift clusters have Enhanced VPC Routing enabled to route COPY and UNLOAD traffic through the VPC.

Medium
Redshift Serverless namespaces should not use the default admin username

Confirms that Redshift Serverless namespaces use a non-default admin username.

Medium
Amazon Redshift clusters should not use the default Admin username

Flags Redshift clusters using the default admin username.

Medium
Redshift Serverless namespaces should export logs to CloudWatch Logs

Ensures Redshift Serverless namespaces export logs to CloudWatch Logs.

Medium
Redshift clusters should be encrypted at rest

Verifies that Redshift clusters are encrypted at rest.

Low
Redshift clusters should be tagged

Flags Amazon Redshift clusters that have no user-defined tags. Tags help associate clusters with their owning team and data lineage; untagged clusters...

Low
Redshift event notification subscriptions should be tagged

Flags Amazon Redshift event notification subscriptions that have no user-defined tags. Tags help associate subscriptions with their owning team and do...

Low
Redshift cluster snapshots should be tagged

Flags Amazon Redshift cluster snapshots that have no user-defined tags. Tags help associate snapshots with their owning team and retention policy; unt...

Low
Redshift cluster subnet groups should be tagged

Flags Amazon Redshift cluster subnet groups that have no user-defined tags. Tags help associate subnet groups with their owning network and team; unta...

High
Redshift security groups should allow ingress on the cluster port only from restricted origins

Flags Redshift cluster security groups that allow unrestricted ingress (0.0.0.0/0 or ::/0) to the cluster port.

Medium
Redshift cluster subnet groups should have subnets from multiple Availability Zones

Verifies that Redshift cluster subnet groups contain subnets from at least two Availability Zones.

Low
Redshift cluster parameter groups should be tagged

Flags Amazon Redshift cluster parameter groups that have no user-defined tags. Tags help associate parameter groups with their owning team and policy ...

Medium
Redshift clusters should have Multi-AZ deployments enabled

Confirms that Multi-AZ deployment is enabled for Redshift clusters.

RedshiftServerless

High
Amazon Redshift Serverless workgroups should use enhanced VPC routing

Flags Amazon Redshift Serverless workgroups that do not have enhanced VPC routing enabled. Without it, COPY/UNLOAD traffic between the workgroup and o...

High
Redshift Serverless workgroups should prohibit public access

Flags Amazon Redshift Serverless workgroups whose publiclyAccessible setting is true. Public workgroups receive a public IP address and are reachable ...

Medium
Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys

Flags Amazon Redshift Serverless namespaces that are not encrypted with a customer-managed KMS key. AWS-owned and AWS-managed keys cannot be audited v...

Medium
Redshift Serverless namespaces should not use the default admin username

Flags Amazon Redshift Serverless namespaces whose admin username matches the AWS default. The default is well known and removing it reduces the value ...

Medium
Redshift Serverless namespaces should export logs to CloudWatch Logs

Flags Amazon Redshift Serverless namespaces that do not export user, connection, and user-activity logs to CloudWatch. Without these exports, detectio...

Route53

Low
Route 53 health checks should be tagged

Flags Amazon Route 53 health checks that have no user-defined tags. Tags help associate health checks with their owning team and dependent application...

Medium
Route 53 public hosted zones should log DNS queries

Confirms that DNS query logging is enabled for Route 53 public hosted zones.

S3

Medium
S3 general purpose buckets should have block public access settings enabled

Confirms that the S3 Block Public Access setting is enabled at the account level.

Critical
S3 general purpose buckets should block public read access

Verifies that S3 buckets block public read access through both ACLs and bucket policies, including policies granting s3:GetObject or wildcard actions ...

Critical
S3 general purpose buckets should block public write access

Confirms that S3 buckets block public write access through both ACLs and bucket policies.

Medium
S3 general purpose buckets should require requests to use SSL

Ensures S3 buckets require all requests to use SSL.

High
S3 general purpose bucket policies should restrict access to other AWS accounts

Flags S3 bucket policies that grant overly permissive access to other AWS accounts.

Low
S3 general purpose buckets should use cross-Region replication

Verifies that S3 buckets have cross-Region replication enabled.

High
S3 general purpose buckets should block public access

Ensures Block Public Access settings are enabled at the individual S3 bucket level.

Medium
S3 general purpose buckets should have server access logging enabled

Verifies that S3 bucket server access logging is enabled.

Medium
S3 general purpose buckets with versioning enabled should have Lifecycle configurations

Confirms that versioned S3 buckets have a lifecycle configuration to manage non-current object versions.

Medium
S3 general purpose buckets should have event notifications enabled

Verifies that S3 general purpose buckets have event notifications enabled.

Medium
ACLs should not be used to manage user access to S3 general purpose buckets

Flags S3 buckets that use ACLs to manage user access, which should be replaced with bucket policies.

Low
S3 general purpose buckets should have Lifecycle configurations

Confirms that S3 buckets have lifecycle policies configured for object management.

Low
S3 general purpose buckets should have versioning enabled

Verifies that S3 buckets have versioning enabled.

Medium
S3 general purpose buckets should have Object Lock enabled

Confirms that S3 buckets are configured to use Object Lock for immutable storage.

Medium
S3 general purpose buckets should be encrypted at rest with AWS KMS keys

Confirms that S3 buckets are encrypted at rest using AWS KMS keys.

Critical
S3 access points should have block public access settings enabled

Verifies that S3 access points have all Block Public Access settings enabled.

Low
S3 general purpose buckets should have MFA delete enabled

Verifies that MFA delete is enabled for S3 general purpose buckets, requiring multi-factor authentication for object deletion.

Medium
S3 general purpose buckets should log object-level write events

Confirms that at least one CloudTrail multi-Region trail is configured to log all S3 object write events.

Medium
S3 general purpose buckets should log object-level read events

Verifies that at least one CloudTrail multi-Region trail is configured to log all S3 object read events.

High
S3 Multi-Region Access Points should have block public access settings enabled

Verifies that S3 Multi-Region Access Points have Block Public Access settings enabled.

Low
S3 directory buckets should have lifecycle configurations

Ensures S3 directory buckets have lifecycle rules configured.

SES

Low
SES contact lists should be tagged

Flags Amazon SES contact lists that have no user-defined tags. Tags help associate contact lists with their owning team and campaign; untagged contact...

Low
SES configuration sets should be tagged

Flags Amazon SES configuration sets that have no user-defined tags. Tags help associate configuration sets with their owning team and use case; untagg...

Medium
SES configuration sets should have TLS enabled for sending emails

Flags Amazon SES configuration sets whose delivery options do not require TLS. When TLS is optional, SES falls back to unencrypted SMTP whenever the r...

SNS

Medium
SNS topics should be encrypted at-rest using AWS KMS

Verifies that SNS topics are encrypted at rest using a KMS key.

Low
SNS topics should be tagged

Flags Amazon SNS topics that have no user-defined tags. Tags help associate topics with their owning team and downstream subscribers; untagged topics ...

Critical
SNS topic access policies should not allow public access

Flags SNS topic access policies that allow public access.

SQS

Medium
Amazon SQS queues should be encrypted at rest

Confirms that SQS queues are encrypted at rest using SSE-SQS or an AWS KMS key.

Low
SQS queues should be tagged

Flags Amazon SQS queues that have no user-defined tags. Tags help associate queues with their owning team and message producers/consumers; untagged qu...

Critical
SQS queue access policies should not allow public access

Flags SQS queue access policies that allow public access.

SSM

Medium
EC2 instances should be managed by AWS Systems Manager

Confirms that EC2 instances are managed by AWS Systems Manager.

High
EC2 instances managed by Systems Manager should have a patch compliance status of COMPLIANT after a patch installation

Verifies that Systems Manager patch compliance on EC2 instances shows a compliant status.

Low
EC2 instances managed by Systems Manager should have an association compliance status of COMPLIANT

Verifies that Systems Manager associations on EC2 instances are in a compliant state.

Critical
SSM documents should not be public

Flags account-owned SSM documents that are publicly shared, which may expose sensitive configuration information.

Low
SSM documents should be tagged

Flags AWS Systems Manager documents that have no user-defined tags. Tags help associate documents with their owning team and use case; untagged docume...

Medium
SSM Automation should have CloudWatch logging enabled

Verifies that CloudWatch logging is enabled for AWS Systems Manager Automation.

Critical
SSM documents should have the block public sharing setting enabled

Ensures the block public sharing setting is enabled for SSM documents.

SageMaker

High
Amazon SageMaker notebook instances should not have direct internet access

Confirms that direct internet access is disabled for SageMaker notebook instances.

High
SageMaker notebook instances should be launched in a custom VPC

Ensures SageMaker notebook instances are launched within a custom VPC.

High
Users should not have root access to SageMaker notebook instances

Flags SageMaker notebook instances that have root access enabled.

Medium
SageMaker endpoint production variants should have an initial instance count greater than 1

Confirms that SageMaker endpoint production variants are configured with more than one initial instance to avoid single points of failure.

Medium
SageMaker models should have network isolation enabled

Verifies that SageMaker hosted models have network isolation enabled, preventing the model container from making outbound network calls.

Low
SageMaker app image configurations should be tagged

Flags SageMaker app image configuration that have no user-defined tags. Tags help associate SageMaker app image configuration with their owning team a...

Low
SageMaker images should be tagged

Flags SageMaker image that have no user-defined tags. Tags help associate SageMaker image with their owning team and use case; untagged images are ope...

Medium
SageMaker notebook instances should run on supported platforms

Verifies that SageMaker notebook instances are configured to run on a supported platform version.

Medium
SageMaker data quality job definitions should have inter-container traffic encryption enabled

Flags Amazon SageMaker data quality monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled. Without it, traf...

Medium
SageMaker model explainability job definitions should have inter-container traffic encryption enabled

Flags Amazon SageMaker model-explainability monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.

Medium
SageMaker data quality job definitions should have network isolation enabled

Flags Amazon SageMaker data quality monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the container...

Medium
SageMaker model bias job definitions should have network isolation enabled

Flags Amazon SageMaker model-bias monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled.

Medium
SageMaker model quality job definitions should have inter-container traffic encryption enabled

Flags Amazon SageMaker model-quality monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.

Medium
SageMaker monitoring schedules should have network isolation enabled

Flags Amazon SageMaker monitoring schedules whose underlying job definition has NetworkConfig.EnableNetworkIsolation disabled. The schedule inherits t...

Medium
SageMaker model bias job definitions should have inter-container traffic encryption enabled

Flags Amazon SageMaker model-bias monitoring job definitions whose NetworkConfig.EnableInterContainerTrafficEncryption is disabled.

Medium
SageMaker models should use private registry in VPC for primary containers

Flags SageMaker models whose PrimaryContainer pulls images via the public ECR endpoint rather than a private-VPC registry. Setting ImageConfig.Reposit...

Medium
SageMaker feature group offline stores should be encrypted with AWS KMS keys

Flags Amazon SageMaker feature groups whose offline store does not specify a KMS key. Without an explicit KmsKeyId, the underlying S3 storage relies o...

Medium
SageMaker feature group online stores with standard storage should be encrypted with AWS KMS keys

Flags Amazon SageMaker feature groups whose online store uses standard storage without a KMS key. Without an explicit KmsKeyId the online store relies...

Medium
SageMaker models should use private registry in VPC for multi-container inference pipelines

Flags SageMaker inference-pipeline models whose Containers[] pull images via the public ECR endpoint. Every container in the pipeline must set ImageCo...

High
SageMaker model explainability job definitions should have network isolation enabled

Flags Amazon SageMaker model explainability monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the c...

Medium
SageMaker notebook instances should be encrypted with customer managed AWS KMS keys

Flags Amazon SageMaker notebook instances that have no KMS key configured for storage-volume encryption. Without a KmsKeyId the volume is encrypted wi...

Medium
SageMaker monitoring schedules should have inter-container traffic encryption enabled

Flags Amazon SageMaker monitoring schedules whose underlying job definition does not enable inter-container traffic encryption. Traffic between distri...

Medium
SageMaker inference experiments should have instance storage volume encrypted with customer managed AWS KMS keys

Flags Amazon SageMaker inference experiments with no KMS key for instance-storage-volume encryption. Without a key the ML storage volume relies on the...

Medium
SageMaker inference experiments should have data storage encrypted with customer managed AWS KMS keys

Flags Amazon SageMaker inference experiments that capture data but specify no KMS key for the captured data at rest. Applies only when data storage ca...

High
SageMaker model quality job definitions should have network isolation enabled

Flags Amazon SageMaker model quality monitoring job definitions whose NetworkConfig.EnableNetworkIsolation is disabled. Without isolation the containe...

SecretsManager

Medium
Secrets Manager secrets should have automatic rotation enabled

Verifies that secrets stored in Secrets Manager are configured for automatic rotation.

Medium
Secrets Manager secrets configured with automatic rotation should rotate successfully

Confirms that Secrets Manager secrets have rotated successfully according to their rotation schedule.

Medium
Remove unused Secrets Manager secrets

Flags secrets that have not been accessed within 90 days, indicating they may be stale or unused.

Medium
Secrets Manager secrets should be rotated within a specified number of days

Flags secrets that have not been rotated within the last 90 days.

Low
Secrets Manager secrets should be tagged

Flags AWS Secrets Manager secrets that have no user-defined tags. Tags help associate secrets with their owning team and consuming application; untagg...

ServiceCatalog

Medium
Service Catalog portfolios should be shared within an AWS organization only

Confirms that Service Catalog portfolios are shared only within the AWS organization when Organizations integration is enabled.

StepFunctions

Medium
Step Functions state machines should have logging turned on

Confirms that Step Functions state machines have logging enabled.

Low
Step Functions activities should be tagged

Flags AWS Step Functions activities that have no user-defined tags. Tags help associate activities with their owning team and consuming state machine;...

Transfer

Low
Transfer Family workflows should be tagged

Flags AWS Transfer Family workflows that have no user-defined tags. Tags help associate workflows with their owning team and trading partner; untagged...

Medium
Transfer Family servers should not use FTP protocol for endpoint connection

Flags Transfer Family servers that use FTP for endpoint connections. FTP transmits data in plaintext and should be replaced with SFTP or FTPS.

Medium
Transfer Family connectors should have logging enabled

Verifies that CloudWatch logging is enabled for AWS Transfer Family connectors.

Low
Transfer Family agreements should be tagged

Flags AWS Transfer Family agreements that have no user-defined tags. Tags help associate AS2 agreements with their owning team and trading partner; un...

Low
Transfer Family certificates should be tagged

Flags AWS Transfer Family certificates that have no user-defined tags. Tags help associate certificates with their owning team and trading partner; un...

Low
Transfer Family connectors should be tagged

Flags AWS Transfer Family connectors that have no user-defined tags. Tags help associate connectors with their owning team and trading partner; untagg...

Low
Transfer Family profiles should be tagged

Flags AWS Transfer Family profiles that have no user-defined tags. Tags help associate AS2 profiles (local and partner) with their owning team and tra...

WAF

Medium
AWS WAF Classic Global Web ACL logging should be enabled

Verifies that logging is enabled for AWS WAF global web ACLs.

Medium
AWS WAF Classic Regional rules should have at least one condition

Verifies that AWS WAF Regional rules contain at least one condition.

Medium
AWS WAF Classic Regional rule groups should have at least one rule

Confirms that AWS WAF Regional rule groups contain at least one rule.

Medium
AWS WAF Classic Regional web ACLs should have at least one rule or rule group

Confirms that AWS WAF Regional web ACLs contain at least one rule or rule group.

Medium
AWS WAF Classic global rules should have at least one condition

Confirms that AWS WAF global rules contain at least one condition.

Medium
AWS WAF Classic global rule groups should have at least one rule

Verifies that AWS WAF global rule groups contain at least one rule.

Medium
AWS WAF Classic global web ACLs should have at least one rule or rule group

Confirms that AWS WAF global web ACLs contain at least one rule or rule group.

Medium
AWS WAF web ACLs should have at least one rule or rule group

Confirms that WAFv2 web ACLs contain at least one rule or rule group.

Low
AWS WAF web ACL logging should be enabled

Verifies that logging is enabled for WAFv2 web ACLs.

Medium
AWS WAF rules should have CloudWatch metrics enabled

Ensures CloudWatch metrics are enabled for AWS WAF rules and rule groups.

WorkSpaces

Medium
WorkSpaces user volumes should be encrypted at rest

Verifies that WorkSpaces user volumes are encrypted at rest.

Medium
WorkSpaces root volumes should be encrypted at rest

Confirms that WorkSpaces root volumes are encrypted at rest.