Cloud Foundations Benchmark v3.0
AWS 34 automated checks
Cloud foundations security benchmark v3.0 — security best practices for cloud accounts
General
- IAM root user must not have access keys
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- S3 bucket must block all public access
- S3 bucket must have server-side encryption enabled
- S3 bucket must have versioning enabled
- CloudTrail must be enabled in all regions
- AWS Config must be enabled in all regions
- EFS file system must be encrypted at rest
Identity and Access Management
Logging
Monitoring
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
Networking
- Security group must not allow unrestricted ingress (0.0.0.0/0)
- Security group must not allow unrestricted ingress (0.0.0.0/0)
- IAM password policy must require minimum length of 14
- VPC must have flow logs enabled
- EC2 instance must enforce IMDSv2 (metadata tokens required)
- Subnet should not auto-assign public IPs
Storage
Measure your Cloud Foundations Benchmark v3.0 posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.