Cloud Security: AWS Foundations
AWS 170 automated checks
Industry-standard cloud security hardening rules aligned with cloud foundations benchmarks
General
- EC2 instance must have detailed monitoring enabled
- EC2 instance must enforce IMDSv2 (metadata tokens required)
- EC2 instance should be EBS-optimized
- EC2 instance must have an IAM instance profile attached
- Security group must not allow unrestricted ingress (0.0.0.0/0)
- EBS volume must be encrypted
- EBS volume should use a customer-managed KMS key
- VPC must have flow logs enabled
- VPC must have DNS support enabled
- Subnet should not auto-assign public IPs
- Network interface should not have a public IP unless required
- NAT gateway must be in available state
- Internet gateway must be attached to a VPC
- Lambda function must not use a deprecated runtime
- Lambda function should have a reasonable timeout configured
- Lambda function should be deployed in a VPC
- Lambda function should have a dead-letter queue configured
- Lambda function must have X-Ray tracing enabled
- ECS cluster must have Container Insights enabled
- ECS service must not assign public IPs to tasks
- EKS cluster must disable public API endpoint access
- EKS cluster must enable private API endpoint access
- EKS cluster must have control plane logging enabled
- EKS cluster must have envelope encryption for secrets
- Auto Scaling group should use ELB health checks
- Launch template must enforce IMDSv2
- Launch template should have detailed monitoring enabled
- Lightsail instance should be reviewed for migration to EC2
- S3 bucket must have server-side encryption enabled
- S3 bucket must have versioning enabled
- S3 bucket must block public ACLs
- S3 bucket must block public bucket policies
- S3 bucket must restrict public bucket access
- S3 bucket must have access logging enabled
- S3 bucket should use SSE-KMS encryption algorithm
- EFS file system must be encrypted at rest
- Backup vault must use a KMS encryption key
- ECR repository must have image scan on push enabled
- ECR repository must have immutable image tags
- ECR repository should use KMS encryption
- Glacier vault must exist and be configured
- FSx file system must be encrypted
- Storage Gateway must be operational
- RDS instance must have storage encryption enabled
- RDS instance must not be publicly accessible
- RDS instance must have Multi-AZ enabled
- RDS instance must have IAM database authentication enabled
- RDS instance must have deletion protection enabled
- RDS instance must have auto minor version upgrade enabled
- RDS cluster must have storage encryption enabled
- RDS cluster must have deletion protection enabled
- RDS cluster must have IAM database authentication enabled
- RDS cluster must have sufficient backup retention period
- DynamoDB table must have server-side encryption enabled
- DynamoDB table must have point-in-time recovery enabled
- ElastiCache cluster must have in-transit encryption enabled
- ElastiCache cluster must have at-rest encryption enabled
- ElastiCache replication group must have in-transit encryption enabled
- ElastiCache replication group must have at-rest encryption enabled
- ElastiCache replication group must have automatic failover enabled
- Redshift cluster must be encrypted
- Redshift cluster must not be publicly accessible
- Redshift cluster must have audit logging enabled
- Redshift cluster should use enhanced VPC routing
- Neptune cluster must have storage encryption enabled
- Neptune cluster must have IAM database authentication enabled
- Neptune cluster must have deletion protection enabled
- DocumentDB cluster must have storage encryption enabled
- DocumentDB cluster must have deletion protection enabled
- Elasticsearch domain must have encryption at rest enabled
- Elasticsearch domain must have node-to-node encryption enabled
- Elasticsearch domain must enforce HTTPS
- MemoryDB cluster must have TLS enabled
- Keyspaces table should use customer-managed KMS encryption
- Timestream database must use a KMS key for encryption
- Load balancer must have access logging enabled
- Load balancer must have deletion protection enabled
- Load balancer listener must use HTTPS protocol
- Load balancer listener must use a secure SSL policy
- CloudFront distribution must enforce HTTPS viewer protocol
- CloudFront distribution must use TLS 1.2 minimum
- CloudFront distribution must have access logging enabled
- CloudFront distribution should have a WAF web ACL associated
- Route53 hosted zone should have DNSSEC signing enabled
- API Gateway REST API must have an endpoint configuration
- API Gateway V2 API must be properly configured
- VPN gateway must be attached and operational
- Global Accelerator must be enabled
- Direct Connect connection should use MACsec encryption
- Transit gateway must not auto-accept shared attachments
- IAM user must have MFA enabled
- IAM user should not have more than one active access key
- IAM role must have a trust policy configured
- IAM policy must be attached and in use
- IAM group should be used for permission management
- KMS key must have automatic key rotation enabled
- KMS key must be in enabled state
- Secrets Manager secret must have rotation enabled
- Secrets Manager secret should use a customer-managed KMS key
- ACM certificate must be in issued status
- ACM certificate must be eligible for renewal
- WAFv2 web ACL must be deployed
- Shield protection must be active on critical resources
- GuardDuty detector must be enabled
- Security Hub must have auto-enable controls active
- Inspector coverage must be active
- Macie session must be enabled
- SSM Parameter for sensitive data must use SecureString type
- AWS Config configuration recorder must be recording
- AWS Config must record all supported resource types
- CloudTrail trail must be multi-region
- CloudTrail trail must be actively logging
- CloudTrail trail must have log file validation enabled
- CloudTrail trail should be encrypted with a KMS key
- CloudWatch log group must have a retention period configured
- CloudWatch log group should be encrypted with a KMS key
- CloudWatch alarm must have actions enabled
- SNS topic must be encrypted with a KMS key
- SQS queue must be encrypted with a KMS key
- SQS queue should have a dead-letter queue configured
- EventBridge rule must be in enabled state
- Kinesis stream must use KMS encryption
- Firehose delivery stream must have encryption enabled
- Cognito user pool must enforce MFA
- Cognito user pool must have deletion protection enabled
- AppSync API must have X-Ray tracing enabled
- AppSync API must have logging configured
- Step Functions state machine must have logging enabled
- Step Functions state machine must have tracing enabled
- CodeBuild project must use a KMS encryption key
- CodeBuild project should not run in privileged mode
- CodePipeline must use an encrypted artifact store
- Amplify app should have basic auth disabled for production
- App Runner service must have encryption enabled
- Elastic Beanstalk environment must be in healthy state
- Batch compute environment must be in enabled state
- MWAA environment must use private web server access
- MWAA environment should use a customer-managed KMS key
- Glue database must be cataloged and accessible
- Athena workgroup must enforce workgroup configuration
- Athena workgroup must have query result encryption enabled
- EMR cluster must have termination protection enabled
- EMR cluster must have a security configuration
- SageMaker notebook instance must not have direct internet access
- SageMaker notebook instance must be encrypted with a KMS key
- SageMaker notebook instance should disable root access
- SageMaker endpoint must be encrypted with a KMS key
- MSK cluster must enforce TLS encryption for client-broker communication
- MSK cluster must have encryption at rest with a KMS key
- Lake Formation resource must be registered
- QuickSight dashboard must be properly configured
- CloudFormation stack must have termination protection enabled
- Service Catalog portfolio must be configured
- Organizations account must be in active status
- RAM resource share must not allow external principals
- SSO permission set must be configured
- Transfer Family server should use VPC endpoint
- Transfer Family server should use a managed identity provider
- IoT thing must be registered and configured
- WorkSpaces workspace must have user volume encryption enabled
- WorkSpaces workspace must have root volume encryption enabled
- Prefer IAM roles over access keys for programmatic access
- CloudWatch log group retention should be at least 90 days
- RDS cluster backup retention should be at least 14 days
- S3 bucket encryption should use SSE-KMS with a customer-managed key
- Lambda function should have a short timeout for API-driven functions
- EC2 instance must not use a deprecated instance metadata version
- EKS cluster should enable all audit log types
- Redshift cluster must not use default database name
- CloudFront distribution should use origin access identity or control
Measure your Cloud Security: AWS Foundations posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.