ISO 27001: Information Security
AWS 55 automated checks
Information security management controls aligned with ISO/IEC 27001:2022 Annex A for AWS resources
Access Control (A.9)
Asset Management (A.8)
Communications Security (A.13)
Cryptography (A.10)
- S3 bucket encryption should use SSE-KMS with a customer-managed key
- S3 bucket must have server-side encryption enabled
- RDS instance must have storage encryption enabled
- RDS cluster must have storage encryption enabled
- EBS volume must be encrypted
- EBS volume should use a customer-managed KMS key
- DynamoDB table must have server-side encryption enabled
- EFS file system must be encrypted at rest
- KMS key must have automatic key rotation enabled
- CloudFront distribution must use TLS 1.2 minimum
- Load balancer listener must use a secure SSL policy
- Elasticsearch domain must enforce HTTPS
- ElastiCache replication group must have in-transit encryption enabled
ISMS Audit
Operations Security (A.12)
Organizational Controls (A.5)
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- Organization should maintain an information security policy approved by management
- Organization should define information security roles and responsibilities
- Organization should maintain contact with relevant authorities
- Organization should collect and analyze threat intelligence
- Organization should integrate security into project management
- Organization should maintain an inventory of information assets
- Organization should classify information according to confidentiality requirements
- Organization should manage information security in supplier relationships
- Organization should establish incident management procedures
- Organization should have procedures for evidence collection and preservation
- Organization should integrate security into business continuity management
- Organization should identify applicable legal and regulatory requirements
People Controls (A.6)
- IAM password policy must require minimum length of 14
- Organization should perform personnel screening
- Organization should provide information security awareness and training
- Organization should have a disciplinary process for security violations
- Organization should define security responsibilities upon termination
Physical Controls (A.7)
Measure your ISO 27001: Information Security posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.