SECURITY ASSESSMENT REPORT
Technology: Amazon Complete CIS
Tenant: AKIA4PUJ2P2LBWDOJXWQ_AWS-Cloud-Complete
Assessment Date: 07/16/2026 05:54:27
Tests Evaluated:316
This Introduction contains a global summary of the security scans performed on the company infrastructure. Detailed information about the scans can be found in the corresponding section in this report. The assessment was performed according to settings recommended by CIS. More Information about CIS can be found here: CIS Benchmarks. There are tests that also recommended by vendor have been performed too.
0Critical
60High
2Medium
0Low
232Passed
13Manual Check
OVERALL TENANT STATUS
Shows overall score settings that need to be configured correctly in Tenant as per CIS Benchmark. These settings are recommended by CIS.
CIS SECURITY SCORE
Shows overall score settings that need to be configured correctly in Tenant. These settings are recommended by Experts not included in CIS.
SP SECURITY SCORE
Technology Categories and Status
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure security contact information is registered | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure security contact information is registered Description AWS provides customers with the option of specifying the contact information for account's security team. It is recommended that this information be provided. Rationale Specifying security-specific contact information will help ensure that security advisories sent by AWS reach the team in your organization that is best equipped to respond to them. Impact Recommendation and Steps Perform the following to establish security contact information: From Console: 1. Click on your account name at the top right corner of the console. 2. From the drop-down menu Click My Account 3. Scroll down to the Alternate Contacts section 4. Enter contact information in the Security section From Command Line: Run the following command with the following input parameters: --email-address, --name, and --phone-number. aws account put-alternate-contact --alternate-contact-type SECURITY Note: Consider specifying an internal email distribution list to ensure emails are regularly monitored by more than one individual. Associated Items
Affected Objects |
| Ensure security questions are registered in the AWS account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
X TEST NAME Ensure security questions are registered in the AWS account Description The AWS support portal allows account owners to establish security questions that can be used to authenticate individuals calling AWS customer service for support. It is recommended that security questions be established. Rationale When creating a new AWS account, a default super user is automatically created. This account is referred to as the 'root user' or 'root' account. It is recommended that the use of this account be limited and highly controlled. During events in which the 'root' password is no longer accessible or the MFA token associated with 'root' is lost/destroyed it is possible, through authentication using secret questions and associated answers, to recover 'root' user login access. Impact Recommendation and Steps From Console: 1. Login to the AWS Account as the 'root' user 2. Click on the Associated Items
Affected Objects
|
| Ensure MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
X TEST NAME Ensure MFA is enabled for the root user account Description The 'root' user account is the most privileged user in an AWS account. Multi-factor Authentication (MFA) adds an extra layer of protection on top of a username and password. With MFA enabled, when a user signs in to an AWS website, they will be prompted for their username and password as well as for an authentication code from their AWS MFA device. Note: When virtual MFA is used for 'root' accounts, it is recommended that the device used is NOT a personal device, but rather a dedicated mobile device (tablet or phone)that is managed to be kept charged and secured independent of any individual personal devices. (non-personal virtual MFA) This lessens the risks of losing access to the MFA due to device loss, device trade-in or if the individual owning the device is no longer employed at the company. Rationale Enabling MFA provides increased security for console access as it requires theauthenticating principal to possess a device that emits a time-sensitive key and haveknowledge of a credential. Impact Recommendation and Steps Perform the following to establish MFA for the 'root' user account: 1. Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. Note: to manage MFA devices for the 'root' AWS account, you must use your 'root' account credentials to sign in to AWS. You cannot manage MFA devices for the 'root' account using other credentials. 2. Choose Dashboard , and under Security Status , expand Activate MFA on your root account. 3. Choose Activate MFA 4. In the wizard, choose A virtual MFA device and then choose Next Step . 5. IAM generates and displays configuration information for the virtual MFA device, including a QR code graphic. The graphic is a representation of the 'secret configuration key' that is available for manual entry on devices that do not support QR codes. 6. Open your virtual MFA application. (For a list of apps that you can use for hosting virtual MFA devices, see Virtual MFA Applications.) If the virtual MFA application supports multiple accounts (multiple virtual MFA devices), choose the option to create a new account (a new virtual MFA device). 7. Determine whether the MFA app supports QR codes, and then do one of the following: o Use the app to scan the QR code. For example, you might choose the camera icon or choose an option similar to Scan code, and then use the device's camera to scan the code. o In the Manage MFA Device wizard, choose Show secret key for manual configuration, and then type the secret configuration key into your MFA application. When you are finished, the virtual MFA device starts generating one-time passwords. In the Manage MFA Device wizard, in the Authentication Code 1 box, type the one-time password that currently appears in the virtual MFA device. Wait up to 30 seconds for the device to generate a new one-time password. Then type the second one-time password into the Authentication Code 2 box. Choose Assign Virtual MFA. Associated Items
Affected Objects
|
| Ensure hardware MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
X TEST NAME Ensure hardware MFA is enabled for the root user account Description The 'root' user account is the most privileged user in an AWS account. MFA adds anextra layer of protection on top of a user name and password. With MFA enabled, whena user signs in to an AWS website, they will be prompted for their user name and password as well as for an authentication code from their AWS MFA device. For Level2, it is recommended that the 'root' user account be protected with a hardware MFA. Rationale A hardware MFA has a smaller attack surface than a virtual MFA. For example, ahardware MFA does not suffer the attack surface introduced by the mobile smartphoneon which a virtual MFA resides.Note: Using hardware MFA for many, many AWS accounts may create a logisticaldevice management issue. If this is the case, consider implementing this Level 2recommendation selectively to the highest security AWS accounts and the Level 1recommendation applied to the remaining accounts. Impact Recommendation and Steps Perform the following to establish a hardware MFA for the 'root' user account: 1. Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. Note: to manage MFA devices for the AWS 'root' user account, you must use your 'root' account credentials to sign in to AWS. You cannot manage MFA devices for the 'root' account using other credentials. 2. Choose Dashboard , and under Security Status , expand Activate MFA on your root account. 3. Choose Activate MFA 4. In the wizard, choose A hardware MFA device and then choose Next Step . 5. In the Serial Number box, enter the serial number that is found on the back of the MFA device. 6. In the Authentication Code 1 box, enter the six-digit number displayed by the MFA device. You might need to press the button on the front of the device to display the number. 7. Wait 30 seconds while the device refreshes the code, and then enter the next six-digit number into the Authentication Code 2 box. You might need to press the button on the front of the device again to display the second number. 8. Choose Next Step . The MFA device is now associated with the AWS account. The next time you use your AWS account credentials to sign in, you must type a code from the hardware MFA device. Remediation for this recommendation is not available through AWS CLI. Associated Items
Affected Objects
|
| Ensure IAM password policy requires minimum length of 14 or greater | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
X TEST NAME Ensure IAM password policy requires minimum length of 14 or greater Description Password policies are, in part, used to enforce password complexity requirements. IAMpassword policies can be used to ensure password are at least a given length. It is recommended that the password policy require a minimum password length 14. Rationale Setting a password complexity policy increases account resiliency against brute forcelogin attempts. Impact Recommendation and Steps Perform the following to set the password policy as prescribed: From Console: 1. Login to AWS Console (with appropriate permissions to View Identity Access Management Account Settings) 2. Go to IAM Service on the AWS Console 3. Click on Account Settings on the Left Pane 4. Set Minimum password length to 14 or greater. 5. Click Apply password policy Page 31 From Command Line: aws iam update-account-password-policy --minimum-password-length 14 Note: All commands starting with aws iam update-account-password-policy can be combined into a single command. Associated Items
Affected Objects
|
| Ensure IAM password policy prevents password reuse | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
X TEST NAME Ensure IAM password policy prevents password reuse Description Page 321.9 Ensure IAM password policy prevents password reuse(Automated)Profile Applicability:? Level 1Description:IAM password policies can prevent the reuse of a given password by the same user. Itis recommended that the password policy prevent the reuse of passwords. Rationale Preventing password reuse increases account resiliency against brute force loginattempts. Impact Recommendation and Steps Perform the following to set the password policy as prescribed: From Console: 1. Login to AWS Console (with appropriate permissions to View Identity Access Management Account Settings) 2. Go to IAM Service on the AWS Console 3. Click on Account Settings on the Left Pane 4. Check Prevent password reuse 5. Set Number of passwords to remember is set to 24 Page 33 From Command Line: aws iam update-account-password-policy --password-reuse-prevention 24 Note: All commands starting with aws iam update-account-password-policy can be combined into a single command. Associated Items
Affected Objects
|
| Ensure IAM Users Receive Permissions Only Through Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure IAM Users Receive Permissions Only Through Groups Description IAM users are granted access to services, functions, and data through IAM policies.There are four ways to define policies for a user: 1) Edit the user policy directly, aka aninline, or user, policy; 2) attach a policy directly to a user; 3) add the user to an IAMgroup that has an attached policy; 4) add the user to an IAM group that has an inlinepolicy.Only the third implementation is recommended. Rationale Assigning IAM policy only through groups unifies permissions management to a single,flexible layer consistent with organizational functional roles. By unifying permissionsmanagement, the likelihood of excessive permissions is reduced. Impact Recommendation and Steps Perform the following to create an IAM group and assign a policy to it: 1. Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. 2. In the navigation pane, click Groups and then click Create New Group . 3. In the Group Name box, type the name of the group and then click Next Step . 4. In the list of policies, select the check box for each policy that you want to apply to all members of the group. Then click Next Step . 5. Click Create Group Perform the following to add a user to a given group: 1. Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. 2. In the navigation pane, click Groups 3. Select the group to add a user to 4. Click Add Users To Group 5. Select the users to be added to the group 6. Click Add Users Perform the following to remove a direct association between a user and policy: 1. Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. 2. In the left navigation pane, click on Users 3. For each user: o Select the user o Click on the Permissions tab o Expand Permissions policies o Click X for each policy; then click Detach or Remove (depending on policy type) Associated Items
Affected Objects
|
| Ensure that IAM Access analyzer is enabled for all regions | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure that IAM Access analyzer is enabled for all regions Description Enable IAM Access analyzer for IAM policies about all resources in each active AWSregion.IAM Access Analyzer is a technology introduced at AWS reinvent 2019. After theAnalyzer is enabled in IAM, scan results are displayed on the console showing theaccessible resources. Scans show resources that other accounts and federated userscan access, such as KMS keys and IAM roles. So the results allow you to determine ifan unintended user is allowed, making it easier for administrators to monitor leastprivileges access. Access Analyzer analyzes only policies that are applied to resourcesin the same AWS Region. Rationale AWS IAM Access Analyzer helps you identify the resources in your organization andaccounts, such as Amazon S3 buckets or IAM roles, that are shared with an externalentity. This lets you identify unintended access to your resources and data. AccessAnalyzer identifies resources that are shared with external principals by using logic-based reasoning to analyze the resource-based policies in your AWS environment. IAMAccess Analyzer continuously monitors all policies for S3 bucket, IAM roles, KMS (Key Management Service) keys, AWS Lambda functions, and Amazon SQS(Simple QueueService) queues. Impact Recommendation and Steps From Console: Perform the following to enable IAM Access analyzer for IAM policies: 1. Open the IAM console at https://console.aws.amazon.com/iam/. 2. Choose Access analyzer. 3. Choose Create analyzer. 4. On the Create analyzer page, confirm that the Region displayed is the Region where you want to enable Access Analyzer. 5. Enter a name for the analyzer. Optional as it will generate a name for you automatically. 6. Add any tags that you want to apply to the analyzer. Optional. 7. Choose Create Analyzer. 8. Repeat these step for each active region From Command Line: Run the following command: aws accessanalyzer create-analyzer --analyzer-name Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html2. https https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-getting-started.html3. https https://docs.aws.amazon.com/cli/latest/reference/accessanalyzer/get-analyzer.html4. https https://docs.aws.amazon.com/cli/latest/reference/accessanalyzer/create-analyzer.html
|
| Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments Description In multi-account environments, IAM user centralization facilitates greater user control.User access beyond the initial account is then provided via role assumption.Centralization of users can be accomplished through federation with an external identityprovider or through the use of AWS Organizations. Rationale Centralizing IAM user management to a single identity store reduces complexity andthus the likelihood of access management errors. Impact Recommendation and Steps The remediation procedure will vary based on the individual organization's implementation of identity federation and/or AWS Organizations with the acceptance criteria that no non-service IAM users, and non-root accounts, are present outside the account providing centralized IAM user management. Associated Items
Affected Objects
|
| Maintain current contact details | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Maintain current contact details Description Ensure contact email and telephone details for AWS accounts are current and map to more than one individual in your organization. An AWS account supports a number of contact details, and AWS will use these to contact the account owner if activity judged to be in breach of Acceptable Use Policy or indicative of likely security compromise is observed by the AWS Abuse team. Contact details should not be for a single individual, as circumstances may arise where that individual is unavailable. Email contact details should point to a mail alias which forwards email to multiple individuals within the organization; where feasible, phone contact details should point to a PABX hunt group or other call-forwarding system. Rationale If an AWS account is observed to be behaving in a prohibited or suspicious manner, AWS will attempt to contact the account owner by email and phone using the contact details listed. If this is unsuccessful and the account behavior needs urgent mitigation, proactive measures may be taken, including throttling of traffic between the account exhibiting suspicious behavior and the AWS API endpoints and the Internet. This will result in impaired service to and from the account in question, so it is in both the customers' and AWS' best interests that prompt contact can be established. This is best achieved by setting AWS account contact details to point to resources which have multiple individuals as recipients, such as email aliases and PABX hunt groups. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure no root user account access key exists | Passed | Status:Configured correctly | N/A | Level 2 | CIS v3.0.0 | YES |
X TEST NAME Ensure no root user account access key exists Description The 'root' user account is the most privileged user in an AWS account. AWS AccessKeys provide programmatic access to a given AWS account. It is recommended that all access keys associated with the 'root' user account be deleted. Rationale Deleting access keys associated with the 'root' user account limits vectors by which the account can be compromised. Additionally, deleting the 'root' access keys encourages the creation and use of role based accounts that are least privileged. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. http https://docs.aws.amazon.com/general/latest/gr/aws-access-keys-best-practices.html2. http https://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html3. http https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountSummary.html4. CCE-78910-75. https https://aws.amazon.com/blogs/security/an-easier-way-to-determine-the-presence-of-aws-account-access-keys/
|
| Eliminate use of the root user for administrative and daily tasks | Passed | Status:Configured correctly:0 | N/A | Level 2 | CIS v3.0.0 | YES |
X TEST NAME Eliminate use of the root user for administrative and daily tasks Description With the creation of an AWS account, a 'root user' is created that cannot be disabled ordeleted. That user has unrestricted access to and control over all resources in the AWSaccount. It is highly recommended that the use of this account be avoided for everydaytasks. Rationale The 'root user' has unrestricted access to and control over all account resources. Use ofit is inconsistent with the principles of least privilege and separation of duties, and canlead to unnecessary harm due to error or account compromise. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password Description Multi-Factor Authentication (MFA) adds an extra layer of authentication assurancebeyond traditional credentials. With MFA enabled, when a user signs in to the AWSConsole, they will be prompted for their user name and password as well as for anauthentication code from their physical or virtual MFA token. It is recommended thatMFA be enabled for all accounts that have a console password. Rationale Enabling MFA provides increased security for console access as it requires theauthenticating principal to possess a device that displays a time-sensitive key and haveknowledge of a credential. Impact AWS will soon end support for SMS multi-factor authentication (MFA). New customersare not allowed to use this feature. We recommend that existing customers switch toone of the following alternative methods of MFA. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://tools.ietf.org/html/rfc62382. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html3. https https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#enable-mfa-for-privileged-users4. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable_virtual.html5. CCE-78901-66. https https://blogs.aws.amazon.com/security/post/Tx2SJJYE082KBUK/How-to-Delegate-Management-of-Multi-Factor-Authentication-to-AWS-IAM-Users
|
| Do not setup access keys during initial user setup for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Do not setup access keys during initial user setup for all IAM users that have a console password Description AWS console defaults to no check boxes selected when creating a new IAM user.When creating the IAM User credentials you have to determine what type of accessthey require.Programmatic access: The IAM user might need to make API calls, use the AWS CLI,or use the Tools for Windows PowerShell. In that case, create an access key (accesskey ID and a secret access key) for that user.AWS Management Console access: If the user needs to access the AWS Management Console, create a password for the user. Rationale Requiring the additional steps be taken by the user for programmatic access after theirprofile has been created will give a stronger indication of intent that access keys are [a]necessary for their work and [b] once the access key is established on an account thatthe keys may be in use somewhere in the organization.Note: Even if it is known the user will need access keys, require them to create the keysthemselves or put in a support ticket to have them created as a separate step from usercreation. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure there is only one active access key available for any single IAM user | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure there is only one active access key available for any single IAM user Description Access keys are long-term credentials for an IAM user or the AWS account 'root' user.You can use access keys to sign programmatic requests to the AWS CLI or AWS API(directly or using the AWS SDK) Rationale Access keys are long-term credentials for an IAM user or the AWS account 'root' user.You can use access keys to sign programmatic requests to the AWS CLI or AWS API.One of the best ways to protect your account is to not allow users to have multipleaccess keys. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure access keys are rotated every 90 days or less | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure access keys are rotated every 90 days or less Description Access keys consist of an access key ID and secret access key, which are used to signprogrammatic requests that you make to AWS. AWS users need their own access keysto make programmatic calls to AWS from the AWS Command Line Interface (AWS CLI),Tools for Windows PowerShell, the AWS SDKs, or direct HTTP calls using the APIs forindividual AWS services. It is recommended that all access keys be regularly rotated. Rationale Rotating access keys will reduce the window of opportunity for an access key that isassociated with a compromised or terminated account to be used.Access keys should be rotated to ensure that data cannot be accessed with an old key which might have been lost, cracked, or stolen. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-78902-42. https https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#rotate-credentials3. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_finding-unused.html4. https https://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html5. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html
|
| Ensure IAM policies that allow full *-* administrative privileges are not attached | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure IAM policies that allow full *-* administrative privileges are not attached Description IAM policies are the means by which privileges are granted to users, groups, or roles. Itis recommended and considered a standard security advice to grant least privilege -thatis, granting only the permissions required to perform a task. Determine what users needto do and then craft policies for them that let the users perform only those tasks, insteadof allowing full administrative privileges. Rationale It's more secure to start with a minimum set of permissions and grant additionalpermissions as necessary, rather than starting with permissions that are too lenient and then trying to tighten them later.Providing full administrative privileges instead of restricting to the minimum set ofpermissions that the user is required to do exposes the resources to potentiallyunwanted actions.IAM policies that have a statement with Effect: Allow with Action: * overResource: * should be removed. Impact Recommendation and Steps Associated Items Affected Objects More Information TEST ID
|
| Ensure a support role has been created to manage incidents with AWS Support | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure a support role has been created to manage incidents with AWS Support Description AWS provides a support center that can be used for incident notification and response,as well as technical support and customer services. Create an IAM Role, with theappropriate policy assigned, to allow authorized users to manage incidents with AWSSupport. Rationale By implementing least privilege for access control, an IAM Role will require anappropriate IAM Policy to allow Support Center Access in order to manage Incidentswith AWS Support. Impact All AWS Support plans include an unlimited number of account and billing supportcases, with no long-term contracts. Support billing calculations are performed on a per-account basis for all plans. Enterprise Support plan customers have the option toinclude multiple enabled accounts in an aggregated monthly billing calculation. Monthlycharges for the Business and Enterprise support plans are based on each month's AWSusage charges, subject to a monthly minimum, billed in advance.When assigning rights, keep in mind that other policies may grant access to Support aswell. This may include AdministratorAccess and other policies including customermanaged policies. Utilizing the AWS managed 'AWSSupportAccess' role is one simpleway of ensuring that this permission is properly granted.To better support the principle of separation of duties, it would be best to only attach thisrole where necessary. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html2. https https://aws.amazon.com/premiumsupport/pricing/3. https https://docs.aws.amazon.com/cli/latest/reference/iam/list-policies.html4. https https://docs.aws.amazon.com/cli/latest/reference/iam/attach-role-policy.html5. https https://docs.aws.amazon.com/cli/latest/reference/iam/list-entities-for-policy.html
|
| Ensure IAM instance roles are used for AWS resource access from instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure IAM instance roles are used for AWS resource access from instances Description AWS access from within AWS instances can be done by either encoding AWS keys intoAWS API calls or by assigning the instance to a role which has an appropriatepermissions policy for the required access. AWS Access means accessing the APIs ofAWS in order to access AWS resources or manage AWS account resources. Rationale AWS IAM roles reduce the risks associated with sharing and rotating credentials thatcan be used outside of AWS itself. If credentials are compromised, they can be usedfrom outside of the AWS account they give access to. In contrast, in order to leveragerole permissions an attacker would need to gain and maintain access to a specificinstance to use the privileges associated with it.Additionally, if credentials are encoded into compiled applications or other hard tochange mechanisms, then they are even more unlikely to be properly rotated due toservice disruption risks. As time goes on, credentials that cannot be rotated are morelikely to be known by an increasing number of individuals who no longer work for theorganization owning the credentials. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that all the expired SSL-TLS certificates stored in AWS IAM are removed | Passed | Status: Configured Correctly | By default, expired certificates won't get deleted. | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that all the expired SSL-TLS certificates stored in AWS IAM are removed Description To enable HTTPS connections to your website or application in AWS, you need anSSL/TLS server certificate. You can use ACM or IAM to store and deploy servercertificates. Use IAM as a certificate manager only when you must support HTTPSconnections in a region that is not supported by ACM. IAM securely encrypts yourprivate keys and stores the encrypted version in IAM SSL certificate storage. IAMsupports deploying server certificates in all regions, but you must obtain your certificatefrom an external provider for use with AWS. You cannot upload an ACM certificate toIAM. Additionally, you cannot manage your certificates from the IAM Console. Rationale Removing expired SSL/TLS certificates eliminates the risk that an invalid certificate willbe deployed accidentally to a resource such as AWS Elastic Load Balancer (ELB),which can damage the credibility of the application/website behind the ELB. As a bestpractice, it is recommended to delete expired certificates. Impact Deleting the certificate could have implications for your application if you are using anexpired server certificate with Elastic Load Balancing, CloudFront, etc. One has to makeconfigurations at respective services to ensure there is no interruption in applicationfunctionality. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure access to AWSCloudShellFullAccess is restricted | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure access to AWSCloudShellFullAccess is restricted Description AWS CloudShell is a convenient way of running CLI commands against AWS services;a managed IAM policy ('AWSCloudShellFullAccess') provides full access to CloudShell,which allows file upload and download capability between a user's local system and theCloudShell environment. Within the CloudShell environment a user has sudopermissions, and can access the internet. So it is feasible to install file transfer software(for example) and move data from CloudShell to external internet servers.
Rationale Access to this policy should be restricted as it presents a potential channel for dataexfiltration by malicious cloud admins that are given full permissions to the service.AWS documentation describes how to create a more restrictive IAM policy which deniesfile transfer permissions. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure credentials unused for 45 days or greater are disabled | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure credentials unused for 45 days or greater are disabled Description AWS IAM users can access AWS resources using different types of credentials, suchas passwords or access keys. It is recommended that all credentials that have beenunused in 45 or greater days be deactivated or removed. Rationale Disabling or removing unnecessary credentials will reduce the window of opportunity forcredentials associated with a compromised or abandoned account to be used. Impact Recommendation and Steps From Console: Perform the following to manage Unused Password (IAM user console access) 1. Login to the AWS Management Console: 2. Click Services 3. Click IAM 4. Click on Users 5. Click on Security Credentials 6. Select user whose Console last sign-in is greater than 45 days 7. Click Security credentials 8. In section Sign-in credentials, Console password click Manage 9. Under Console Access select Disable 10.Click Apply Perform the following to deactivate Access Keys: 1. Login to the AWS Management Console: 2. Click Services 3. Click IAM 4. Click on Users 5. Click on Security Credentials 6. Select any access keys that are over 45 days old and that have been used and Page 42 -Click on Make Inactive 7. Select any access keys that are over 45 days old and that have not been used and -Click the X to Delete Associated Items Affected Objects More Information TEST ID
LINK
https:1. CCE-78900-82. https https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#remove-credentials3. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_finding-unused.html4. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_passwords_admin-change-user.html5. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure S3 Bucket Policy is set to deny HTTP requests | Passed | Status:Configured correctly | Both HTTP and HTTPS Request are allowed | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure S3 Bucket Policy is set to deny HTTP requests Description At the Amazon S3 bucket level, you can configure permissions through a bucket policymaking the objects accessible only through HTTPS. Rationale By default, Amazon S3 allows both HTTP and HTTPS requests. To achieve onlyallowing access to Amazon S3 objects through HTTPS you also have to explicitly denyaccess to HTTP requests. Bucket policies that allow HTTPS requests without explicitlydenying HTTP requests will not comply with this recommendation. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://aws.amazon.com/premiumsupport/knowledge-center/s3-bucket-policy-for-config-rule/2. https https://aws.amazon.com/blogs/security/how-to-use-bucket-policies-and-apply-defense-in-depth-to-help-secure-your-amazon-s3-data/3. https https://awscli.amazonaws.com/v2/documentation/api/latest/reference/s3api/get-bucket-policy.html
|
| Ensure MFA Delete is enabled on S3 buckets | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure MFA Delete is enabled on S3 buckets Description Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires theuser to have two forms of authentication. Rationale Adding MFA delete to an S3 bucket, requires additional authentication when youchange the version state of your bucket or you delete and object version adding anotherlayer of security in the event your security credentials are compromised or unauthorizedaccess is granted. Impact Enabling MFA delete on an S3 bucket could required additional administrator oversight.Enabling MFA delete may impact other services that automate the creation and/ordeletion of S3 buckets. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete2. https https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMFADelete.html3. https https://aws.amazon.com/blogs/security/securing-access-to-aws-using-mfa-part-3/4. https https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html
|
| Ensure all data in Amazon S3 has been discovered- classified and secured when required | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure all data in Amazon S3 has been discovered- classified and secured when required Description Amazon S3 buckets can contain sensitive data, that for security purposes should bediscovered, monitored, classified and protected. Macie along with other 3rd party toolscan automatically provide an inventory of Amazon S3 buckets. Rationale Using a Cloud service or 3rd Party software to continuously monitor and automate theprocess of data discovery and classification for S3 buckets using machine learning andpattern matching is a strong defense in protecting that information.Amazon Macie is a fully managed data security and data privacy service that usesmachine learning and pattern matching to discover and protect your sensitive data inAWS. Impact There is a cost associated with using Amazon Macie. There is also typically a costassociated with 3rd Party tools that perform similar processes and protection. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that S3 Buckets are configured with Block public access (bucket settings) | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that S3 Buckets are configured with Block public access (bucket settings) Description Amazon S3 provides Block public access (bucket settings) and Block publicaccess (account settings) to help you manage public access to Amazon S3resources. By default, S3 buckets and objects are created with public access disabled.However, an IAM principal with sufficient S3 permissions can enable public access atthe bucket and/or object level. While enabled, Block public access (bucket settings)prevents an individual bucket, and its contained objects, from becoming publiclyaccessible. Similarly, Block public access (account settings) prevents all buckets,and contained objects, from becoming publicly accessible across the entire account. Rationale Amazon S3 Block public access (bucket settings) prevents the accidental ormalicious public exposure of data contained within the respective bucket(s).Amazon S3 Block public access (account settings) prevents the accidental ormalicious public exposure of data contained within all buckets of the respective AWSaccount.Whether blocking public access to all or some buckets is an organizational decision thatshould be based on data sensitivity, least privilege, and use case. Impact When you apply Block Public Access settings to an account, the settings apply to allAWS Regions globally. The settings might not take effect in all Regions immediately orsimultaneously, but they eventually propagate to all Regions. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Amazon Simple Storage Service | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Amazon Simple Storage Service Description Amazon Simple Storage Service (Amazon S3) is an object storage service that provides industry-leading scalability, data availability, security, and performance. It allows customers of all sizes and industries to store and protect any amount of data for virtually any use case, including data lakes, cloud-native applications, and mobile apps. With cost-effective storage classes and intuitive management features, you can optimize costs, organize data, and configure precise access controls to meet your specific business, organizational, and compliance requirements. Rationale By utilizing S3, businesses of all sizes can efficiently store and protect large amounts of data, ensuring it is accessible when needed. The service's cost-effective storage classes and user-friendly management features help optimize costs and streamline data organization. Additionally, S3's fine-tuned access controls allow organizations to meet specific business, organizational, and compliance requirements, enhancing overall data management and security. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure direct data addition to S3 | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure direct data addition to S3 Description Your bucket name must be unique and not already in use on AWS. Click on your bucket name, and in the right corner, you will find an option to upload data directly to your S3 bucket. You can choose the file option to upload individual files, images, or even entire folders. Rationale Accessing the upload option within your bucket simplifies the process of adding data, making it easy to manage and organize your files. This streamlined approach allows for efficient data storage, retrieval, and management within the AWS S3 environment, enhancing overall operational efficiency. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure Storage Classes are Configured | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Storage Classes are Configured Description Amazon S3 offers various storage classes to optimize cost and performance based on data access patterns and retention needs. Standard Storage is for frequently accessed data, while Standard-IA and One Zone-IA are for infrequent access, with the latter offering cost savings by storing in a single Availability Zone. Intelligent-Tiering automatically moves data between access tiers based on usage, and Glacier and Glacier Deep Archive provide low-cost options for long-term archival storage with varying retrieval times. Each class balances availability, durability, performance, and cost, enabling a tailored storage strategy to meet specific requirements. Rationale This approach ensures frequently accessed data is readily available, while infrequently accessed data is stored cost-effectively, balancing availability, durability, and cost. Impact Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure EBS Volume Encryption is Enabled in all Regions | High | Status: Not Configured | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure EBS Volume Encryption is Enabled in all Regions Description Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic BlockStore (EBS) service. While disabled by default, forcing encryption at EBS volumecreation is supported. Rationale Encrypting data at rest reduces the likelihood that it is unintentionally exposed and cannullify the impact of disclosure if the encryption remains unbroken. Impact Losing access or removing the KMS key in use by the EBS volumes will result in nolonger being able to access the volumes. Recommendation and Steps From Console: 1. Login to AWS Management Console and open the Amazon EC2 console using https://console.aws.amazon.com/ec2/ 2. Under Account attributes, click EBS encryption. 3. Click Manage. 4. Click the Enable checkbox. 5. Click Update EBS encryption 6. Repeat for every region requiring the change. Note: EBS volume encryption is configured per region. From Command Line: 1. Run aws --region Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Implementation of EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Implementation of EFS Description AWS EFS is a fully managed storage service that enables rapid file system deployment without the need for configuration, patching, or maintenance. Rationale The rationale behind using AWS EFS is to simplify and expedite the deployment of file systems, eliminating the need for manual configuration, patching, and maintenance. This allows you to focus on other critical aspects of your operations while benefiting from a reliable, scalable, and fully managed storage solution. Impact Not using AWS EFS can lead to increased complexity and time-consuming manual management for configuration, patching, and maintenance. This raises the risk of human error, system downtime, and data loss, while also making it more challenging to scale your file systems efficiently. Recommendation and Steps Remediate the issues of manual file system management, follow these steps to create and use Amazon EFS: 1. Open the Amazon EFS Console: Sign in to the AWS Management Console and navigate to the Amazon EFS service. 2. Create a New File System: Click on Create file system to start the setup process. 3. Configure Settings: Select your desired VPC, availability zones, throughput mode, and any additional settings like lifecycle management. 4. Set Up Access Points: Configure access points to control permissions and simplify access management. 5. Review and Create: Verify your settings and click Create to finalize the file system setup. 6. Mount the File System: Use the provided mount targets and instructions to attach the file system to your EC2 instances or other resources. Associated Items
Affected Objects
|
| Ensure EFS and VPC Integration | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure EFS and VPC Integration Description You can use EFS as a network file system across availability zones on a virtual private cloud. This capability allows the organization to create a highly available file sharing solution. Leveraging AWS VPC and EC2 in tandem with AWS EFS makes for a highly available and scalable cloud file storage solution. Rationale Redundancy and scalability are crucial for maintaining uninterrupted services. By integrating these AWS services, users can harness the full power of AWS, ensuring a resilient and scalable infrastructure. Impact Not integrating AWS services for redundancy and scalability can lead to service disruptions and increased downtime. This approach also limits your ability to efficiently handle growing workloads, negatively impacting performance and user experience. Recommendation and Steps Create an EC2 instance in each availability zone within your VPC. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure controlling Network access to EFS Services | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure controlling Network access to EFS Services Description It's important that you secure access to your resources on your AWS VPC network. There are several ways to ensure that you control what traffic is accessing your resources. Some of which include tightening down network layer security using a Security Group and a NACL within the VPC console. You can also tighten down Security Groups within your EC2 console and by using AWS IAM. Maintaining network security is a high priority to ensure that no unauthorized users can access the data stored on your EFS service. Rationale Maintaining network security is a best practice essential for keeping your data safe and secure. Impact Failing to maintain network security can lead to significant vulnerabilities, exposing your data to unauthorized access, breaches, and potential data loss. This can result in severe financial, operational, and reputational damage to your organization. Recommendation and Steps Implement network security access controls. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure File-Level Access Control with Mount Targets | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure File-Level Access Control with Mount Targets Description Mount targets act as gateways, enabling resources to be accessed across different availability zones within a VPC. When you create an EFS file system, mount targets are automatically provisioned in each availability zone associated with the VPC. This ensures high availability and redundancy, allowing seamless and efficient access to the EFS file system from any availability zone. Rationale Using mount targets ensures seamless access to the EFS file system across different availability zones within a VPC. This automatic provisioning of mount targets in each availability zone provides high availability and redundancy, essential for maintaining uninterrupted data access. It simplifies configuration and enhances the resilience and scalability of the file system architecture. Impact Not using mount targets can lead to inefficient and unreliable access to the EFS file system across availability zones. This lack of automatic provisioning reduces high availability and redundancy, increasing the risk of service interruptions and data access issues. Consequently, your infrastructure may suffer from decreased performance, higher latency, and potential data loss or downtime. Recommendation and Steps Control access by modifying mount targets in each availability zone. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure managing mount target security groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure managing mount target security groups Description Managing security groups for mount targets is essential for controlling access to your Amazon EFS file systems. By configuring these security groups, you ensure that only authorized network traffic can access your file systems, enhancing security. Regular reviews and updates of security group rules maintain strict access control, protecting your data from unauthorized access and potential breaches. Rationale The rationale for managing security groups for mount targets is to ensure robust access control and security for your Amazon EFS file systems. By configuring these security groups, you restrict access to only authorized network traffic, thereby minimizing the risk of unauthorized access and potential data breaches. Regularly reviewing and updating these rules helps maintain strong security measures and compliance with organizational policies and industry standards. Impact Not managing security groups for mount targets can lead to significant vulnerabilities, exposing your Amazon EFS file systems to unauthorized access and potential breaches. This lack of control increases the risk of malicious attacks, data theft, and data corruption. Consequently, your organization may face severe financial losses, operational disruptions, and damage to its reputation. Recommendation and Steps Managing security groups for mount targets is essential for controlling access to your Amazon EFS file systems. By configuring these security groups, you ensure that only authorized network traffic can access your file systems, enhancing security. Regular reviews and updates of security group rules maintain strict access control, protecting your data from unauthorized access and potential breaches. The rationale for managing security groups for mount targets is to ensure robust access control and security for your Amazon EFS file systems. By configuring these security groups, you restrict access to only authorized network traffic, thereby minimizing the risk of unauthorized access and potential data breaches. Regularly reviewing and updating these rules helps maintain strong security measures and compliance with organizational policies and industry standards. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure using VPC endpoints - EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure using VPC endpoints - EFS Description With AWS PrivateLink, VPC Endpoints allow services to communicate within AWS using private IP addresses within approved CIDR ranges. This communication can be achieved without the need for a VPN, ensuring secure and efficient data transfer. Rationale The rationale behind using AWS PrivateLink with VPC Endpoints is to enable secure and efficient communication between services within AWS. By using private IP addresses within approved CIDR ranges, it eliminates the need for a VPN, reducing complexity and potential points of failure. This approach enhances security, reduces latency, and ensures data remains within the AWS network, aligning with best practices for secure and reliable cloud architecture. Impact Not using AWS PrivateLink with VPC Endpoints can lead to several issues, including increased security risks and potential data exposure since services would need to communicate over the public internet or through more complex VPN setups. This can result in higher latency, reduced performance, and greater vulnerability to attacks. Additionally, managing VPN connections adds complexity and potential points of failure, compromising the overall efficiency and reliability of your network architecture. Recommendation and Steps Use VPC Endpoints in tandem with AWS Private Link to secure your EFS connections. Associated Items
Affected Objects
|
| Ensure managing AWS EFS access points | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure managing AWS EFS access points Description EFS access points serve as gateways to your EFS file system, allowing applications to interact with the file system across various resources. Proper configuration of these access points within your applications is crucial to ensure seamless and secure access. By configuring EFS access points, you can control and manage which users have access to specific resources in your EFS environment, enhancing security and operational efficiency. Rationale The rationale behind properly configuring EFS access points is to ensure secure and efficient interaction between your applications and the EFS file system. By setting up these access points correctly, you can control and manage user permissions, ensuring that only authorized users can access specific resources. This not only enhances the security of your data but also improves operational efficiency by preventing unauthorized access and potential data breaches. Impact Recommendation and Steps Implement AWS EFS access points Associated Items
Affected Objects
More Information TEST ID
|
| Ensure accessing Points and IAM Policies | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure accessing Points and IAM Policies Description You can use IAM policies to control access to your EFS access points. To achieve this, utilize the elasticfilesystem:AccessPointArn IAM condition key. The AccessPointArn represents the Amazon Resource Name (ARN) of the access point that the file system is mounted with. Rationale The rationale for using IAM policies with the elasticfilesystem:AccessPointArn condition key is to ensure precise and secure access control to EFS access points. By specifying the access point's ARN, you can restrict interactions to authorized users and resources only, thereby enhancing data security and preventing unauthorized access. This approach maintains the integrity and confidentiality of your data within the AWS environment. Impact Recommendation and Steps You can use IAM policies to control access to your EFS access points. To achieve this, utilize the elasticfilesystem:AccessPointArn IAM condition key. The AccessPointArn represents the Amazon Resource Name (ARN) of the access point that the file system is mounted with. The rationale for using IAM policies with the elasticfilesystem:AccessPointArn condition key is to ensure precise and secure access control to EFS access points. By specifying the access point's ARN, you can restrict interactions to authorized users and resources only, thereby enhancing data security and preventing unauthorized access. This approach maintains the integrity and confidentiality of your data within the AWS environment. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure configuring IAM for AWS Elastic Disaster Recovery | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure configuring IAM for AWS Elastic Disaster Recovery Description Before installing the AWS Elastic Disaster Recovery client, you need to configure AWS IAM permissions and users for both the AWS Replication and AWS Failback Client. Rationale Configuring AWS IAM permissions and users before installing the AWS Elastic Disaster Recovery client ensures that the AWS Replication and AWS Failback Client have the necessary access rights. This setup is essential for maintaining security and preventing unauthorized access. Proper IAM configuration guarantees the smooth operation of disaster recovery processes, safeguarding your data and ensuring system reliability. Impact Recommendation and Steps Configure IAM Credentials for AWS Elastic Disaster Recovery. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure that encryption is enabled for EFS file systems | Passed | Status:Configured correctly: | EFS file system data is encrypted at rest by default when creating a file system via theConsole. Encryption at rest is not enabled by default when creating a new file systemusing the AWS CLI, API, and SDKs. | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that encryption is enabled for EFS file systems Description EFS data should be encrypted at rest using AWS KMS (Key Management Service). Rationale Data should be encrypted at rest to reduce the risk of a data breach via direct access tothe storage device. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure using Security Groups for VPC | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure using Security Groups for VPC Description A security group controls the traffic that is allowed to reach and leave the resources that it is associated with. For example, after you associate a security group with an EC2 instance, it controls the inbound and outbound traffic for the instance. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Secure Ports | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Secure Ports Description Securing network ports is essential for protecting AWS storage services like Amazon S3, EFS, and EBS. By configuring security groups and network access control lists (NACLs) to allow only necessary traffic, you minimize the risk of unauthorized access. Regular audits and monitoring of port usage ensure that only approved ports and protocols are operational, enhancing the overall security of your AWS storage environment. Rationale By limiting traffic to only necessary and approved ports and protocols, you reduce the attack surface and enhance the overall security of your storage environment. Regular audits and monitoring further ensure that security measures remain effective and up-to- date, safeguarding your data from emerging threats. Impact Not securing network ports in AWS storage services can lead to significant vulnerabilities, exposing your data to unauthorized access and potential breaches. This lack of control increases the risk of attacks, such as port scanning and exploitation of open ports, which can result in data loss, corruption, and theft. Consequently, your organization may face severe financial losses, operational disruptions, and damage to its reputation. Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure CloudTrail is enabled in all regions | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure CloudTrail is enabled in all regions Description AWS CloudTrail is a web service that records AWS API calls for your account and delivers log files to you. The recorded information includes the identity of the API caller, the time of the API call, the source IP address of the API caller, the request parameters, and the response elements returned by the AWS service. CloudTrail provides a history of AWS API calls for an account, including API calls made via the ManagementConsole, SDKs, command line tools, and higher-level AWS services (such as CloudFormation). Rationale The AWS API call history produced by CloudTrail enables security analysis, resource change tracking, and compliance auditing. Additionally,? ensuring that a multi-regions trail exists will ensure that unexpected activity occurring in otherwise unused regions is detected? ensuring that a multi-regions trail exists will ensure that Global Service Logging is enabled for a trail by default to capture recording of events generated on AWS global services? for a multi-regions trail, ensuring that management events configured for all type of Read/Writes ensures recording of management operations that are performed on all resources in an AWS account Impact S3 lifecycle features can be used to manage the accumulation and management of logs over time. See the following AWS resource for more information on these features:1. https://docs.aws.amazon.com/AmazonS3/latest/dev/object-lifecycle-mgmt.html Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-78913-12. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-concepts.html#cloudtrail-concepts-management-events3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-management-and-data-events-with-cloudtrail.html?icmpid=docs_cloudtrail_console#logging-management-events4. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-supported-services.html#cloud-trail-supported-services-data-events
|
| Ensure CloudTrail log file validation is enabled | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure CloudTrail log file validation is enabled Description CloudTrail log file validation creates a digitally signed digest file containing a hash ofeach log that CloudTrail writes to S3. These digest files can be used to determine whether a log file was changed, deleted, or unchanged after CloudTrail delivered the log. It is recommended that file validation be enabled on all CloudTrails. Rationale Enabling log file validation will provide additional integrity checking of CloudTrail logs. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure AWS Config is enabled in all regions | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure AWS Config is enabled in all regions Description AWS Config is a web service that performs configuration management of supported AWS resources within your account and delivers log files to you. The recorded information includes the configuration item (AWS resource), relationships between configuration items (AWS resources), any configuration changes between resources. Itis recommended AWS Config be enabled in all regions. Rationale The AWS configuration item history captured by AWS Config enables security analysis, resource change tracking, and compliance auditing. Impact It is recommended AWS Config be enabled in all regions. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-78917-22. https https://docs.aws.amazon.com/cli/latest/reference/configservice/describe-configuration-recorder-status.html3. https https://docs.aws.amazon.com/cli/latest/reference/configservice/describe-configuration-recorders.html4. https https://docs.aws.amazon.com/config/latest/developerguide/gs-cli-prereq.html
|
| Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket | Passed | Status:Configured correctly: | Logging is disabled. | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket Description S3 Bucket Access Logging generates a log that contains access records for each request made to your S3 bucket. An access log record contains details about the request, such as the request type, the resources specified in the request worked, andthe time and date the request was processed. It is recommended that bucket access logging be enabled on the CloudTrail S3 bucket. Rationale By enabling S3 bucket logging on target S3 buckets, it is possible to capture all events which may affect objects within any target buckets. Configuring logs to be placed in a separate bucket allows access to log information which can be useful in security and incident response workflows. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure CloudTrail logs are encrypted at rest using KMS CMKs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure CloudTrail logs are encrypted at rest using KMS CMKs Description AWS CloudTrail is a web service that records AWS API calls for an account and makes those logs available to users and resources in accordance with IAM policies. AWS KeyManagement Service (KMS) is a managed service that helps create and control the encryption keys used to encrypt account data, and uses Hardware Security Modules (HSMs) to protect the security of encryption keys. CloudTrail logs can be configured to leverage server side encryption (SSE) and KMS customer created master keys (CMK)to further protect CloudTrail logs. It is recommended that CloudTrail be configured to use SSE-KMS. Rationale Configuring CloudTrail to use SSE-KMS provides additional confidentiality controls on log data as a given user must have S3 read permission on the corresponding log bucket and must be granted decrypt permission by the CMK policy. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure rotation for customer-created symmetric CMKs is enabled | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure rotation for customer-created symmetric CMKs is enabled Description AWS Key Management Service (KMS) allows customers to rotate the backing keywhich is key material stored within the KMS which is tied to the key ID of the customer-created customer master key (CMK). It is the backing key that is used to perform cryptographic operations such as encryption and decryption. Automated key rotation currently retains all prior backing keys so that decryption of encrypted data can take place transparently. It is recommended that CMK key rotation be enabled for symmetric keys. Key rotation can not be enabled for any asymmetric CMK. Rationale Rotating encryption keys helps reduce the potential impact of a compromised key as data encrypted with a new key cannot be accessed with a previous key that may have been exposed. Keys should be rotated every year, or upon event that would result in the compromise of that key. Impact Creation, management, and storage of CMKs may require additional time from an administrator. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure VPC flow logging is enabled in all VPCs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure VPC flow logging is enabled in all VPCs Description VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. After you've created a flow log, you can view and retrieve its data in Amazon CloudWatch Logs. It is recommended that VPC Flow Logs be enabled for packet Rejects for VPCs. Rationale VPC Flow Logs provide visibility into network traffic that traverses the VPC and can beused to detect anomalous traffic or insight during security workflows. Impact By default, CloudWatch Logs will store Logs indefinitely unless a specific retention period is defined for the log group. When choosing the number of days to retain, keep in mind the average days it takes an organization to realize they have been breached is210 days (at the time of this writing). Since additional time is required to research a breach, a minimum 365 day retention policy allows time for detection and research. You may also wish to archive the logs to a cheaper storage service rather than simply deleting them. See the following AWS resource to manage CloudWatch Logs retentionperiods:1. https://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/SettingLogRetention.html Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure that Object-level logging for write events is enabled for S3 bucket | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that Object-level logging for write events is enabled for S3 bucket Description S3 object-level API operations such as GetObject, DeleteObject, and PutObject arecalled data events. By default, CloudTrail trails don't log data events and so it is recommended to enable Object-level logging for S3 buckets. Rationale Enabling object-level logging will help you meet data compliance requirements withinyour organization, perform comprehensive security analysis, monitor specific patterns ofuser behavior in your AWS account or take immediate actions on any object-level APIactivity within your S3 Buckets using Amazon CloudWatch Events. Impact Enabling logging for these object level events may significantly increase the number of events logged and may incur additional cost. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure that Object-level logging for read events is enabled for S3 bucket | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that Object-level logging for read events is enabled for S3 bucket Description S3 object-level API operations such as GetObject, DeleteObject, and PutObject arecalled data events. By default, CloudTrail trails don't log data events and so it is recommended to enable Object-level logging for S3 buckets. Rationale Enabling object-level logging will help you meet data compliance requirements withinyour organization, perform comprehensive security analysis, monitor specific patterns ofuser behavior in your AWS account or take immediate actions on any object-level APIactivity using Amazon CloudWatch Events. Impact Enabling logging for these object level events may significantly increase the number of events logged and may incur additional cost. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure AWS Security Hub is enabled | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure AWS Security Hub is enabled Description Security Hub collects security data from across AWS accounts, services, and supportedthird-party partner products and helps you analyze your security trends and identify thehighest priority security issues. When you enable Security Hub, it begins to consume,aggregate, organize, and prioritize findings from AWS services that you have enabled,such as Amazon GuardDuty, Amazon Inspector, and Amazon Macie. You can alsoenable integrations with AWS partner security products. Rationale AWS Security Hub provides you with a comprehensive view of your security state inAWS and helps you check your environment against security industry standards andbest practices - enabling you to quickly assess the security posture across your AWSaccounts. Impact It is recommended AWS Security Hub be enabled in all regions. AWS Security Hubrequires AWS Config to be enabled Recommendation and Steps To grant the permissions required to enable Security Hub, attach the Security Hub managed policy AWSSecurityHubFullAccess to an IAM user, group, or role. Enabling Security Hub From Console: 1. Use the credentials of the IAM identity to sign in to the Security Hub console. 2. When you open the Security Hub console for the first time, choose Enable AWS Security Hub. 3. On the welcome page, Security standards list the security standards that Security Hub supports. 4. Choose Enable Security Hub. From Command Line: 1. Run the enable-security-hub command. To enable the default standards, include --enable-default-standards. aws securityhub enable-security-hub --enable-default-standards 2. To enable the security hub without the default standards, include --no-enable- default-standards. aws securityhub enable-security-hub --no-enable-default-standards Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-get-started.html2. https https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-enable.html#securityhub-enable-api3. https https://awscli.amazonaws.com/v2/documentation/api/latest/reference/securityhub/enable-security-hub.html
|
| Ensure unauthorized API calls are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure unauthorized API calls are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for unauthorized APIcalls. Rationale Monitoring unauthorized API calls will help reduce time to detect malicious activity andcan alert you to a potential security incident.CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting. Impact This alert may be triggered by normal read-only console activities that attempt toopportunistically gather optional information, but gracefully fail if they don't havepermissions.If an excessive number of alerts are being generated then an organization may wish toconsider adding read access to the limited IAM user permissions simply to quiet thealerts.In some cases doing this may allow the users to actually view some areas of the system- any additional access given should be reviewed for alignment with the original limitedIAM user intent. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://aws.amazon.com/sns/2. CCE-79186-33. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html4. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html5. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure management console sign-in without MFA is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure management console sign-in without MFA is monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for console logins thatare not protected by multi-factor authentication (MFA). Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring for single-factor console logins will increase visibility into accounts that arenot protected by MFA. These type of accounts are more susceptible to compromise andunauthorized access. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/viewing_metrics_with_cloudwatch.html2. CCE-79187-13. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html4. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html5. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure usage of root account is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure usage of root account is monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for 'root' login attemptsto detect the unauthorized use, or attempts to use the root account. Rationale Monitoring for 'root' account logins will provide visibility into the use of a fully privilegedaccount and an opportunity to reduce the use of it.Cloud Watch is an AWS native service that allows you to observe and monitorresources and applications. CloudTrail Logs can also be sent to an external Securityinformation and event management (SIEM) environment for monitoring and alerting. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79188-92. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure IAM policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure IAM policy changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established changes made toIdentity and Access Management (IAM) policies. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to IAM policies will help ensure authentication and authorizationcontrols remain intact. Impact Monitoring these changes may cause a number of false positives more so in largerenvironments. This alert may need more tuning then others to eliminate some of thoseerroneous alerts Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79189-72. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure CloudTrail configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure CloudTrail configuration changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, where metric filters and alarms can be established.It is recommended that a metric filter and alarm be utilized for detecting changes toCloudTrail's configurations. Rationale Monitoring changes to CloudTrail's configuration will help ensure sustained visibility toactivities performed in the AWS account. Impact These steps can be performed manually in a company's existing SIEM platform in caseswhere CloudTrail logs are monitored outside of the AWS monitoring tools withinCloudWatch. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79190-52. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure AWS Management Console authentication failures are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure AWS Management Console authentication failures are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for failed consoleauthentication attempts. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring failed console logins may decrease lead time to detect an attempt to bruteforce a credential, which may provide an indicator, such as source IP address, that can be used in other event correlation. Impact Monitoring for these failures may create a large number of alerts, more so in largerenvironments. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79191-32. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure disabling or scheduled deletion of customer created CMKs is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure disabling or scheduled deletion of customer created CMKs is monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for customer createdCMKs which have changed state to disabled or scheduled deletion. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Data encrypted with disabled or deleted keys will no longer be accessible. Changes inthe state of a CMK should be monitored to make sure the change is intentional. Impact Creation, storage, and management of CMK may create additional labor requirementscompared to the use of Provide Managed Keys Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79192-12. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure S3 bucket policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure S3 bucket policy changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for changes to S3 bucketpolicies. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to S3 bucket policies may reduce time to detect and correctpermissive policies on sensitive S3 buckets. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79193-92. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure AWS Config configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure AWS Config configuration changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms.It is recommended that a metric filter and alarm be established for detecting changes toAWS Config's configurations. Rationale Monitoring changes to AWS Config configuration will help ensure sustained visibility ofconfiguration items within the AWS account.CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79194-72. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure security group changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure security group changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. Security Groupsare a stateful packet filter that controls ingress and egress traffic within a VPC.It is recommended that a metric filter and alarm be established for detecting changes toSecurity Groups. Rationale Monitoring changes to security group will help ensure that resources and services arenot unintentionally exposed.CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting. Impact This may require additional 'tuning' to eliminate false positive and filter out expectedactivity so anomalies are easier to detect. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79195-42. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure Network Access Control Lists (NACL) changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure Network Access Control Lists (NACL) changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. NACLs are usedas a stateless packet filter to control ingress and egress traffic for subnets within a VPC.It is recommended that a metric filter and alarm be established for changes made toNACLs. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to NACLs will help ensure that AWS resources and services are notunintentionally exposed. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79196-22. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure changes to network gateways are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure changes to network gateways are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. Networkgateways are required to send/receive traffic to a destination outside of a VPC. It is recommended that a metric filter and alarm be established for changes to networkgateways Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to network gateways will help ensure that all ingress/egress traffictraverses the VPC border via a controlled path Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79197-02. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure route table changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure route table changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. Routing tablesare used to route network traffic between subnets and to network gateways. It is recommended that a metric filter and alarm be established for changes to route tables. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to route tables will help ensure that all VPC traffic flows through anexpected path and prevent any accidental or intentional modifications that may lead touncontrolled network traffic. An alarm should be triggered every time an AWS API call isperformed to create, replace, delete, or disassociate a Route Table. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79198-82. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.htm
|
| Ensure VPC changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure VPC changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. It is possible tohave more than 1 VPC within an account, in addition it is also possible to create a peerconnection between 2 VPCs enabling network traffic to route between VPCs. It is recommended that a metric filter and alarm be established for changes made to VPCs Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.VPCs in AWS are logically isolated virtual networks that can be used to launch AWSresources. Monitoring changes to VPC configuration will help ensure VPC traffic flow isnot getting impacted. Changes to VPCs can impact network accessibility from the publicinternet and additionally impact VPC traffic flow to and from resources launched in theVPC. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. CCE-79199-62. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/receive-cloudtrail-log-files-from-multiple-regions.html3. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html4. https https://docs.aws.amazon.com/sns/latest/dg/SubscribeTopic.html
|
| Ensure AWS Organizations changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure AWS Organizations changes are monitored Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs toCloudWatch Logs, and establishing corresponding metric filters and alarms. It is recommended that a metric filter and alarm be established for AWS Organizationschanges made in the master AWS Account. Rationale CloudWatch is an AWS native service that allows you to observe and monitor resourcesand applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring AWS Organizations changes can help you prevent any unwanted, accidentalor intentional modifications that may lead to unauthorized access or other securitybreaches. This monitoring technique helps you to ensure that any unexpected changesperformed within your AWS Organizations can be investigated and any unwantedchanges can be rolled back. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html1. https https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html2. https https://docs.aws.amazon.com/organizations/latest/userguide/orgs_security_incident-response.html
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure no Network ACLs allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure no Network ACLs allow ingress from 0000-0 to remote server administration ports Description The Network Access Control List (NACL) function provide stateless filtering of ingressand egress network traffic to AWS resources. It is recommended that no NACL allowsunrestricted ingress access to remote server administration ports, such as SSH to port22 and RDP to port 3389, using either the TDP (6), UDP (17) or ALL (-1) protocols Rationale Public access to remote server administration ports, such as 22 and 3389, increasesresource attack surface and unnecessarily raises the risk of resource compromise. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure no security groups allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure no security groups allow ingress from 0000-0 to remote server administration ports Description Security groups provide stateful filtering of ingress and egress network traffic to AWSresources. It is recommended that no security group allows unrestricted ingress accessto remote server administration ports, such as SSH to port 22 and RDP to port 3389,using either the TDP (6), UDP (17) or ALL (-1) protocols Rationale Public access to remote server administration ports, such as 22 and 3389, increasesresource attack surface and unnecessarily raises the risk of resource compromise. Impact When updating an existing environment, ensure that administrators have access toremote server administration ports through another mechanism before removing accessby deleting the 0.0.0.0/0 inbound rule. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure the default security group of every VPC restricts all traffic | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure the default security group of every VPC restricts all traffic Description A VPC comes with a default security group whose initial settings deny all inbound traffic,allow all outbound traffic, and allow all traffic between instances assigned to the securitygroup. If you don't specify a security group when you launch an instance, the instance isautomatically assigned to this default security group. Security groups provide statefulfiltering of ingress/egress network traffic to AWS resources. It is recommended that thedefault security group restrict all traffic.The default VPC in every region should have its default security group updated tocomply. Any newly created VPCs will automatically contain a default security group thatwill need remediation to comply with this recommendation.NOTE: When implementing this recommendation, VPC flow logging is invaluable indetermining the least privilege port access required by systems to work properlybecause it can log all packet acceptances and rejections occurring under the currentsecurity groups. This dramatically reduces the primary barrier to least privilegeengineering - discovering the minimum ports required by systems in the environment.Even if the VPC flow logging recommendation in this benchmark is not adopted as apermanent security measure, it should be used during any period of discovery andengineering for least privileged security groups. Rationale Configuring all VPC default security groups to restrict all traffic will encourage leastprivilege security group development and mindful placement of AWS resources intosecurity groups which will in-turn reduce the exposure of those resources. Impact Implementing this recommendation in an existing VPC containing operating resourcesrequires extremely careful migration planning as the default security groups are likely tobe enabling many ports that are unknown. Enabling VPC flow logging (of accepts) in anexisting environment that is known to be breach free will reveal the current pattern ofports being used for each instance to communicate successfully Recommendation and Steps Associated Items
Affected Objects
|
| Ensure routing tables for VPC peering are least access | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure routing tables for VPC peering are least access Description Once a VPC peering connection is established, routing tables must be updated toestablish any connections between the peered VPCs. These routes can be as specificas desired - even peering a VPC to only a single host on the other side of theconnection. Rationale Being highly selective in peering routing tables is a very effective way of minimizing theimpact of breach as resources outside of these routes are inaccessible to the peeredVPC. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that EC2 Metadata Service only allows IMDSv2 | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that EC2 Metadata Service only allows IMDSv2 Description When enabling the Metadata Service on AWS EC2 instances, users have the option ofusing either Instance Metadata Service Version 1 (IMDSv1; a request/responsemethod) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method). Rationale Instance metadata is data about your instance that you can use to configure or managethe running instance. Instance metadata is divided into categories, for example, hostname, events, and security groups.When enabling the Metadata Service on AWS EC2 instances, users have the option ofusing either Instance Metadata Service Version 1 (IMDSv1; a request/responsemethod) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method).With IMDSv2, every request is now protected by session authentication. A sessionbegins and ends a series of requests that software running on an EC2 instance uses toaccess the locally-stored EC2 instance metadata and credentials.Allowing Version 1 of the service may open EC2 instances to Server-Side RequestForgery (SSRF) attacks, so Amazon recommends utilizing Version 2 for better instancesecurity. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure no security groups allow ingress from ---0 to remote server administration ports | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
X TEST NAME Ensure no security groups allow ingress from ---0 to remote server administration ports Description Security groups provide stateful filtering of ingress and egress network traffic to AWSresources. It is recommended that no security group allows unrestricted ingress accessto remote server administration ports, such as SSH to port 22 and RDP to port 3389. Rationale Public access to remote server administration ports, such as 22 and 3389, increasesresource attack surface and unnecessarily raises the risk of resource compromise. Impact When updating an existing environment, ensure that administrators have access toremote server administration ports through another mechanism before removing accessby deleting the ::/0 inbound rule Recommendation and Steps Perform the following to implement the prescribed state: 1. Login to the AWS Management Console at https://console.aws.amazon.com/vpc/home 2. In the left pane, click Security Groups 3. For each security group, perform the following: 4. Select the security group 5. Click the Inbound Rules tab 6. Click the Edit inbound rules button 7. Identify the rules to be edited or removed 8. Either A) update the Source field to a range other than ::/0, or, B) Click Delete to remove the offending inbound rule 9. Click Save rules Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Consistent Naming Convention is used for Organizational AMI | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Consistent Naming Convention is used for Organizational AMI Description The naming convention for AMI (Amazon Machine Images) should be documented and followed for any AMI's created. Rationale The majority of AWS resources can be named and tagged. Most organizations have already created standardize naming conventions, and have existing rules in effect. They simply need to extend that for all AWS cloud resources to include Amazon Machine Images (AMI) Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Images (AMIs) are encrypted | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Images (AMIs) are encrypted Description Amazon Machine Images should utilize EBS Encrypted snapshots Rationale AMIs backed by EBS snapshots should use EBS encryption. Snapshot volumes can be encrypted and attached to an AMI. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Only Approved AMIs (Images) are Used | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure Only Approved AMIs (Images) are Used Description Ensure that all base AMIs utilized are approved for use by your organization. Rationale An approved AMI is a base EC2 machine image that is a pre-configured OS configured to run your application. Using approved AMIs helps enforce consistency and security. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Images (AMI) are not older than 90 days | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure Images (AMI) are not older than 90 days Description Ensure that your AMIs are not older than 90 days Rationale Using up-to-date AMIs will provide many benefits from OS updates and security patches helping to ensure reliability, security and compliance. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Images are not Publicly Available | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure Images are not Publicly Available Description EC2 allows you to make an AMI public, sharing it with all AWS accounts. Rationale Publicly sharing an AMI with all AWS accounts could expose organizational data and configuration information. Impact Recommendation and Steps Associated Items Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Apply updates to any apps running in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Apply updates to any apps running in Lightsail Description Amazon Lightsail is a virtual private server (VPS) provider and is the easiest way to get started with AWS for developers, small businesses, students, and other users who need a solution to build and host their applications on cloud. Rationale Lightsail offers a range of operating system and application templates that are automatically installed when you create a new Lightsail instance. Application templates include WordPress, Drupal, Joomla!, Ghost, Magento, Redmine, LAMP, Nginx (LEMP), MEAN, Node.js, Django, and more. You can install additional software on your instances by using the in-browser SSH or your own SSH client. Impact Recommendation and Steps Associated Items
Affected Objects |
| Change default Administrator login names and passwords for applications | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Change default Administrator login names and passwords for applications Description Change the default settings for the administrator login names and passwords of the application software that you install on Lightsail instances. Rationale Default administrator login names and passwords for applications used on Lightsail instances can be used by hackers and individuals to break into your servers. Impact Recommendation and Steps Associated Items
Affected Objects |
| Disable SSH and RDP ports for Lightsail instances when not needed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Disable SSH and RDP ports for Lightsail instances when not needed Description Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should remove and disable these ports when not is use. Rationale Any ports enable within Lightsail by default are open and exposed to the world. This can result in outside traffic trying to access or even deny access to the Lightsail instances. Removing and disabling a protocol when not in use even if restricted by IP address is the safest solution especially when it is not required for access. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure SSH is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure SSH is restricted to only IP address that should have this access Description Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should identify which IP address need access. Rationale Any ports enable within Lightsail by default are open and exposed to the world. This can result in outside traffic trying to access or even deny access to the Lightsail instances. Removing and adding approved IP address required for access. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure RDP is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure RDP is restricted to only IP address that should have this access Description Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should identify which IP address need access. Rationale Any ports enable within Lightsail by default are open and exposed to the world. This can result in outside traffic trying to access or even deny access to the Lightsail instances. Removing and adding approved IP address required for access. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Disable IPv6 Networking if not in use within your organization | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Disable IPv6 Networking if not in use within your organization Description Any protocols enable within Lightsail by default that aren't being used should be disabled. Rationale Any ports enable within Lightsail by default are open and exposed to the world. This can result in outside traffic trying to access or even deny access to the Lightsail instances. Removing and disabling a protocol when not in use even if restricted by IP address is the safest solution especially when it is not required for access. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure you are using an IAM policy to manage access to buckets in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure you are using an IAM policy to manage access to buckets in Lightsail Description The following policy grants a user access to manage a specific bucket in the Amazon Lightsail object storage service. Rationale This policy grants access to buckets through the Lightsail console, the AWS Command Line Interface (AWS CLI), AWS API, and AWS SDKs. Impact Users who don't have this policy will experience errors when viewing the Objects tab of the bucket management page in the Lightsail console. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure Lightsail instances are attached to the buckets | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Lightsail instances are attached to the buckets Description Attaching an Amazon Lightsail instance to a Lightsail storage bucket gives it full programmatic access to the bucket and its objects. Rationale When you attach instances to buckets, you don't have to manage credentials like access keys. Resource access is ideal if you're configuring software or a plugin on your instance to upload files directly to your bucket. For example, if you want to configure a WordPress instance to store media files on a bucket configuration with bucket storage resource access allows for that securely. Impact You can attach instances that are in a running state only. Additionally, the instances have to be in the same AWS Region as the bucket or the buckets have to be in the same region as the instances. Recommendation and Steps Associated Items
Affected Objects |
| Ensure that your Lightsail buckets are not publicly accessible | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure that your Lightsail buckets are not publicly accessible Description You can make all objects private, public (read-only) or private while making individual objects public (read-only). By default when creating a bucket the permissions are set to All objects are private. Rationale When the Bucket access permissions are set to All objects are public (read-only) and All objects in the bucket are readable by anyone on the internet through the URL of the bucket. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Enable storage bucket access logging | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Enable storage bucket access logging Description Access logging provides detailed records for the requests that are made to this bucket. This information can include the request type, the resources that are specified in the request, and the time and date that the request was processed. Access logs are useful for many applications. Rationale Access log information is useful in security and access audits. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure your Windows Server based lightsail instances are updated with the latest security patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure your Windows Server based lightsail instances are updated with the latest security patches Description Windows server based Lightsail instances are still managed by the consumer and any security updates or patches have to be installed and maintained by the user. Rationale Windows Server-based Lightsail instances need to be updated with the latest security patches so they are not vulnerable to attacks. Be sure your server is configured to download and install updates. Impact Recommendation and Steps Associated Items
Affected Objects |
| Change the auto-generated password for Windows based instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Change the auto-generated password for Windows based instances Description When you create a Windows Server-based instance, Lightsail randomly generates a long password that is hard to guess. You use this password uniquely with your new instance. You can use the default password to connect quickly to your instance using remote desktop (RDP). You are always logged in as the Administrator on your Lightsail instance. Rationale Like any password it should be changed from the default and over time. The randomly generated password can be hard to remember and if anyone gains access to your AWS Lightsail environment they can utilize that to access your instances. For this reason you should change the password to something you can remember. Impact If you change your password from the unique, default password, be sure to use a strong password. You should avoid passwords that are based on names or dictionary words, or repeating sequences of characters. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure AWS Config is Enabled for Lambda and Serverless | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure AWS Config is Enabled for Lambda and Serverless Description With AWS Config, you can track configuration changes to the Lambda functions (including deleted functions), runtime environments, tags, handler name, code size, memory allocation, timeout settings, and concurrency settings, along with Lambda IAM execution role, subnet, and security group associations. Rationale This gives you a holistic view of the Lambda function's lifecycle and enables you to surface that data for potential audit and compliance requirements. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure Cloudwatch Lambda insights is enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Cloudwatch Lambda insights is enabled Description Ensure that Amazon CloudWatch Lambda Insights is enabled for your Amazon Lambda functions for enhanced monitoring Rationale Amazon CloudWatch Lambda Insights allows you to monitor, troubleshoot, and optimize your Lambda functions. The service collects system-level metrics and summarizes diagnostic information to help you identify issues with your Lambda functions and resolve them as soon as possible. CloudWatch Lambda Insights collects system-level metrics and emits a single performance log event for every invocation of that Lambda function. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure AWS Secrets manager is configured and being used by Lambda for databases | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure AWS Secrets manager is configured and being used by Lambda for databases Description Lambda functions often have to access a database or other services within your environment. Rationale Credentials used to access databases and other AWS Services need to be managed and regularly rotated to keep access into critical systems secure. Keeping any credentials and manually updating the passwords would be cumbersome, but AWS Secrets Manager allows you to manage and rotate passwords. Impact note - Lambda code should be checked for correct configuration to get the credentials from AWS Secrets Manager. This audit and remediation is only to confirm you have the credentials in Secrets manager. Recommendation and Steps Associated Items
Affected Objects |
| Ensure least privilege is used with Lambda function access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure least privilege is used with Lambda function access Description Lambda is fully integrated with IAM, allowing you to control precisely what each Lambda function can do within the AWS Cloud. As you develop a Lambda function, you expand the scope of this policy to enable access to other resources. For example, for a function that processes objects put into an S3 bucket, it requires read access to objects stored in that bucket. Do not grant the function broader permissions to write or delete data, or operate in other buckets. Rationale You can use AWS Identity and Access Management (IAM) to manage access to the Lambda API and resources like functions and layers. For users and applications in your account that use Lambda, you manage permissions in a permissions policy that you can apply to IAM users, groups, or roles. To grant permissions to other accounts or AWS services that use your Lambda resources, you use a policy that applies to the resource itself. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/service-
authorization/latest/reference/reference_policies_actions-resources-
contextkeys.html
2. https https://awspolicygen.s3.amazonaws.com/policygen.html
3. https https://policysim.aws.amazon.com/home/index.jsp?#
4. https https://github.com/aws-samples/aws-iamctl/
5. https https://docs.aws.amazon.com/lambda/latest/operatorguide/least-privilege-
iam.html
|
| Ensure every Lambda function has its own IAM Role | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure every Lambda function has its own IAM Role Description Every Lambda function should have a one to one IAM execution role and the roles should not be shared between functions. Rationale The Principle of Least Privilege means that any Lambda function should have the minimal amount of access required to perform its tasks. In order to accomplish this Lambda functions should not share IAM Execution roles. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Lambda functions are not exposed to everyone | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Lambda functions are not exposed to everyone Description A publicly accessible Amazon Lambda function is open to the public and can be reviewed by anyone. To protect against unauthorized users that are sending requests to invoke these functions they need to be changed so they are not exposed to the public. Rationale Allowing anyone to invoke and run your Amazon Lambda functions can lead to data exposure, data loss, and unexpected charges on your AWS bill. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure Lambda functions are referencing active execution roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Lambda functions are referencing active execution roles Description In order to have the necessary permissions to access the AWS cloud services and resources Amazon Lambda functions should be associated with active(available) execution roles. Rationale A Lambda function's execution role is an Identity and Access Management (IAM) role that grants the function permission to process and access specific AWS services and resources. When Amazon Lambda functions are not referencing active execution roles, the functions are losing the ability to perform critical operations securely. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure that Code Signing is enabled for Lambda functions | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure that Code Signing is enabled for Lambda functions Description Ensure that all your Amazon Lambda functions are configured to use the Code Signing feature in order to restrict the deployment of unverified code. Rationale Code Signing, ensures that the function code is signed by an approved (trusted) source, and that it has not been altered since signing, and that the code signature has not expired or been revoked. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure there are no Lambda functions with admin privileges within your AWS account | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure there are no Lambda functions with admin privileges within your AWS account Description Ensure that your Amazon Lambda functions don't have administrative permissions potentially giving the function access to all AWS cloud services and resources. Rationale In order to promote the Principle of Least Privilege (POLP) and provide your functions the minimal amount of access required to perform their tasks the right IAM execution role associated with the function should be used. Instead of providing administrative permissions you should grant the role the necessary permissions that the function really needs. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Lambda functions do not allow unknown cross account access via permission policies | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Lambda functions do not allow unknown cross account access via permission policies Description Ensure that all your Amazon Lambda functions are configured to allow access only to trusted AWS accounts in order to protect against unauthorized cross-account access. Rationale Allowing unknown (unauthorized) AWS accounts to invoke your Amazon Lambda functions can lead to data exposure and data loss. To prevent any unauthorized invocation requests for your Lambda functions, restrict access only to trusted AWS accounts. Impact Recommendation and Steps From the Console 1. Login to the AWS Console using https://console.aws.amazon.com/lambda/. 2. In the left column, under AWS Lambda, click Functions. 3. Under Function name click on the name of the function that you want to review 4. Click the Configuration tab 5. In the left column, click Permissions. 6. In the Resource-based policy statements section, select the policy statement that allows the unknown AWS Account cross-account access 7. Click Edit 8. On the Edit permissions page, replace or remove the AWS Account(s) ARN of the unauthorized principal in the Principal box 9. Click Save 10. Repeat steps for each Lambda function that failed the Audit Associated Items Affected Objects |
| Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates Description Always using a recent version of the execution environment configured for your Amazon Lambda functions adheres to best practices for the newest software features, the latest security patches and bug fixes, and performance and reliability. Rationale When you execute your Lambda functions using recent versions of the implemented runtime environment, you should benefit from new features and enhancements, better security, along with performance and reliability. Impact Recommendation and Steps From the Console 1. Login to the AWS Console using https://console.aws.amazon.com/lambda/. 2. In the left column, under AWS Lambda, click Functions. 3. Under Function name click on the name of the function that you want to review 4. Click Code tab 5. Go to the Runtime settings section. 6. Click Edit 7. On the Edit runtime settings page, select the latest supported version of the runtime environment from the dropdown list. **Note - make sure the correct architecture is also selected. 8. Click Save 9. Select the Code tab 10. Click Test from the Code source section. 11. Once the testing is completed, the execution result of your Lambda function will be listed 12. Repeat steps for each Lambda function that failed the Audit within the current region. From the Command Line 1. Run aws lambda update-function-configuration using the name of the Function you need to remediate aws lambda update-function-configuration --output table --query 'Functions[*].FunctionName' This command will provide a table titled ListFunctions 2. Run aws lambda get-function-configuration using the Function names returned in the table. aws lambda get-function-configuration --function-name name_of_fuunction -- function-name name_of_function --runtime python3.9 3. The command output should return the metadata available for the reconfigured function. 4. Repeat steps 1-2 to upgrade the runtime environment for each Amazon Lambda function found in the Audit Associated Items Affected Objects More Information TEST ID
|
| Ensure encryption is enabled for Lambda function variables | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure encryption is enabled for Lambda function variables Description As you can set your own environmental variables for Lambda it is important to also encrypt them for in transit protection. Rationale Lambda environment variables should be encrypted in transit for client-side protection as they can store sensitive information. Impact Recommendation and Steps From the Console 1. Login to the AWS Console using https://console.aws.amazon.com/lambda/. 2. In the left column, under AWS Lambda, click Functions. 3. Under Function name click on the name of the function that you want to review 4. Click the Configuration tab 5. In the left column, click Environment variables. 6. In the Environment variables section, click Edit 7. Click the check box for Enable helpers for encryption in transit 8. Click the Encrypt option for all the variable that need to be encrypted. 9. Repeat steps 2 and 8 for each Lambda function identified in the Audit within the current AWS region. 10. Repeat this remediation for all the other AWS regions. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Batch roles are configured for cross-service confused deputy prevention | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Batch roles are configured for cross-service confused deputy prevention Description The Cross-service confused deputy problem is a security issue where an entity that doesn't have permission to perform an action can coerce a more-privileged entity to perform the action. Rationale Cross-service impersonation can result in the confused deputy problem. Cross-service impersonation can occur when one service (the calling service) calls another service (the called service). The calling service can be manipulated to use its permissions to act on another customer's resources in a way it should not otherwise have permission to access. Impact An IAM role is an identity you can create that has specific permissions with credentials that are valid for short durations. Roles can be assumed by entities that you trust. IAM Roles are often organization named and organization based. Searching for and reviewing the roles for this recommendation is a manual process. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure AWS Batch is configured with AWS Cloudwatch Logs | Manual Check | NONE | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure AWS Batch is configured with AWS Cloudwatch Logs Description You can configure Batch jobs to send log information to CloudWatch Logs Rationale This enables you to view different logs from all your jobs in one convenient location. Impact Recommendation and Steps From the Console 1. Login to the AWS Console using https://console.aws.amazon.com/batch/. 2. In the left column under Console settings, Click on Permissions 3. In the Job logs section click on Edit 4. Click the Authorize Batch to use CloudWatch 5. Click Save Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Managed Platform updates is configured | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Managed Platform updates is configured Description AWS Elastic Beanstalk regularly releases platform updates to provide fixes, software updates, and new features. With managed platform updates, you can configure your environment to automatically upgrade to the latest version of a platform during a scheduled maintenance window. Rationale Your application remains in service during the update process with no reduction in capacity. Managed updates are available on both single-instance and load-balanced environments. They also ensure you aren't introducing any vulnerabilities by running legacy systems that require updates and patches. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure Persistent logs is setup and configured to S3 | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Persistent logs is setup and configured to S3 Description Elastic Beanstalk can be configured to automatically stream logs to the CloudWatch service. Rationale With CloudWatch Logs, you can monitor and archive your Elastic Beanstalk application, system, and custom log files from Amazon EC2 instances of your environments. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure access logs are enabled | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure access logs are enabled Description When you enable load balancing, your AWS Elastic Beanstalk environment is equipped with an Elastic Load Balancing load balancer to distribute traffic among the instances in your environment Rationale For security reasons it is important to have a record of all the access logs and this is enabled within the Load Balancer assigned to the Elastic Beanstalk environments. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure that HTTPS is enabled on load balancer | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure that HTTPS is enabled on load balancer Description The simplest way to use HTTPS with an Elastic Beanstalk environment is to assign a server certificate to your environment's load balancer Rationale When you configure your load balancer to terminate HTTPS, the connection between the client and the load balancer is secure. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure you are using VPC Endpoints for source code access | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure you are using VPC Endpoints for source code access Description App Runner needs access to your application source, so it can't be encrypted. Therefore, be sure to secure the connection between your development or deployment environment and App Runner. Rationale Client-side encryption isn't a valid method for protecting the source image or code that you provide to App Runner for deployment. Using a VPC endpoint, you can privately connect your VPC to supported AWS services and VPC endpoint services that are powered by AWS PrivateLink. Impact Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure communications between your applications and clients is encrypted | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure communications between your applications and clients is encrypted Description SimSpace Weaver doesn't manage communications between your apps and the clients. Rationale Be sure to implement some form of authentication and encryption for all client sessions while using SimSpace Weaver. Impact Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure securing AWS Backups | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure securing AWS Backups Description As an AWS administrator, it's important to know what you're responsible for. You're responsible for keeping things safe in the cloud, which means taking care of the resources and data on AWS. Here's what you need to secure, according to AWS documentation: 1. Responsible for alert communication with AWS. 2. Managing access credentials for AWS resources. 3. Configuring backup plans according to organization policies. 4. Ensuring backup recovery capability. 5. Including AWS Backups in the organization's disaster recovery procedures. 6. Ensuring user awareness and familiarity with AWS Backups platform usage Rationale AWS will send periodic emails regarding the status of your backups and any service issues. The administrator must address any communicated issues from AWS, such as billing problems or backup inactivity, and take necessary steps to resolve them. Impact Recommendation and Steps As an AWS administrator, it's important to know what you're responsible for. You're responsible for keeping things safe in the cloud, which means taking care of the resources and data on AWS. Here's what you need to secure, according to AWS documentation: 1. Responsible for alert communication with AWS. 2. Managing access credentials for AWS resources. 3. Configuring backup plans according to organization policies. 4. Ensuring backup recovery capability. 5. Including AWS Backups in the organization's disaster recovery procedures. 6. Ensuring user awareness and familiarity with AWS Backups platform usage AWS will send periodic emails regarding the status of your backups and any service issues. The administrator must address any communicated issues from AWS, such as billing problems or backup inactivity, and take necessary steps to resolve them. Associated Items
Affected Objects
More Information TEST ID
|
| AWS Storage Backups | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME AWS Storage Backups Description AWS Storage Backups is a managed AWS Service that establishes high resiliency to your cloud resources. AWS Storage Backups are like making extra copies of your important stuff on Amazon's computers. It is an excellent strategy to ensure that the data and resources you use remain available in the event of unrecoverable damage or loss to your resources. Rationale AWS Backups enable you to back up and restore all data lost during the attack,While AWS Storage Backups provide a level of security, there are numerous methods to fortify your backups, ensuring the protection of your data and services. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to create backup template and name | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure to create backup template and name Description To create a backup plan, select a template and specify a name for the plan. Additionally, define backup rules according to your requirements and then click on create backup option. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure to create AWS IAM Policies | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure to create AWS IAM Policies Description AWS IAM policies, specify the desired permissions for accessing AWS resources and define the conditions under which those permissions are granted. Configure the appropriate policies to keep your resources secure. Rationale Managing AWS IAM policies is crucial to safeguard your backups from unauthorized access, ensuring that only approved users can manipulate or view sensitive data. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure to create IAM roles for Backup | Passed | Status: Configured Correctly | When using the AWS Backup console for the first time, you can choose to have AWS Backup create a default service role for you. This role has the permissions that AWS Backup needs to create and restore backups on your behalf. | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to create IAM roles for Backup Description An AWS Identity and Access Management (IAM) role is similar to a user, in that it is an AWS identity with permissions policies that determine what the identity can and cannot do in AWS. However, instead of being uniquely associated with one person, a role is intended to be assumable by anyone who needs it. Rationale While Service Linked Roles offer quick deployment, using default configurations isn't recommended for security best practices. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure AWS Backup with Service Linked Roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure AWS Backup with Service Linked Roles Description AWS Service Linked Roles are IAM roles designed specifically for AWS Backup. These roles come with default configurations allowing access to all AWS resources by default. Rationale While Service Linked Roles offer quick deployment, using default configurations isn't recommended for security best practices. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure EBS volume encryption is enabled | High | Status:Not Configured correctly | N/A | Level 2 | CIS v1.0.0 | NO |
X TEST NAME Ensure EBS volume encryption is enabled Description Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported. Rationale Encrypting data at rest reduces the likelihood that it is unintentionally exposed and can nullify the impact of disclosure if the encryption remains unbroken. Impact Recommendation and Steps From Console: 1. Login to the EC2 console using https://console.aws.amazon.com/ec2/ 2. Under Account attributes, click EBS encryption. 3. Click Manage. 4. Click the Enable checkbox. 5. Click Update EBS encryption 6. Repeat for every region requiring the change. Note: EBS volume encryption is configured per region. From Command Line: 1. Run aws --region Associated Items
Affected Objects
|
| Ensure Tag Policies are Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Tag Policies are Enabled Description Tag policies help you standardize tags on all tagged resources across your organization. Rationale You can use tag policies to define tag keys (including how they should be capitalized) and their allowed values. Impact Recommendation and Steps From the Console: You must sign in as an IAM user, assume an IAM role, or sign in as the root user (not recommended) in the organization's management account. 1. Login to AWS Organizations using https://console.aws.amazon.com/organizations/ 2. In the Left pane click on Policies 3. Click on Tag policies 4. Click on Enable Tag Policies 5. The page is update with a list of the Available policies and the ability to create one. From the Command Line: You must use an IAM user, assume an IAM role, or sign in as the root user (not recommended) in the organization's management account. 1. Run the enable-policy-type command aws organizations enable-policy-type --root-id Associated Items
Affected Objects
|
| Ensure no AWS EC2 Instances are Older than 180 days | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure no AWS EC2 Instances are Older than 180 days Description Identify any running AWS EC2 instances older than 180 days. Rationale An EC2 instance is not supposed to run indefinitely and having instance older than 180 days can increase the risk of problems and issues. Impact Recommendation and Steps From the Console: 1. Login to EC2 using https://console.aws.amazon.com/ec2/ 2. On the left Click INSTANCES, click Instances. 3. Select the EC2 instance identified above in the audit. The Instance State must be 'running'. 4. Click Actions, click Instance State, click Stop. 5. Wait for the Instance State to read 'stopped'. 6. Click 'Actions' click 'Instance State', click 'Start' 7. Select the Description tab. 8. Check the Launch time. Confirm that the instance active age is now set to today's date and time. Associated Items
Affected Objects
|
| Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches Description Tags can help with managing, identifying, organizing, searching for, and filtering resources. Additionally, tags can help with security and compliance. Tags can be propagated from an Auto Scaling group to the EC2 instances that it launches. Rationale Without tags, EC2 instances created via Auto Scaling can be without tags and could be out of compliance with security policy. Impact Recommendation and Steps AWS Console 1. Login to AWS Console using https://console.aws.amazon.com 2. Click All services and click EC2 under Compute. 3. Select Auto Scaling Groups. 4. Click Edit for each Auto Scaling Group. 5. Check the Tag new instances Box for the Auto Scaling Group. 6. Click Update. 7. Repeat Steps 1-6 for each AWS Region used. 1. Run aws autoscaling create-or-update-tags for tags that are not set to PropogateAtLaunch for each Auto Scaling Group that does not have this property set to true. aws autoscaling create-or-update-tags \ --tags ResourceId=example-autoscaling-group,ResourceType=auto-scaling- group,Key=TagKey,Value=TagValue,PropagateAtLaunch=true 2. Repeat Step 1 for each AWS Region used. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure configuring Security Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure configuring Security Groups Description Security groups are your first line of defense for the EC2 instance. A security group is a firewall that controls inbound and outbound traffic. Rationale Security groups play a critical role in maintaining the security of your AWS resources. It is advisable to restrict traffic to only what is necessary for accessing your instance, thereby minimizing potential security risks. Impact Recommendation and Steps Security groups are your first line of defense for the EC2 instance. A security group is a firewall that controls inbound and outbound traffic. Security groups play a critical role in maintaining the security of your AWS resources. It is advisable to restrict traffic to only what is necessary for accessing your instance, thereby minimizing potential security risks. Associated Items Affected Objects |
| Ensure the proper configuration of EBS storage | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure the proper configuration of EBS storage Description All computer instances need to have a device on which to store files. EBS is built on top of EC2 instances as a block storage device. Rationale Remember that we are working with cloud computing. Rather than purchasing and manually installing disk drives on a server, AWS allows you to virtually add storage using Elastic Block Store (EBS). Impact Failure to properly configure EBS storage can lead to data loss, performance issues, increased costs, security vulnerabilities, and operational downtime. Ensuring correct configuration is crucial to maintain data integrity, efficiency, cost-effectiveness, security, and reliability. Recommendation and Steps 1. Open the Amazon EC2 Console: Navigate to the EC2 Dashboard in the AWS Management Console. 2. Select Volumes: Under the Elastic Block Store section, select Volumes. 3. Create Volume: o Click on Create Volume. o Choose the volume type (e.g., General Purpose SSD (gp2), Provisioned IOPS SSD (io1), etc.). o Specify the size and availability zone. o Optionally, configure additional settings such as IOPS, encryption, and tags. 4. Attach Volume to Instance: o Select the volume you created. o Click on Actions and choose Attach Volume. o Select the instance to which you want to attach the volume and specify the device name. 5. Format and Mount the Volume (on the instance): o Connect to your instance using SSH. o List available disks using the command: lsblk. o Format the new volume (e.g., sudo mkfs -t ext4 /dev/xvdf for ext4 filesystem). o Create a mount point (e.g., sudo mkdir /mnt/data). o Mount the volume (e.g., sudo mount /dev/xvdf /mnt/data). 6. Configure Automatic Mounting (optional): o Edit the /etc/fstab file to add an entry for the new volume to ensure it mounts automatically on reboot. o Example entry: /dev/xvdf /mnt/data ext4 defaults,nofail 0 2. By following these steps, you can effectively configure and manage EBS storage for your AWS instances. Associated Items
Affected Objects |
| Ensure the Creation of IAM Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure the Creation of IAM Groups Description IAM Groups are collections of users that share the same permissions for accessing AWS resources. For instance, you can create a group named Administrators, which includes users who require full access to your AWS environment. This simplifies permission management by assigning common access policies to all members of the group. Rationale IAM groups in AWS simplify permission management by grouping users with similar access needs and applying common access policies, reducing administrative overhead and enhancing security through the principle of least privilege. This approach ensures consistency, scalability, and ease of auditing, strengthening the overall security posture of the AWS environment. Impact Recommendation and Steps 1. CloudTrail and AWS Config Configuration: o If CloudTrail or AWS Config is not enabled, configure them to capture and monitor IAM activities and configurations respectively. Enable logging and set up appropriate rules to track IAM group changes and ensure compliance. 2. Review CloudTrail Logs for Anomalies: o Regularly review CloudTrail logs to identify any unauthorized or unexpected changes to IAM groups. o Investigate any anomalies detected in the logs, such as unauthorized user additions or policy modifications, and take appropriate action to rectify them. 3. AWS Config Remediation Rules: o Define AWS Config rules to automatically detect non-compliant IAM group configurations. o Configure remediation actions within AWS Config to automatically revert any deviations from the desired IAM group settings back to the compliant state. 4. IAM Group Cleanup: o Periodically review IAM groups to ensure they are still necessary and relevant. o Remove any unused or obsolete IAM groups to reduce the attack surface and simplify permission management. 5. Permissions Review: o Regularly review the permissions assigned to IAM groups to ensure they follow the principle of least privilege. o Remove any excessive permissions or policies that are not required for the group's intended purpose. 6. Security Best Practices: o Implement security best practices for IAM, such as enforcing multi-factor authentication (MFA) for privileged IAM users and regularly rotating access keys. o Train IAM administrators and users on security best practices to prevent inadvertent misconfigurations and unauthorized access. 7. Documentation and Monitoring: o Document IAM group configurations, policies, and access controls to maintain an audit trail and facilitate future audits. o Set up monitoring alerts to notify administrators of any suspicious activities related to IAM groups. Associated Items
Affected Objects More Information TEST ID
|
| Ensure Granular Policy Creation | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure Granular Policy Creation Description Granular policies are meticulously tailored to AWS resources, ensuring precision in access control measures. Rationale Emphasizing granular policies in AWS ensures that access control measures are precisely aligned with the requirements of each resource, bolstering security and minimizing unauthorized access. By tailoring policies to specific resources, organizations can adhere more closely to the principle of least privilege, mitigating risks and maintaining compliance with regulatory standards. Impact Recommendation and Steps 1. Policy Refinement: o Review existing IAM policies to identify those that are overly broad or lack granularity. o Refine these policies to restrict permissions to only the resources and actions necessary for each user or group. 2. IAM Policy Simulator: o Utilize the IAM Policy Simulator in the AWS Management Console to test the effectiveness of policy changes. o Simulate various access scenarios to ensure that policies are granting the intended level of access without unintended consequences. 3. Access Reviews: o Conduct regular access reviews to ensure that IAM policies remain aligned with the principle of least privilege. o Identify and remove any unnecessary permissions or policies that grant excessive access to resources. 4. AWS Config Remediation: o Configure AWS Config rules to automatically remediate non-compliant IAM policies. o Set up remediation actions to adjust policies to adhere to granular access control principles automatically. 5. Employee Training: o Provide training and guidance to IAM administrators on best practices for crafting granular policies. o Ensure that administrators understand the importance of restricting permissions to only what is necessary for each user or group. 6. Monitoring and Alerting: o Implement continuous monitoring solutions to detect and alert on any deviations from granular access control policies. o Set up alerts to notify administrators of any unauthorized changes to IAM policies in real-time. 7. Documentation and Documentation: o Document changes made to IAM policies and keep records of policy adjustments. o Maintain up-to-date documentation on IAM policies and access controls for reference during audits and compliance assessments. Associated Items
Affected Objects More Information TEST ID
|
| Ensure Resource Access via Tag-based Policies | High | Status: Not Configured | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure Resource Access via Tag-based Policies Description For optimal granularity in EC2 access, configuring IAM policies via tags proves highly effective. This involves editing the JSON text editor to specify access permissions based on specific tags. In the provided example, I'm granting the developers group access exclusively to the newly created EC2 image, as illustrated in the attached screenshot depicting the policy creation process. Rationale Implementing IAM policies based on tags in EC2 enables administrators to finely tailor access control, granting permissions dynamically according to resource attributes. This approach enhances security and scalability by aligning access rights with specific resource requirements while minimizing manual intervention. Impact Recommendation and Steps 1. Policy Adjustment: o Review existing IAM policies associated with EC2 resources to ensure they include tag-based conditions where applicable. o Modify policies to incorporate tag-based conditions for granular access control, ensuring that access is granted or denied based on resource attributes. 2. IAM Policy Simulator Validation: o Utilize the IAM Policy Simulator to validate the effectiveness of policy adjustments. o Test various access scenarios to verify that policies accurately reflect the intended access control based on EC2 resource tags. 3. AWS Config Remediation: o Configure AWS Config rules to automatically remediate IAM policies that do not include tag-based conditions. o Set up remediation actions to adjust policies to adhere to tag-based access control principles automatically. 4. Employee Training: o Provide training to IAM administrators on best practices for crafting IAM policies based on tags. o Ensure that administrators understand the importance of utilizing tag- based conditions for granular access control in EC2. 5. Monitoring and Alerting: o Implement continuous monitoring solutions to detect and alert on any deviations from tag-based access control policies. o Set up alerts to notify administrators of any unauthorized modifications or policy changes that do not adhere to tag-based access control principles. 6. Documentation and Documentation: o Document changes made to IAM policies to include tag-based conditions. o Maintain up-to-date documentation on IAM policies and access controls for reference during audits and compliance assessments. Associated Items
Affected Objects
|
| Ensure an Organizational EC2 Tag Policy has been Created | Medium | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure an Organizational EC2 Tag Policy has been Created Description A tag policy enables you to define tag compliance rules to help you maintain consistency in the tags attached to your organization's resources. Rationale You can use an EC2 tag policy to enforce your tag strategy across all of your EC2 resources. Impact Recommendation and Steps From the Console: You must sign in as an IAM user, assume an IAM role, or sign in as the root user (not recommended) in the organization's management account. To create a tag policy 1. Login to the AWS Organizations using https://console.aws.amazon.com/organizations/ 2. Left hand side Click on Policies 3. Under Support policy types click on Tag policies 4. Under Available policies click on Create policy 5. Enter policy name 6. Enter policy description (Indicate this is the EC2 tag policy) 7. For New tag key 1, specify the name of a tag key to add. 8. For Tag key capitalization compliance select the box for Use the capitalization to enable this option mandating a specific capitalization for the tag key using this policy. 9. For Resource types to enforce check the box for Prevent non-compliant operations for this tag 10. Click on Specify resource types 11. Expand EC2 12. Select ec2:image, ec2:instance, ec2:reserved-instances 13. Click Save changes 14. Click Create policy Associated Items
Affected Objects
More Information TEST ID
|
| Ensure creating EC2 instance with EBS | Medium | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
X TEST NAME Ensure creating EC2 instance with EBS Description EBS are storage volumes that you attach to Amazon EC2 instances. After you attach a volume to an instance, you can use it in the same way you would use a local hard drive attached to a computer, for example to store files or to install applications. Rationale Impact Recommendation and Steps EBS are storage volumes that you attach to Amazon EC2 instances. After you attach a volume to an instance, you can use it in the same way you would use a local hard drive attached to a computer, for example to store files or to install applications. Associated Items
Affected Objects
|
| Ensure Public Access to EBS Snapshots is Disabled | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure Public Access to EBS Snapshots is Disabled Description To protect your data disable the public mode of EBS snapshots. Rationale This protects your data so that it is not accessible to all AWS accounts preventing accidental access and leaks. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure EBS volume snapshots are encrypted | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure EBS volume snapshots are encrypted Description Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. Rationale Encrypting data at rest reduces the likelihood that it is unintentionally exposed and can nullify the impact of disclosure if the encryption remains unbroken. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html
2. https https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/describ
e-snapshots.html
3. https https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/delete-
snapshot.html
4. https https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/copy-
snapshot.html
|
| Ensure unused EBS volumes are removed | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
X TEST NAME Ensure unused EBS volumes are removed Description Identify any unused Elastic Block Store (EBS) volumes in your AWS account and remove them. Rationale Any Elastic Block Store volume created in your AWS account contains data, regardless of being used or not. If you have EBS volumes (other than root volumes) that are unattached to an EC2 instance they should be removed to prevent unauthorized access or data leak to any sensitive data on these volumes Impact Once a EBS volume is deleted, the data will be lost. If this is data that you need to archive, create an encrypted EBS snapshot before deleting them. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure detailed monitoring is enable for production EC2 Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure detailed monitoring is enable for production EC2 Instances Description Ensure that detailed monitoring is enabled for your Amazon EC2 instances. Rationale Monitoring is an important part of maintaining the reliability, availability, and performance of your Amazon EC2 instances Impact Data is available in 1-minute periods. For the instances where you've enabled detailed monitoring, you can also get aggregated data across groups of similar instances. You are charged per metric that is sent to CloudWatch. You are not charged for data storage. Due to this added cost it is recommended that you only enable this on critical instances. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Default EC2 Security groups are not being used | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Default EC2 Security groups are not being used Description When an EC2 instance is launched a specified custom security group should be assigned to the instance. Rationale When an EC2 Instance is launched the default security group is automatically assigned. In error a lot of instances are launched in this way, and if the default security group is configured to allow unrestricted access, it will increase the attack footprint allowing the opportunity for malicious activity. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure the Use of IMDSv2 is Enforced on All Existing Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure the Use of IMDSv2 is Enforced on All Existing Instances Description Ensure the Instance Metadata Service Version 2 (IMDSv2) method is enabled on all running instances. Rationale The IMDSv2 method uses session-based controls to help protect access and control of Amazon Elastic Compute Cloud (Amazon EC2) instance metadata. With IMDSv2, controls can be implemented to restrict changes to instance metadata. Impact Once you enforce IMDSv2, then IMDSv1 no longer works, and applications that use IMDSv1 might not function correctly. Before enforcing IMDSv2, verify that any applications that use Amazon EC2 metadata are upgraded to a version that supports IMDSv2. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
LINK
https:1. https https://aws.amazon.com/premiumsupport/knowledge-center/ssm-ec2-enforce-
imdsv2/
2. https https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-
metadata-service.html
3. https https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-
metadata-options.html
4. https https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/launching-
instance.html#configure_instance_details_step
5. https https://docs.aws.amazon.com/config/latest/developerguide/ec2-imdsv2-
check.html
6. https https://docs.aws.amazon.com/systems-manager-automation-
runbooks/latest/userguide/automation-aws-enforce-ec2-imdsv2.html
|
| Ensure use of AWS Systems Manager to manage EC2 instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure use of AWS Systems Manager to manage EC2 instances Description An inventory and management of Amazon Elastic Compute Cloud (Amazon EC2) instances is made possible with AWS Systems Manager. Rationale Use AWS Systems Manager to provide detailed system configurations, operating system patch levels, services name and type, software installations, application name, publisher and version, and other details about your environment. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure unused ENIs are removed | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure unused ENIs are removed Description Identify and delete any unused Amazon AWS Elastic Network Interfaces in order to adhere to best practices and to avoid reaching the service limit. An AWS Elastic Network Interface (ENI) is pronounced unused when is not attached anymore to an EC2 instance. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure instances stopped for over 90 days are removed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure instances stopped for over 90 days are removed Description Enable this rule to help with the baseline configuration of Amazon Elastic Compute Cloud (Amazon EC2) instances by checking whether Amazon EC2 instances have been stopped for more than the allowed number of days, according to your organization's standards. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination Description This rule ensures that Amazon Elastic Block Store volumes that are attached to Amazon Elastic Compute Cloud (Amazon EC2) instances are marked for deletion when an instance is terminated. If an Amazon EBS volume isn't deleted when the instance that it's attached to is terminated, it may violate the concept of least functionality. Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data Description User Data can be specified when launching an ec2 instance. Examples include specifying parameters for configuring the instance or including a simple script Rationale The user data is not protected by authentication or cryptographic methods. Therefore, sensitive data, such as passwords or long-lived encryption keys should not be stored as user data. Impact Anyone who has access to the instance and configuration can view the user data. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure the creation of a new volume | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure the creation of a new volume Description Leave the root volume unchanged and create a new volume. To ensure the security of the instance and prevent data loss, select no under the delete on termination option and encrypt your volume using AWS KMS. A default key is available for encrypting the volume. Rationale By leaving the root volume unchanged and creating a new volume, you separate critical data from the operating system. Selecting no for the delete on termination option ensures that data on the new volume is not automatically deleted when the instance is terminated, protecting against accidental data loss. Encrypting the volume using AWS KMS adds an additional layer of security, safeguarding the data against unauthorized access. The use of a default key for encryption simplifies the process while maintaining strong security measures. Impact Not following these steps can lead to data loss, security risks, operational disruptions, and prolonged recovery times. Setting delete on termination to no prevents data deletion upon instance termination, while encrypting the volume with AWS KMS protects against unauthorized access. Storing critical data separately from the root volume ensures operational continuity and easier recovery. Recommendation and Steps Associated Items
Affected Objects |
| Ensure creating snapshots of EBS volumes | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure creating snapshots of EBS volumes Description A snapshot is a backup of your EBS volume that captures its state at a specific point in time, storing only the data changes since the last snapshot to optimize storage costs and speed. Snapshots are crucial for data recovery, creating new EBS volumes, and replicating data across AWS regions for disaster recovery and high availability. Restoring from a snapshot allows you to create a new EBS volume and attach it to an EC2 instance in the same availability zone, ensuring data integrity and accessibility. Rationale The rationale behind using EBS snapshots is to ensure efficient and cost-effective data backup and recovery. By capturing only the data changes since the last snapshot, storage costs are minimized and the backup process is expedited. Snapshots are essential for maintaining data integrity, facilitating quick recovery, and enabling seamless data replication across regions, thereby enhancing disaster recovery capabilities and operational resilience. Impact Not utilizing EBS snapshots can lead to significant risks and drawbacks. Without snapshots, data recovery becomes more complex and time-consuming, increasing the risk of prolonged downtime in the event of data loss or system failure. Additionally, the absence of incremental backups can lead to higher storage costs and inefficient use of resources. The lack of data replication across regions can severely compromise disaster recovery efforts, making it challenging to maintain high availability and operational continuity. Overall, failing to use snapshots undermines data integrity, security, and the ability to quickly restore critical information. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Ensure Proper IAM Configuration for EC2 Instances | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Proper IAM Configuration for EC2 Instances Description IAM, or Identity and Access Management, is a vital security service used to control and manage access to AWS resources, ensuring only authorized users and services can interact with them. It allows you to create users and groups, set permissions, enforce multi-factor authentication, and implement least privilege principles to enhance security and compliance. Rationale The rationale behind using IAM is to enhance security by controlling and managing access to AWS resources, ensuring that only authorized users and services can interact with them. This minimizes the risk of unauthorized access and potential security breaches, while also allowing for the implementation of best practices such as multi- factor authentication and least privilege principles, which further strengthen the security and compliance of your AWS environment. Impact Not implementing IAM properly can lead to significant security vulnerabilities, including unauthorized access to AWS resources, data breaches, and potential loss of sensitive information. Without IAM, it is challenging to enforce access controls, monitor user activity, and implement security best practices such as multi-factor authentication and least privilege principles. This can result in increased risk of malicious attacks, operational disruptions, non-compliance with regulatory requirements, and substantial financial damage. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure Secure Password Policy Implementation | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Secure Password Policy Implementation Description Password policies outline the appropriate parameters for password configuration within an organization. Rationale Clear password policies provide essential guidelines for maintaining strong authentication practices, reducing the risk of unauthorized access and data breaches within an organization. By enforcing requirements for complex passwords and regular updates, these policies help bolster cybersecurity defenses and ensure compliance with industry standards and regulations. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Monitoring EC2 and EBS with CloudWatch | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring EC2 and EBS with CloudWatch Description CloudWatch is an AWS monitoring service that allows you to keep an eye on your AWS resources. You can track metrics via log files or worldclass data visuals. AWS CloudWatch allows the administrator to keep an eye on his/her AWS resources. You can set up alarms, monitor activity, and analyze log data. CloudWatch is a must to keep your AWS EBS and EC2 resources secure. Rationale Using CloudWatch to monitor EC2 instances and EBS volumes is essential for enhancing operational oversight and ensuring optimal performance within the AWS environment. This approach provides real-time insights into resource usage and system health, enabling proactive adjustments and timely responses to potential issues, thereby maintaining high availability and efficiency. Impact Failing to monitor EC2 instances and EBS volumes with CloudWatch can lead to delayed detection of performance issues and resource bottlenecks, potentially causing system outages and degraded user experiences. Without this monitoring, organizations also miss opportunities for proactive optimizations, increasing the risk of unexpected downtime and higher operational costs. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure creating an SNS subscription | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
X TEST NAME Ensure creating an SNS subscription Description Create an SNS notification to send to the system administrator's email address. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure creating IAM User | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure creating IAM User Description IAM users are individuals whose accounts have been created by the AWS administrator, providing them access to specific AWS resources. These users have undergone identity verification with your organization, ensuring that only authorized personnel can manage and interact with your AWS environment. Rationale The purpose of creating IAM users and verifying their identities with your organization is to ensure that only authorized individuals have access to AWS resources, enhancing security and preventing unauthorized access. This practice helps maintain control over your AWS environment, ensuring that sensitive data and critical operations are managed by trusted and validated personnel. Impact Not creating IAM users and verifying their identities can lead to unauthorized access to your AWS resources, increasing the risk of security breaches and data leaks. This lack of control can result in compromised sensitive data, unauthorized changes to critical systems, and overall reduced security posture, potentially causing significant operational and financial damage to your organization. Recommendation and Steps 1. Remove Unauthorized Users: o Go to the IAM Dashboard, select Users, and review the list of users. o Identify any unauthorized or unverified users and delete their accounts to prevent unauthorized access. 2. Enable Multi-Factor Authentication (MFA): o For each IAM user, go to the Security credentials tab and enable MFA. o Ensure all users have MFA configured to enhance security and reduce the risk of unauthorized access. 3. Update User Policies: o Review the policies attached to each IAM user. o Modify policies to follow the principle of least privilege, ensuring users have only the permissions necessary for their role. o Remove any overly permissive policies that could lead to security risks. 4. Rotate Access Keys: o For IAM users with long-lived access keys, create new keys and update the applications or services using them. o Delete the old access keys to reduce the risk of compromised credentials. o Encourage regular rotation of access keys as a security best practice. 5. Review and Correct IAM Roles and Groups: o Ensure IAM roles are assigned only to authorized users and that trust relationships are properly configured. o Check group memberships and remove users who should not be part of specific groups. o Update role policies to adhere to the principle of least privilege. 6. Configure AWS IAM Access Analyzer: o Enable IAM Access Analyzer to continuously monitor and analyze access to your IAM resources. o Address any findings related to unauthorized or overly broad access permissions. 7. Implement and Enforce IAM Policies: o Create and enforce organizational IAM policies that require identity verification for all users. o Use AWS Organizations and Service Control Policies (SCPs) to enforce these policies across all accounts within your organization. 8. Enable AWS Config and Create Compliance Rules: o Enable AWS Config to monitor IAM configurations and compliance. o Create AWS Config rules to ensure all users have MFA enabled, policies adhere to least privilege, and access keys are rotated regularly. 9. Conduct Regular Training: o Provide regular security awareness training for all users to emphasize the importance of secure IAM practices. o Educate users on how to properly use IAM features and the significance of identity verification. 10. Schedule Regular Reviews and Audits: o Establish a schedule for regular audits of IAM configurations and access controls. o Document findings and remediation actions taken during each audit. o Continuously improve your IAM practices based on audit results and evolving security threats. Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Elastic Disaster Recovery is Configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Elastic Disaster Recovery is Configured Description AWS Elastic Disaster Recovery is a service that enables you to create and maintain backups of your workloads on AWS, particularly your servers. This service is crucial for ensuring high resilience for your AWS workloads. It operates by establishing and maintaining backups in selected AWS regions, guaranteeing that your data is safe, durable, and highly available in the event of issues in the primary availability zone or region where your AWS server is located. Rationale AWS Elastic Disaster Recovery is crucial for establishing high resiliency in the cloud, synonymous with effective disaster recovery. High resiliency measures your organization's ability to respond to and recover from disasters impacting IT infrastructure. Achieving high resiliency minimizes downtime and long-term costs associated with outages, while low resiliency can result in prolonged downtime, potential data loss, and even permanent infrastructure damage. Impact Recommendation and Steps 1. Update Disaster Recovery Plans: o Action: Log in to the AWS Management Console. o Procedure: ? Navigate to the AWS Elastic Disaster Recovery service. ? Locate and review the current disaster recovery plans. ? Update the plans to ensure they are comprehensive and cover all critical workloads. ? Ensure that the plans specify clear recovery time objectives (RTO) and recovery point objectives (RPO). ? Save and document the updated plans. 2. Correct Backup Configurations: o Action: Verify and adjust backup settings. o Procedure: ? In the AWS Elastic Disaster Recovery dashboard, review the list of protected servers and workloads. ? Enable backups for any critical servers and workloads that are not currently being backed up. ? Adjust the backup schedule and frequency to meet organizational requirements. ? Ensure backups are stored in the correct AWS regions as specified in the disaster recovery plan. 3. Conduct Recovery Procedure Drills: o Action: Test and refine recovery procedures. o Procedure: ? Identify a non-production environment to conduct recovery drills. ? Simulate a disaster scenario to test the recovery procedures. ? Execute the recovery process for each critical workload. ? Measure and document the time taken to recover each workload. ? Compare the measured recovery times against the RTO and RPO. ? Identify and address any issues or delays encountered during the recovery process. ? Update the recovery procedures based on the findings from the drill. 4. Ensure Backup Integrity: o Action: Monitor and verify the integrity of backups. o Procedure: ? Open the AWS CloudWatch console. ? Set up CloudWatch Alarms to monitor the status of backups. ? Configure alerts for any failed or incomplete backups. ? Regularly review CloudWatch logs to verify that backups are successfully completed and stored. ? Resolve any issues identified in the logs, such as incomplete or failed backups. 5. Enhance Backup Storage and Security: o Action: Improve the storage and security of backup data. o Procedure: ? Access the AWS S3 or Glacier console, depending on where backups are stored. ? Ensure all backup data is encrypted in transit and at rest. ? Adjust storage settings to confirm that data is being stored in secure, durable storage solutions. ? Review and update access control policies to ensure only authorized personnel can access backup data. ? Implement any additional security measures necessary to protect the backup data. 6. Ensure Compliance with Policies and Regulations: o Action: Align disaster recovery practices with compliance requirements. o Procedure: ? Review organizational and regulatory compliance requirements relevant to disaster recovery. ? Adjust disaster recovery practices and configurations to ensure compliance with these requirements. ? Document the compliance efforts, including specific steps taken to meet industry standards and regulations. ? Prepare and maintain reports or evidence of compliance for any upcoming audits or assessments. Associated Items
Affected Objects |
| Ensure AWS Disaster Recovery Configuration | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure AWS Disaster Recovery Configuration Description It's important to understand how the network on EDR works. This isn't a simple service to configure, but it works with multiple work loads over the network. You can connect your on-premises or third-party cloud service to AWS EDR over the network. Below are the descriptions of the AWS network architecture: 1. Your local network inside the data center or cloud a.Connect an AWS Replication Agent to each of your resources. 2. AWS Cloud Architecture a. Choose the AWS Region that you want to house your disaster recovery instances. b.Create AWS API Endpoints for EC2, Disaster Recovery, and S3. c.Upon creation of Disaster Recovery endpoints, two subnets will be created in your VPC i.Staging Area Subnets: Replication servers with EBS volumes attached to each disk on the replication servers. ii.Recovery Subnets: Recovery EC2 instances attached to EBS volumes/ d.Connect local network over TCP port 443 to EDR and S3 e.Connect local replication agent to AWS replication servers over TCP port 1500 f.Connectivity out of staging area: Connect staging area on AWS to EDR over TCP port 443 g.Allow connection to S3 over TCP 443 h.Allow connectivity to EC2 over TCP 443 to connect to API Endpoint Rationale Impact Recommendation and Steps It's important to understand how the network on EDR works. This isn't a simple service to configure, but it works with multiple work loads over the network. You can connect your on-premises or third-party cloud service to AWS EDR over the network. Below are the descriptions of the AWS network architecture: 1. Your local network inside the data center or cloud a.Connect an AWS Replication Agent to each of your resources. 2. AWS Cloud Architecture a. Choose the AWS Region that you want to house your disaster recovery instances. b.Create AWS API Endpoints for EC2, Disaster Recovery, and S3. c.Upon creation of Disaster Recovery endpoints, two subnets will be created in your VPC i.Staging Area Subnets: Replication servers with EBS volumes attached to each disk on the replication servers. ii.Recovery Subnets: Recovery EC2 instances attached to EBS volumes/ d.Connect local network over TCP port 443 to EDR and S3 e.Connect local replication agent to AWS replication servers over TCP port 1500 f.Connectivity out of staging area: Connect staging area on AWS to EDR over TCP port 443 g.Allow connection to S3 over TCP 443 h.Allow connectivity to EC2 over TCP 443 to connect to API Endpoint Associated Items
Affected Objects
|
| Ensure functionality of Endpoint Detection and Response (EDR) | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure functionality of Endpoint Detection and Response (EDR) Description Establish and maintain an effective Endpoint Detection and Response (EDR) system to proactively monitor, detect, and respond to security threats on endpoints such as computers, mobile devices, and servers. This involves deploying EDR software that continuously collects data from endpoints, analyzes this data for signs of malicious activity, and provides real-time alerts and detailed incident reports. Regularly test and update the EDR system to ensure it can accurately identify and mitigate advanced threats, including zero-day exploits and sophisticated malware, ensuring comprehensive protection and swift response to potential security incidents. Rationale Ensuring the functionality of Endpoint Detection and Response (EDR) systems is essential for early detection and swift response to security threats on endpoints. These systems continuously monitor and analyze endpoint data, providing real-time alerts and detailed incident reports to identify and mitigate potential threats. Regular testing and updates of the EDR system ensure it remains effective against advanced threats, maintaining comprehensive protection for the organization's assets. Impact Recommendation and Steps Establish and maintain an effective Endpoint Detection and Response (EDR) system to proactively monitor, detect, and respond to security threats on endpoints such as computers, mobile devices, and servers. This involves deploying EDR software that continuously collects data from endpoints, analyzes this data for signs of malicious activity, and provides real-time alerts and detailed incident reports. Regularly test and update the EDR system to ensure it can accurately identify and mitigate advanced threats, including zero-day exploits and sophisticated malware, ensuring comprehensive protection and swift response to potential security incidents. Ensuring the functionality of Endpoint Detection and Response (EDR) systems is essential for early detection and swift response to security threats on endpoints. These systems continuously monitor and analyze endpoint data, providing real-time alerts and detailed incident reports to identify and mitigate potential threats. Regular testing and updates of the EDR system ensure it remains effective against advanced threats, maintaining comprehensive protection for the organization's assets. Associated Items
Affected Objects
|
| Ensure configuration of replication settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure configuration of replication settings Description Set up and maintain the replication settings to ensure accurate and efficient data duplication across systems. Proper configuration includes specifying source and target locations, defining replication schedules, and setting bandwidth limits to optimize performance. Regularly review and update these settings to accommodate changes in data volume and network conditions, ensuring data integrity and availability during replication processes. Rationale Proper configuration of replication settings is essential to ensure data consistency and availability across systems. Accurate replication schedules and bandwidth management optimize performance and prevent network congestion. Regular reviews and updates of these settings help adapt to changes in data volume and network conditions, maintaining efficient and reliable data replication processes. Impact Recommendation and Steps Set up and maintain the replication settings to ensure accurate and efficient data duplication across systems. Proper configuration includes specifying source and target locations, defining replication schedules, and setting bandwidth limits to optimize performance. Regularly review and update these settings to accommodate changes in data volume and network conditions, ensuring data integrity and availability during replication processes. Proper configuration of replication settings is essential to ensure data consistency and availability across systems. Accurate replication schedules and bandwidth management optimize performance and prevent network congestion. Regular reviews and updates of these settings help adapt to changes in data volume and network conditions, maintaining efficient and reliable data replication processes. Associated Items
Affected Objects
|
| Ensure proper configuration of the Launch Settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure proper configuration of the Launch Settings Description Set up and verify the launch settings to ensure systems and applications start correctly and securely. This includes defining startup parameters, specifying required resources, and configuring security settings to prevent unauthorized changes. Regularly review and update these settings to align with best practices and organizational requirements, ensuring optimal performance and security at launch. Rationale Proper configuration of launch settings is crucial for ensuring that systems and applications start securely and perform optimally. Defining startup parameters and resource requirements prevents potential issues and enhances efficiency. Regular reviews and updates to these settings help maintain alignment with best practices and evolving organizational needs, thereby strengthening security and operational reliability from the moment of launch. Impact Recommendation and Steps Set up and verify the launch settings to ensure systems and applications start correctly and securely. This includes defining startup parameters, specifying required resources, and configuring security settings to prevent unauthorized changes. Regularly review and update these settings to align with best practices and organizational requirements, ensuring optimal performance and security at launch. Proper configuration of launch settings is crucial for ensuring that systems and applications start securely and perform optimally. Defining startup parameters and resource requirements prevents potential issues and enhances efficiency. Regular reviews and updates to these settings help maintain alignment with best practices and evolving organizational needs, thereby strengthening security and operational reliability from the moment of launch. Associated Items
Affected Objects
|
| Ensure execution of a recovery drill | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure execution of a recovery drill Description To ensure your organization is prepared for a disaster, it's crucial to verify that your disaster recovery services function as expected. Your IT team should conduct regular recovery drills on your AWS Elastic Recovery Instance to confirm everything operates smoothly and according to plan. Rationale Regular recovery drills are essential to verify the functionality of your disaster recovery services and ensure your organization is well-prepared for any disruptions. By conducting these drills on your AWS Elastic Recovery Instance, you can identify and address potential issues before they impact operations. This proactive approach enhances the reliability and effectiveness of your disaster recovery plan, providing confidence that your systems can recover swiftly and efficiently in the event of a disaster. Impact Recommendation and Steps To ensure your organization is prepared for a disaster, it's crucial to verify that your disaster recovery services function as expected. Your IT team should conduct regular recovery drills on your AWS Elastic Recovery Instance to confirm everything operates smoothly and according to plan. Regular recovery drills are essential to verify the functionality of your disaster recovery services and ensure your organization is well-prepared for any disruptions. By conducting these drills on your AWS Elastic Recovery Instance, you can identify and address potential issues before they impact operations. This proactive approach enhances the reliability and effectiveness of your disaster recovery plan, providing confidence that your systems can recover swiftly and efficiently in the event of a disaster. Associated Items
Affected Objects
More Information TEST ID
|
| Ensure installation of the AWS Replication Agent | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure installation of the AWS Replication Agent Description Set up and verify the installation of the AWS Replication Agent on all relevant systems to facilitate efficient and reliable data replication. This process includes downloading the agent, configuring it according to best practices, and ensuring it is correctly integrated with your AWS environment. Regularly check the agent's performance and update it as needed to maintain optimal functionality and data integrity during replication processes. Rationale Installing the AWS Replication Agent is crucial for enabling efficient and reliable data replication, ensuring that critical data is accurately duplicated across systems. Proper configuration and integration with your AWS environment optimize the agent's performance, enhancing data availability and disaster recovery capabilities. Regular checks and updates of the replication agent help maintain its effectiveness, ensuring data integrity and minimizing the risk of replication failures. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure proper IAM configuration for AWS Elastic Disaster Recovery | Manual Check | NONE | Configure IAM Credentials for AWS Elastic Disaster Recovery. | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure proper IAM configuration for AWS Elastic Disaster Recovery Description Set up and maintain Identity and Access Management (IAM) roles and policies specifically for AWS Elastic Disaster Recovery. This includes defining least-privilege access for users and services, creating roles for automated processes, and enforcing multi-factor authentication (MFA) for added security. Regularly review and update IAM policies to adapt to changes in the organization and to maintain compliance with security best practices, ensuring that only authorized personnel and services can access and manage disaster recovery resources. Rationale Proper IAM configuration for AWS Elastic Disaster Recovery ensures that only authorized users and services have access to critical recovery functions, reducing the risk of unauthorized access and potential security breaches. Implementing least- privilege access and MFA enhances security by limiting permissions and adding an extra layer of authentication. Regular reviews and updates of IAM policies help maintain security compliance and adapt to organizational changes, ensuring continuous protection of disaster recovery resources. Impact Recommendation and Steps Set up and maintain Identity and Access Management (IAM) roles and policies specifically for AWS Elastic Disaster Recovery. This includes defining least-privilege access for users and services, creating roles for automated processes, and enforcing multi-factor authentication (MFA) for added security. Regularly review and update IAM policies to adapt to changes in the organization and to maintain compliance with security best practices, ensuring that only authorized personnel and services can access and manage disaster recovery resources. Proper IAM configuration for AWS Elastic Disaster Recovery ensures that only authorized users and services have access to critical recovery functions, reducing the risk of unauthorized access and potential security breaches. Implementing least- privilege access and MFA enhances security by limiting permissions and adding an extra layer of authentication. Regular reviews and updates of IAM policies help maintain security compliance and adapt to organizational changes, ensuring continuous protection of disaster recovery resources. Associated Items Affected Objects More Information TEST ID
|
| Ensure Continuous Disaster Recovery Operations | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Continuous Disaster Recovery Operations Description Maintain ongoing disaster recovery operations to ensure that systems and data can be swiftly restored in the event of a disruption. This involves regularly updating and testing recovery plans, monitoring replication processes, and verifying the integrity and accessibility of backups. Continuously evaluate and improve disaster recovery strategies to adapt to evolving threats and organizational changes, ensuring resilience and minimal downtime during incidents. Rationale Maintaining continuous disaster recovery operations is essential for ensuring that systems and data can be quickly and effectively restored following a disruption. Regular updates and tests of recovery plans, along with constant monitoring of replication processes, help verify the integrity and availability of backups. This proactive approach allows organizations to adapt to evolving threats and changes, ensuring resilience and minimizing downtime during incidents, which ultimately protects business continuity and reduces potential losses. Impact Recommendation and Steps Maintain ongoing disaster recovery operations to ensure that systems and data can be swiftly restored in the event of a disruption. This involves regularly updating and testing recovery plans, monitoring replication processes, and verifying the integrity and accessibility of backups. Continuously evaluate and improve disaster recovery strategies to adapt to evolving threats and organizational changes, ensuring resilience and minimal downtime during incidents. Maintaining continuous disaster recovery operations is essential for ensuring that systems and data can be quickly and effectively restored following a disruption. Regular updates and tests of recovery plans, along with constant monitoring of replication processes, help verify the integrity and availability of backups. This proactive approach allows organizations to adapt to evolving threats and changes, ensuring resilience and minimizing downtime during incidents, which ultimately protects business continuity and reduces potential losses. Associated Items Affected Objects |
| Ensure execution of a Disaster Recovery Failover | Manual Check | NONE | Implement a disaster recovery failover. | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure execution of a Disaster Recovery Failover Description Execute a comprehensive disaster recovery failover to transition operations from the primary system to a backup system during disruptions. This process includes ensuring all critical data and applications are accurately replicated to the backup site for seamless operational continuity. Regularly test and document the failover process to identify and resolve any issues, maintaining readiness to minimize downtime and data loss during real disasters. Rationale Executing a comprehensive disaster recovery failover is essential to ensure operational continuity during disruptions. Accurate replication of critical data and applications to the backup site guarantees that business operations can continue seamlessly. Regular testing and documentation of the failover process help identify and resolve potential issues, maintaining a state of readiness and minimizing downtime and data loss in actual disaster scenarios. Impact Recommendation and Steps Execute a comprehensive disaster recovery failover to transition operations from the primary system to a backup system during disruptions. This process includes ensuring all critical data and applications are accurately replicated to the backup site for seamless operational continuity. Regularly test and document the failover process to identify and resolve any issues, maintaining readiness to minimize downtime and data loss during real disasters. Executing a comprehensive disaster recovery failover is essential to ensure operational continuity during disruptions. Accurate replication of critical data and applications to the backup site guarantees that business operations can continue seamlessly. Regular testing and documentation of the failover process help identify and resolve potential issues, maintaining a state of readiness and minimizing downtime and data loss in actual disaster scenarios. Associated Items Affected Objects More Information TEST ID
|
| Ensure execution of a failback | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure execution of a failback Description This method involves transitioning operations back from the backup or recovery system to the primary system after the resolution of a disruption or disaster. You can execute a failback either to the original server, ensuring continuity and restoring the previous state, or to a new server, which might be necessary if the original server is compromised or no longer functional. The failback process ensures that all updated data and configurations are transferred back, maintaining the integrity and functionality of the primary system. Rationale A failback is crucial for restoring normal operations after a disaster recovery scenario. Transitioning operations back to the primary system ensures continuity and leverages the original environment's configurations and settings. This process can be directed either to the original server, maintaining the existing infrastructure, or to a new server if the original is compromised. Ensuring all data and configurations are accurately transferred back preserves system integrity and functionality, reducing downtime and allowing the organization to resume normal operations efficiently. Impact Failback Prerequisites: -The volumes on the server you are failing back to are the same size or larger than the recovery instance if failing back to a new server. -The failback client has the proper permissions to access both Elastic Disaster Recovery and S3 services on TCP port 1500 inbound and TCP port 443 outbound to communicate with the failback client. -A public IP is added to the recovery instance. Recommendation and Steps This method involves transitioning operations back from the backup or recovery system to the primary system after the resolution of a disruption or disaster. You can execute a failback either to the original server, ensuring continuity and restoring the previous state, or to a new server, which might be necessary if the original server is compromised or no longer functional. The failback process ensures that all updated data and configurations are transferred back, maintaining the integrity and functionality of the primary system. A failback is crucial for restoring normal operations after a disaster recovery scenario. Transitioning operations back to the primary system ensures continuity and leverages the original environment's configurations and settings. This process can be directed either to the original server, maintaining the existing infrastructure, or to a new server if the original is compromised. Ensuring all data and configurations are accurately transferred back preserves system integrity and functionality, reducing downtime and allowing the organization to resume normal operations efficiently. Associated Items Affected Objects More Information TEST ID
|
| Ensure CloudWatch Metrics for AWS EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure CloudWatch Metrics for AWS EDR Description Set up and monitor AWS CloudWatch metrics for Endpoint Detection and Response (EDR) to track and analyze the performance and security of your AWS environment. This involves configuring CloudWatch to collect detailed logs and metrics on EDR activities, such as threat detections, response actions, and system health. Regularly review these metrics to identify trends, anomalies, and potential security issues, enabling proactive management and timely responses to ensure the effectiveness of your EDR solution. Rationale Implementing AWS CloudWatch metrics for Endpoint Detection and Response (EDR) is essential for maintaining a secure and efficient AWS environment. By collecting detailed logs and metrics on EDR activities, you gain valuable insights into the performance and health of your security measures. Regular review of these metrics allows for the early detection of trends, anomalies, and potential security threats, enabling proactive management and swift responses to maintain the integrity and effectiveness of your EDR solution. This continuous monitoring ensures that your security posture remains robust and adaptive to evolving threats. Impact Recommendation and Steps Set up and monitor AWS CloudWatch metrics for Endpoint Detection and Response (EDR) to track and analyze the performance and security of your AWS environment. This involves configuring CloudWatch to collect detailed logs and metrics on EDR activities, such as threat detections, response actions, and system health. Regularly review these metrics to identify trends, anomalies, and potential security issues, enabling proactive management and timely responses to ensure the effectiveness of your EDR solution. Implementing AWS CloudWatch metrics for Endpoint Detection and Response (EDR) is essential for maintaining a secure and efficient AWS environment. By collecting detailed logs and metrics on EDR activities, you gain valuable insights into the performance and health of your security measures. Regular review of these metrics allows for the early detection of trends, anomalies, and potential security threats, enabling proactive management and swift responses to maintain the integrity and effectiveness of your EDR solution. This continuous monitoring ensures that your security posture remains robust and adaptive to evolving threats. Associated Items Affected Objects More Information TEST ID
|
| Ensure working of EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure working of EDR Description Rationale Impact Recommendation and Steps Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure the Use of Security Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure the Use of Security Groups Description Security groups act as a firewall for associated Amazon RDS DB instances, controllingboth inbound and outbound traffic. Here is a step-by-step guide on how to create anduse Security Groups for an Amazon Aurora instance: Rationale Creating your severity group either inbound or outbound rules. Inbound rules allow anindividual to create a rule that permits the traffic to go to a specific port depending onwhich source it's coming from. Outbound rules enable your instances to connect withone another allow them to connect to the internet. If needed, you can limit the outgoingtraffic. Impact Recommendation and Steps 1. Sign in to AWS Management Console If you do not already have an AWS account, you'll need to create one at https://aws.amazon.com. 2. Navigate to Amazon EC2 Dashboard Once you have logged in to the AWS Management Console, navigate to the EC2 service. You can find this under the Compute category. 3. Create a New Security Group ? In the EC2 Dashboard, find the Network & Security section on the left-side navigation pane, then click Security Groups. ? Click on the Create Security Group button. 4. Configure the New Security Group ? In the Create Security Group panel, give your new security group a name and a description. ? Select the VPC in which your Amazon Aurora instance will be deployed. ? Then click Create. 5. Add Rules to the Security Group After creating the Security Group, you can add inbound and outbound rules. For Inbound Rules: ? Click on the Inbound rules tab, then click Edit inbound rules. Click Add Rule. For the type, select MYSQL/Aurora. For the source, you can specify the IP addresses allowed to access your Amazon Aurora instance. For Outbound Rules: ? Click on the Outbound rules tab, then click Edit outbound rules. Outbound rules allow your instances to communicate with other instances or access the internet. You can restrict outbound traffic if necessary. In most cases, you can leave the default setting, which allows all outbound traffic. 6. Assign the Security Group to Amazon Aurora ? When launching a new Amazon Aurora instance (in the Amazon RDS dashboard), you can select your new security group in the Configure advanced settings step. ? If your Aurora instance has already been launched, you can modify it to use the new security group by selecting the instance. ? Click Modify, and then select the new security group. Associated Items
Affected Objects
|
| Ensure Data at Rest is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Data at Rest is Encrypted_Aurora Description Amazon Aurora allows you to encrypt your databases using keys you manage throughAWS Key Management Service (KMS). Here is a step-by-step guide on how to encryptdata at rest for an Amazon Aurora instance: Rationale Once you are in your AWS account you can either create or modify your existing AuroraDB. A master key would be needed by the authorized user to enable encryption.Enabling encryption would keep the user's data private and stored securely, whichwould only allow them to access it with their key. Impact Unauthorized users will not be able to access the account because a key would beneeded that only authorized users have access to. Recommendation and Steps 1. Sign in to AWS Management Console If you do not already have an AWS account, you'll need to create one at https://aws.amazon.com 2. Navigate to Amazon RDS Dashboard Navigate to the RDS service once logged in to the AWS Management Console. You can find this under the Database category. 3. Create or Modify an Amazon Aurora DB Instance ? If creating a new Aurora DB instance, select Create Database and choose Amazon Aurora as your engine option. ? If you are modifying an existing Aurora DB instance, select the instance from the RDS Dashboard and click Modify. 4. Enable Encryption ? In the Settings or DB Instance Settings section, you will see an option labeled Enable encryption. Check this box to enable encryption for data at rest. ? You will also need to select a master key to use for encryption. You can choose the default AWS managed key for RDS or a custom AWS Key Management Service (KMS) key you have created. Note: ? If you are creating a new DB instance, the Enable encryption option is found under the Settings section. ? If you are modifying an existing DB instance, the Enable encryption option is found under the DB Instance Settings section. However, to encrypt an existing Aurora instance that was not initially created with encryption enabled, you will need to create a snapshot of the instance, make a copy of the snapshot with encryption enabled, and then restore the DB instance from the copied snapshot. 5. Launch the DB Instance ? After you have selected the appropriate encryption settings, click Create database or Continue (if modifying an existing instance). ? Review your settings on the following page, and if everything looks correct, click Launch DB Instance or Modify DB Instance. Associated Items
Affected Objects
|
| Ensure Data in Transit is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Data in Transit is Encrypted_Aurora Description Use SSL (Secure Sockets Layer) to secure data in transit. Aurora supports SSL-encrypted connections between your application and your DB instance. Here is a step-by-step guide on how to encrypt data in transit for an Amazon Aurora instance: Rationale Aurora supports SSL-encrypted application for the individual DB. To secure your data intransit the individual should identify their client application and what is supported bySSL/TLS in order to configure it correctly. Impact If the configuration is not properly implemented the data can be compromised bymalicious actors, they could cause ransomware attack or possibly steal data. Recommendation and Steps 1. Sign in to AWS Management Console If you do not already have an AWS account, you'll need to create one at https://aws.amazon.com. 2. Navigate to Amazon RDS Dashboard ? Navigate to the RDS service once logged in to the AWS Management Console. ? You can find this under the Database category. 3. Create or Modify an Amazon Aurora DB Instance ? If creating a new Aurora DB instance, select Create Database and choose Amazon Aurora as your engine option. ? If you are modifying an existing Aurora DB instance, select the instance from the RDS Dashboard and click Modify. 4. Enable Encryption ? By default, Aurora uses Secure Socket Layer (SSL) or Transport Layer Security (TLS) to encrypt data in transit. However, you must ensure that your client application supports SSL/TLS and is correctly configured to use it. ? For MySQL-compatible Aurora, Amazon provides an SSL certificate that you can download from their documentation. ? PostgreSQL-compatible Aurora uses the default PostgreSQL SSL certificate. Once you have the appropriate certificate, you must configure your client application to use SSL/TLS. For example, in MySQL, you might use a command like this: mysql -h Associated Items
Affected Objects
|
| Ensure IAM Roles and Policies are Created | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure IAM Roles and Policies are Created Description AWS Identity and Access Management (IAM) helps manage access to AWS resources.While you cannot directly associate IAM roles with Amazon Aurora instances, you canuse IAM roles and policies to define which AWS IAM users and groups havemanagement permissions for Amazon RDS resources and what actions they canperform. Here is a guide: Rationale Individual creates IAM roles and polices that define specific permission given to thatrole. This determines what the identity or instance can and cannot do. Impact If an IAM Role is not created, then it would be challenging to access AWS resources. Recommendation and Steps 1. Sign in to AWS Management Console ? If you do not already have an AWS account, you will need to create one at https://aws.amazon.com. 2. Navigate to IAM Dashboard ? Navigate to the IAM service once logged in to the AWS Management Console. ? This is under the Security, Identity, & Compliance category. 3. Create a New IAM Role ? In the IAM Dashboard, find the Roles section on the left-side navigation pane and click on it. Then, click on the Create Role button. 4. Select the Service that will Use the Role ? Choose RDS as the AWS service that will use this new role, then click Next: Permissions. 5. Attach Policy ? In the next screen, you can attach policies defining this role?s permissions. You can use the filter to find existing policies like AmazonRDSFullAccess or AmazonRDSReadOnlyAccess. ? Select the appropriate policy and then click Next: Tags. 6. Add Tags (Optional) ? You can add metadata to the role by attaching tags as key-value pairs. This is optional, and you can proceed to the next step if you do not wish to add tags. 7. Review ? Provide a name and a description for the role. Review the role and then click Create Role. 8. Creating IAM Policy (Optional) ? You can create a custom IAM policy if the predefined policies do not meet your requirements. ? Navigate to Policies in the IAM dashboard and click Create Policy. ? Use the visual editor or JSON editor to define the permissions. ? Once done, click Review Policy, give it a name and a description, and click Create Policy. ? You can then attach this custom policy to the IAM role. 9. Assign the IAM Role to an IAM User or Group To assign the newly created role to an IAM User or Group. ? Navigate to the user or group in the IAM dashboard. ? Click Add permissions. ? Then Attach existing policies directly. ? Use the filter to find your new role and select it. ? Click Next: Review and then Add permissions Associated Items
Affected Objects
|
| Ensure Database Audit Logging is Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Database Audit Logging is Enabled Description Amazon Aurora provides advanced auditing capabilities through AWS CloudTrail andAmazon RDS Database Activity Streams. Here is a step-by-step guide on how toenable and use these features: Rationale Allows individuals to access and retrieve their old logs, log their new events, and storetheir log. Impact Recommendation and Steps Below are the instructions for enabling logging through AWS CloudTrail: 1. Sign in to AWS Management Console ? If you do not already have an AWS account, you will need to create one at https://aws.amazon.com. 2. Navigate to CloudTrail Dashboard ? Navigate to the CloudTrail service. ? You can find this under the Management & Governance category. 3. Create a new trail ? In the CloudTrail Dashboard, click on Create trail. ? Provide a name for the trail, and specify the S3 bucket where you want the logs to be stored. 4. Configure trail settings ? Choose the settings that meet your requirements. For instance, you can log events for all regions, or you can log management events, data events, or both. 5. Create the trail ? After specifying the trail settings, click Create. Below are the instructions for enabling logging through Amazon Database Activity Streams: 1. Navigate to Amazon RDS Dashboard ? In the AWS Management Console, navigate to the RDS service. ? You can find this under the Database category. 2. Choose your Aurora DB instance ? In the RDS Dashboard, click on Databases, and then click on the name of your Aurora DB instance. 3. Enable Database Activity Streams ? In the Connectivity & Security tab, find the Database Activity Streams section. Click Create stream. ? In the Create Stream panel, choose the settings that meet your requirements and click Create. Note: Enabling Database Activity Streams can impact the performance of your DB instance, so you should test this feature in a non-production environment before enabling it in production. 4. View the Database Activity Stream ? You can view the Database Activity Stream using Amazon Kinesis Data Streams. ? In the Kinesis Data Streams dashboard, click on the stream?s name and then click View data. Associated Items
Affected Objects
|
| Ensure Automatic Backups and Retention Policies are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Automatic Backups and Retention Policies are configured Description Backups help protect your data from accidental loss or database failure. With AmazonAurora, you can turn on automatic backups and specify a retention period. The backupsinclude a daily snapshot of the entire DB instance and transaction logs. Rationale The individual logs into their account and chooses their database once selected theycan modify the backup settings. To have the database being backed up automaticallythe individual is encouraged to select from 1 to 35 days. This ensures that the file isbeing saved automatically and can prevent it from accidental loss. This ensures that theindividual can restore their files quickly in the event of a data loss. Impact It would result in having the files protected and being able to retrieve those files in theevent of an accidental loss. Recommendation and Steps 1. Sign in to AWS Management Console ? If you do not already have an AWS account, you will need to create one at https://aws.amazon.com. 2. Navigate to Amazon RDS Dashboard ? Navigate to the RDS service once logged in to the AWS Management Console. ? You can find this under the Database category. 3. Choose your Aurora DB instance ? In the RDS Dashboard, click on Databases. ? Then click on the name of your Aurora DB instance. 4. Check or modify the backup settings ? In the Details section, find the Backup section. Here, you can see if automatic backups are enabled (the Backup retention period is more than 0 days) and when the backup window is. To modify these settings, click Modify. o In the Backup section of the Modify DB instance screen, you can change the Backup retention period and the Backup window. o The retention period can be between 1 and 35 days. To disable automatic backups, set the retention period to 0 days. 5. Apply the changes ? Scroll to the bottom and choose when to apply the changes. You can apply them immediately or schedule them for the next maintenance window. ? Then, click Continue and Modify DB Instance. Associated Items
Affected Objects
|
| Ensure Multi-Factor Authentication (MFA) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Multi-Factor Authentication (MFA) is in use Description MFA adds an extra layer of protection to your AWS resources. MFA can be used tosecure AWS Management Console and CLI access which indirectly affects Aurora andother AWS services. Rationale Multi-Factor Authentication (MFA) requires an individual to select a second step ofverification process to access the platform. The individual has a choice of eitherselecting a virtual MFA device or a hardware MFA device to complete the process. MFAmust also be used when performing specific actions to modify their database. Impact The user is required to complete the second step which is the multi-factor authenticationbefore any access is granted to them. Recommendation and Steps 1. Sign in to AWS Management Console ? If you do not already have an AWS account, you will need to create one at https://aws.amazon.com. 2. Navigate to IAM Dashboard ? Navigate to the IAM service once logged in to the AWS Management Console. ? You can find this under the Security, Identity, & Compliance category. 3. Select the User ? In the IAM Dashboard, click on Users. ? Click on the name of the user for whom you want to enable MFA. 4. Manage MFA Device ? In the User details page, click the Security credentials tab. ? In the Multi-factor authentication (MFA) section. ? Click on Manage. 5. Choose MFA Device Type ? You can choose a virtual MFA device (such as an app on a smartphone) or a hardware MFA device. ? Choose the device type that suits your requirements. 6. Follow the MFA Device Setup Wizard ? The setup wizard will guide you through setting up your MFA device. ? This will typically involve scanning a QR code or entering a serial number in your MFA device and then entering two consecutive MFA codes from your device. 7. Enable MFA Protected API Access ? By writing an IAM policy, you can enforce MFA authentication for AWS CLI or SDK operations. This policy specifies that MFA must be used to perform specific actions, such as calling the Amazon RDS APIs to modify a DB instance. Associated Items
Affected Objects
|
| Ensure Amazon VPC (Virtual Private Cloud) has been created | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Amazon VPC (Virtual Private Cloud) has been created Description Amazon VPCs allow you to launch AWS resources into a defined virtual network,providing network isolation and controlling inbound and outbound traffic. Here's a step-by-step guide on how to create an Amazon Virtual Private Cloud (VPC): Rationale Impact User would be required to have an AWS account to access AWS resources. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Ensure Passwords are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Passwords are Regularly Rotated Description Regularly rotating your Aurora passwords is critical to access management, contributingto maintaining system security. The database password can be rotated in AmazonAurora, but the access keys refer to the rotation of AWS IAM User access keys. Rationale Updating your password is critical to access AWS resources. This also ensures thatyour account is being kept safe from a potential threat. Impact Having the passwords updated frequently allows only the authorized individual toaccess the AWS resources. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Access Keys are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Access Keys are Regularly Rotated Description Regularly rotating your Aurora Access Keys is critical to access management,contributing to maintaining system security. Rationale Rotating AWS IAM user access keys ensures security and any potential risk of thebusiness that may be compromised due to the active key since it changes quite often. Impact Only authorized personnel would need to login with their key, which restrictsunauthorized users access to the database. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Least Privilege Access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Least Privilege Access Description Use the principle of least privilege when granting access to your Amazon Auroraresources. This principle of least privilege (POLP) is a computer security concept whereusers are given the minimum access levels necessary to complete their job functions.In Amazon Aurora, this can be implemented at various levels, including AWS IAM formanaging AWS resources and within the database for managing database users androles.Here is a step-by-step guide for each: Rationale POLP limits the user interaction on the database, and it only gives the databasepermission to complete the necessary or mandatory task. AWS IAM gives permissionfor what the entity can and cannot do. Incorporating both POLP and AWS IAM in adatabase gives limited permission to the user to complete the tasks. Impact Users would need to create a IAM role to implement POLP into their database. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Enable Amazon Aurora Backtrack | High | Status: Not Configured | N/A | N/A | SP v1.0 | NO |
X TEST NAME Enable Amazon Aurora Backtrack Description Rationale Impact Recommendation and Steps Ensure that the Backtrack feature is enabled for your Amazon Aurora (with MySQL compatibility) database clusters in order to backtrack your clusters to a specific time, without using backups. Backtrack is an Amazon RDS feature that allows you to specify the amount of time that an Aurora MySQL database cluster needs to retain change records, in order to have a fast way to recover from user errors, such as dropping the wrong table or deleting the wrong row by moving your MySQL database to a prior point in time without the need to restore from a recent backup. Associated Items
Affected Objects
|
| Enable event notifications for RDS | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Enable event notifications for RDS Description Rationale Impact Recommendation and Steps Ensure that your Amazon RDS resources have event notifications enabled in order to get notifications when an event occurs for a given database instance, database snapshot, database security group, or database parameter group. The Amazon RDS service groups these events into categories that you can subscribe to, so that you can be notified via Amazon SNS when an event in that category occurs. For example, if you subscribe to the Backup category for a given database instance, you will be notified whenever a backup-related event occurs for the specified instance. Associated Items
Affected Objects
|
| Enable Event Subscriptions for DB Security Groups Events | High | Status: Not Configured | N/A | N/A | SP v1.0 | NO |
X TEST NAME Enable Event Subscriptions for DB Security Groups Events Description Rationale Impact Recommendation and Steps
01 Sign in to the AWS Management Console.
02 Navigate to Amazon RDS console at https://console.aws.amazon.com/rds/.
03 In the navigation panel, under Amazon RDS, choose Event subscriptions.
04 Choose Create event subscription to initiate the subscription setup process.
05 On the Create event subscription setup page, perform the following actions:
Provide a unique name for the event subscription in the Name box.
In the Target section, perform one of the following commands:
Select New email topic for Send notifications to, to create and configure a new Amazon SNS topic. If you choose this option, you must provide a unique name for your new SNS topic in the Topic name box and specify the email address(es) to send the notifications to, in the With these recipients configuration box.
Select ARN for Send notifications to, to choose an existing Amazon SNS topic. Select the Amazon Resource Name (ARN) of the existing SNS topic from the ARN dropdown list.
In the Source section, perform the following commands:
Select Security groups from the Source Type dropdown list. This is the type of the RDS resource which this subscription will consume events from.
For Security groups to include, choose All security groups to include all your database security groups in the event subscription.
For Event categories to include, choose All event categories to include all supported events.
Choose Create to create your new Amazon RDS event subscription.
06 Repeat steps no. 4 and 5 to create event subscriptions for other database security groups available within the current AWS region.
07 Change the AWS cloud region from the navigation bar and repeat the Remediation process for other regions.
Associated Items
Affected Objects
|
| Ensure that encryption-at-rest is enabled for RDS Instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that encryption-at-rest is enabled for RDS Instances Description Amazon RDS encrypted DB instances use the industry standard AES-256 encryptionalgorithm to encrypt your data on the server that hosts your Amazon RDS DB instances.After your data is encrypted, Amazon RDS handles authentication of access anddecryption of your data transparently with a minimal impact on performance. Rationale Databases are likely to hold sensitive and critical data, it is highly recommended toimplement encryption in order to protect your data from unauthorized access ordisclosure. With RDS encryption enabled, the data stored on the instance's underlyingstorage, the automated backups, read replicas, and snapshots, are all encrypted. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.Encryption.html2. https https://aws.amazon.com/blogs/database/selecting-the-right-encryption-options-for-amazon-rds-and-amazon-aurora-database-engines/# https:~ https:text=With%20RDS%2Dencrypted%20resources%2C%20data,transparent%20to%20your%20database%20engine.3. https https://aws.amazon.com/rds/features/security/
|
| Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances Description Ensure that RDS database instances have the Auto Minor Version Upgrade flagenabled in order to receive automatically minor engine upgrades during the specifiedmaintenance window. So, RDS instances can get the new features, bug fixes, andsecurity patches for their database engines. Rationale AWS RDS will occasionally deprecate minor engine versions and provide new ones foran upgrade. When the last version number within the release is replaced, the versionchanged is considered minor. With Auto Minor Version Upgrade feature enabled, theversion upgrades will occur automatically during the specified maintenance window soyour RDS instances can get the new features, bug fixes, and security patches for theirdatabase engines. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that public access is not given to RDS Instance | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
X TEST NAME Ensure that public access is not given to RDS Instance Description Ensure and verify that RDS database instances provisioned in your AWS account dorestrict unauthorized access in order to minimize security risks. To restrict access to anypublicly accessible RDS database instance, you must disable the database PubliclyAccessible flag and update the VPC security group associated with the instance. Rationale Ensure that no public-facing RDS database instances are provisioned in your AWSaccount and restrict unauthorized access in order to minimize security risks. When theRDS instance allows unrestricted access (0.0.0.0/0), everyone and everything on theInternet can establish a connection to your database and this can increase theopportunity for malicious activities such as brute force attacks, PostgreSQL injections,or DoS/DDoS attacks. Impact Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https:1. https https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.html2. https https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Scenario2.html3. https https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_VPC.WorkingWithRDSInstanceinaVPC.html4. https https://aws.amazon.com/rds/faqs/
|
| Ensure to Choose the Appropriate Database Engine | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Choose the Appropriate Database Engine Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Create The Appropriate Deployment Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Create The Appropriate Deployment Configuration Description This control is important and helps businesses to choose from two deployment options,either single or multi-AZ deployment. Depending on the business factor and theirsecurity needs the organization is then encouraged to make a decision that wouldbenefit them. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Create a Virtual Private Cloud (VPC) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Create a Virtual Private Cloud (VPC) Description Setting up a Virtual Private Cloud (VPC) protects the private network that has beenestablished from any external networks from interfering. It allows internal networks tocommunicate with one another with the network that has been established. Rationale Impact Builds a strong connection between internal networks and the internet, and it securesyour data from getting into the hand of an unauthorized party. Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Configure Security Groups | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Configure Security Groups Description Configuring security groups benefits the user because it helps manage networks withinthe database and gives only certain permission for traffic that leaves and enters the database. Rationale Impact Allows certain users to access the instance and it only allows them to work within thatnetwork. Recommendation and Steps Associated Items
Affected Objects |
| Enable Encryption at Rest | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Enable Encryption at Rest Description This helps ensure that the data is kept secure and protected when at rest. The usermust choose from two key options which then determine when the data is encrypted atrest. Rationale Impact If an unauthorized user steals the data, it would be unreadable for them because a keywould be required to decrypt the message into plaintext Recommendation and Steps Associated Items
Affected Objects
|
| Enable Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Enable Encryption in Transit Description Amazon Relational Database uses SSL/TLS to encrypt data during transit. To secureyour data in transit the individual should identify their client application and what issupported by SSL/TLS to configure it correctly. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Implement Access Control and Authentication_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Access Control and Authentication_RDS Description Users should select whether they like to enable authentication. If they want toauthenticate a password would be required, which would only allow the authorizedperson to access the database. Defining access control allows specific workers in abusiness access to the database. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Regularly Patch Systems | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Regularly Patch Systems Description Rationale Impact Helps the organization reduce their security risk by regularly updating and patching theirdatabase and database engine. Regularly updating and scanning for any weaknessesin the company can bring up possible vulnerabilities that could have led to potentialcyber-attack. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Monitoring and Logging is Enabled_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring and Logging is Enabled_RDS Description Rationale Impact If the individual is not monitoring and logging their activity it allows the attacker to attackthe system and extract or destroy data. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Enable Backup and Recovery_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Enable Backup and Recovery_RDS Description The individual logs into their AWS account and chooses their Amazon relationaldatabase that they want to backup. To have the database being backed upautomatically the individual is encouraged to enable backup. This ensures that the file isbeing saved automatically and can prevent it from accidental loss. This ensures that theindividual can restore their files quickly in the event of a data loss. Rationale Impact It would result in having the files protected and being able to retrieve those files in theevent of an accidental loss. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Regularly Review Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Regularly Review Security Configuration Description This helps by reviewing the database factors from database engine, review instance details, security networks, encryption settings, audit logging, and authentication. By updating or removing a few things from these lists it helps tighten security and ensures that the users do not have excessive permissions. Rationale Impact Updating the system and being updated with security configurations keeps everythingsecure and prevents it from an attack. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure no Underutilized RDS Instances | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure no Underutilized RDS Instances Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Amazon RDS Public Snapshots | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Amazon RDS Public Snapshots Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that Amazon Aurora clusters are configured to use database activity streams | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that Amazon Aurora clusters are configured to use database activity streams Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that all database instances within an Amazon Aurora cluster have the same accessibility | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that all database instances within an Amazon Aurora cluster have the same accessibility Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Enable AWS RDS Cluster Deletion Protection | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Enable AWS RDS Cluster Deletion Protection Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure you always use the latest generation of DB instances to get better performance with lower cost | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure you always use the latest generation of DB instances to get better performance with lower cost Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Identify overutilized RDS instances and upgrade them in order to optimize database workload and response time | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Identify overutilized RDS instances and upgrade them in order to optimize database workload and response time Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Enable AWS RDS Performance Insights | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Enable AWS RDS Performance Insights Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure automated backups are enabled for RDS instances | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure automated backups are enabled for RDS instances Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Enable RDS Copy Tags to Snapshots | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Enable RDS Copy Tags to Snapshots Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Amazon RDS database instances are not using the default ports | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Amazon RDS database instances are not using the default ports Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure fewer Amazon RDS instances than the established limit in your AWS account Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure RDS instances are encrypted with CMKs to have full control over encrypting and decrypting data | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure RDS instances are encrypted with CMKs to have full control over encrypting and decrypting data Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure encryption is setup for RDS instances to fulfill compliance requirements for data-at-rest encryption | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure encryption is setup for RDS instances to fulfill compliance requirements for data-at-rest encryption Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure RDS instances are using General Purpose SSD storage | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure RDS instances are using General Purpose SSD storage Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure fewer Amazon RDS instances than the established limit in your AWS account Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that no AWS RDS database instances are provisioned inside VPC public subnets | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that no AWS RDS database instances are provisioned inside VPC public subnets Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure AWS RDS instances are using secure and unique master usernames for their databases | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure AWS RDS instances are using secure and unique master usernames for their databases Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure RDS instances are launched into Multi-AZ | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure RDS instances are launched into Multi-AZ Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure RDS instances are not public facing to minimise security risks | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure RDS instances are not public facing to minimise security risks Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Amazon RDS Reserved Instances (RI) are renewed before expiration | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Amazon RDS Reserved Instances (RI) are renewed before expiration Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure AWS RDS Reserved Instance purchases have not failed | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure AWS RDS Reserved Instance purchases have not failed Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Amazon RDS Reserved Instance purchases are not pending | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Amazon RDS Reserved Instance purchases are not pending Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure RDS instances have sufficient backup retention period for compliance purposes | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure RDS instances have sufficient backup retention period for compliance purposes Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure there are not any unrestricted DB security groups assigned to your RDS instances | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure there are not any unrestricted DB security groups assigned to your RDS instances Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that Amazon Backup service is used to manage AWS RDS database snapshots | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that Amazon Backup service is used to manage AWS RDS database snapshots Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure AWS Identity and Access Management (IAM) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure AWS Identity and Access Management (IAM) is in use Description AWS Identity and Access Management (IAM) lets you securely control your users'access to AWS services and resources. To manage access control for AmazonDynamoDB, you can create IAM policies that control access to tables and data. Rationale IAM policies help you control and maintain access to Amazon DynamoDB as needed. Impact Recommendation and Steps 1. Open IAM Console ? Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/. 2. Navigate to Policies ? In the IAM console, in the navigation pane, choose Policies. 3. Create Policy ? Choose Create policy. ? You will be taken to the Create policy page. 4. Choose Service ? Click on Choose a service. ? Type DynamoDB in the search box and select it. 5. Configure Actions ? Under the Actions section, select the actions you want to allow the user to perform. ? For instance, you can select Read to allow read actions like GetItem, Scan, Query, etc. 6. Set Resources ? Under the Resources section, you can specify which tables this policy applies to. ? You can choose All resources or specify the ARN (Amazon Resource Name) of specific tables. 7. Review Policy ? Click on Review policy. ? Give your policy a name and description. ? Then click Create policy. ? Now, you have an IAM policy. 8. Attach Policy ? Navigate to the Users, Groups, or Roles section in the IAM console. ? Choose an existing user, group, or role, or create a new one. ? Once you've selected a user, group, or role, click Add permissions. ? Choose Attach existing policies directly. ? Search for your created policy, select it, and click Attach policy. ? With these steps, you have attached an IAM policy that controls access to DynamoDB resources. Associated Items
Affected Objects
|
| Ensure DynamoDB Encryption at Rest | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure DynamoDB Encryption at Rest Description Encryption at rest in Amazon DynamoDB enhances the security of your data byencrypting it using AWS Key Management Service (AWS KMS) keys. Here is how toenable encryption at rest while creating a DynamoDB table. Rationale Once the user is in their AWS account, they should open the DynamoDB to create thetable and enable encryption. A key would be required to be created to enableencryption. Only the authorized user would always have access to this key. Enablingencryption would keep the user's data private and stored securely, which would onlyallow them to access it with their key. Impact Add an additional layer of security by preventing any unauthorized personnel fromaccessing the data since both IAM access to the data and access to the encryption keywould be required. Recommendation and Steps 1. Open DynamoDB Console ? Sign in to the AWS Management Console and open the DynamoDB console at https://console.aws.amazon.com/dynamodb/. 2. Create DynamoDB Table ? Click Create table. This will bring you to the Create DynamoDB table page. 3. Specify Table Details ? Enter a Table name and Primary key. ? The primary key consists of a partition key and, optionally, a sort key. ? Fill in these details according to your requirements. 4. Enable Encryption ? Under the Settings section, check the Enable encryption at rest. ? By default, DynamoDB uses an AWS-owned CMK to encrypt your data. ? To use an AWS-managed CMK or a customer-managed CMK instead, select AWS-managed CMK or Customer-managed CMK from the dropdown menu, then choose the desired CMK. 5. Create a Table ? Click Create. ? This will create your DynamoDB table with encryption at rest enabled. Note: 1. The setting for encryption at rest applies to all DynamoDB data associated with the table, including primary key data and indexes. 2. If you need to apply encryption at rest to an existing table, you can modify the table settings. However, modifying settings on large tables could take time and impact performance during the transition. 3. Ensure you have the necessary permissions in AWS KMS when choosing an AWS-managed CMK or a customer-managed CMK. Associated Items
Affected Objects
|
| Ensure VPC Endpoints are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure VPC Endpoints are configured Description Using VPC endpoints with Amazon DynamoDB allows you to securely accessDynamoDB resources within your Amazon Virtual Private Cloud (VPC). This keeps yourtraffic off the public internet. Rationale Using VPC endpoint in the DynamoDB helps ensure that the data is secured and thatno external networks would have access to the network. It is a private network wherethe user has access to their desired availability zones and subnets. Impact Recommendation and Steps 1. Open Amazon VPC Console ? Sign in to the AWS Management Console and open the Amazon VPC console at https://console.aws.amazon.com/vpc/. 2. Create a VPC Endpoint ? In the Amazon VPC console, navigate to the Endpoints section in the left-side menu. ? Click Create Endpoint. ? Select your desired VPC in the VPC dropdown menu. ? In the Service category section, choose AWS services. ? In the Filter Services search box, enter DynamoDB and select DynamoDB from the results. ? Choose your desired availability zone(s) and subnet(s). ? Leave the default settings for other options or customize them according to your requirements. ? Click Create endpoint. 3. Update Route Tables ? In the Amazon VPC console, navigate to the Route Tables section in the left-side menu. ? Find the route table associated with your VPC or subnet from which you want to access DynamoDB. 1. Edit the route table and add a route for the DynamoDB VPC endpoint. Destination: Enter the CIDR block of the DynamoDB VPC endpoint, typically in the form of vpce-xxxxxx-xxxxxxx-xxxxxxx- xxxxxxx.vpce.amazonaws.com/32. o Target: Select the VPC endpoint ID from the dropdown menu. 2. Save the changes to update the route table. 3. Verify Connectivity To ensure that your VPC endpoint for DynamoDB is functioning correctly: ? Launch an Amazon EC2 instance within your VPC or use an existing one. ? Connect to the EC2 instance using SSH or other remote access methods. ? From the EC2 instance, try to access DynamoDB using the SDK or CLI. ? Ensure that the access to DynamoDB is successful and that data can be retrieved or modified. Associated Items
Affected Objects
|
| Ensure DynamoDB Streams and AWS Lambda for Automated Compliance Checking is Enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure DynamoDB Streams and AWS Lambda for Automated Compliance Checking is Enabled Description Enabling DynamoDB Streams and integrating AWS Lambda allows you to automatecompliance checking and perform actions based on changes made to your DynamoDBdata. Rationale Enabling the DynamoDB with AWS Lambda allows the individual to either use anexisting or create a new execution role that allows Lambda to access DynamoDB andwrite logs. Impact Recommendation and Steps 1. Open DynamoDB Console ? Sign in to the AWS Management Console and open the DynamoDB console at https://console.aws.amazon.com/dynamodb/. 2. Create or Select a DynamoDB Table ? You can create a new DynamoDB table or select an existing one to enable DynamoDB Streams. 3. Enable DynamoDB Streams ? In the DynamoDB console, select your table. ? Click on the Overview tab. ? Under the DynamoDB Streams section, click on Manage stream. ? In the Manage stream dialog, choose Enable and select the desired view type (e.g., New and old images). ? Click Enable. 4. Create an AWS Lambda Function ? Open the AWS Management Console and navigate to the Lambda service at https://console.aws.amazon.com/lambda/. ? Click Create function to create a new Lambda function. ? Choose a function name, runtime (e.g., Node.js, Python), and other basic settings. Page 84 ? Under Permissions, choose an existing or create a new execution role that allows Lambda to access DynamoDB and write logs. ? Click Create function to create the Lambda function. 5. Configure AWS Lambda with DynamoDB Stream ? Scroll down to the Designer section in the Lambda function editor. ? Click on Add trigger. ? Select DynamoDB from the trigger list. ? In the Configure triggers dialog, choose the DynamoDB table and the stream that you enabled in the previous step. ? Define the batch size and starting position, if applicable. ? Click Add. 6. Write Lambda Function Code for Compliance Checking ? In the Lambda function editor, scroll up to the code editor section. ? Write your compliance-checking logic in the selected runtime language (e.g., Node.js, Python). ? The code should handle the incoming DynamoDB stream records and perform the necessary compliance checks. ? If needed, you can use the AWS SDKs or other libraries to interact with DynamoDB or other AWS services. 7. Configure Lambda Function Settings ? Scroll down to the Function overview section. ? Configure the memory, timeout, and other settings as per your requirements. ? Click Save to save the Lambda function. 8. Test the Compliance Checking ? You can test the compliance checking by changing the DynamoDB table and observing the Lambda function's behavior through the CloudWatch logs or other desired actions performed by the function. Associated Items
Affected Objects
|
| Ensure Monitor and Audit Activity is enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Monitor and Audit Activity is enabled Description Regular monitoring and auditing of activity in Amazon DynamoDB help ensure yourdatabase's security, performance, and compliance. Rationale This keeps track and ensures who has recently modified a document and monitors allactivity within the database. This information allows the individual to use the detailsprovided for auditing purposes and to address any compliance requirements. Impact Recommendation and Steps 1. Enable CloudTrail Logging for DynamoDB ? Sign in to the AWS Management Console and open the CloudTrail console at https://console.aws.amazon.com/cloudtrail/. ? Choose Trails from the left-side menu. ? Click Create trail or select an existing trail. ? Specify a trail name, choose an S3 bucket for storing logs, and configure other trail settings. ? Under Data events, select the checkbox for DynamoDB to enable logging of DynamoDB data events. ? Click Create trail or Save changes to save the CloudTrail configuration. 2. Enable DynamoDB Streams ? Sign in to the AWS Management Console and open the DynamoDB console at https://console.aws.amazon.com/dynamodb/. ? Select the DynamoDB table you want to monitor. ? Click on the Overview tab. ? Under the DynamoDB Streams section, click Manage stream. ? Enable DynamoDB Streams with the desired view type (e.g., New and old images). ? Click Enable. 3. Configure Amazon CloudWatch Alarms ? Sign in to the AWS Management Console and open the CloudWatch console at https://console.aws.amazon.com/cloudwatch/. ? In the left-side menu, click on Alarms. ? Click Create alarm. ? Select a DynamoDB metric to monitor (e.g., Read or Write capacity units). ? Configure the threshold, conditions, and actions for the alarm. ? Choose the actions to take when the alarm state is triggered (e.g., send notifications, auto-scaling actions, etc.). ? Click Create alarm to save the configuration. 4. Analyze and Review Logs and Metrics ? Sign in to the AWS Management Console and open the CloudWatch console at https://console.aws.amazon.com/cloudwatch/. ? In the left-side menu, click Logs to access CloudWatch Logs. ? Select the appropriate log group for DynamoDB (e.g., /aws/dynamodb/TableName). ? Review the logs to monitor activities, errors, and any unusual behavior. ? Navigate to the CloudWatch console and click Metrics in the left-side menu. ? Select the DynamoDB namespace and the desired metrics (e.g., ConsumedReadCapacityUnits, ConsumedWriteCapacityUnits). ? Analyze the metrics to identify trends, capacity needs, and potential issues. 5. Enable AWS Config for DynamoDB ? Sign in to the AWS Management Console and open the AWS Config console at https://console.aws.amazon.com/config/. ? Click on Rules in the left-side menu. ? Click Add rule. ? Configure a rule for DynamoDB compliance checks, such as checking for unencrypted tables or insecure IAM policies. ? Customize the rule settings and scope based on your requirements. ? Click Save to create the AWS Config rule. Associated Items
Affected Objects
|
| Ensure Fine-Grained Access Control is implemented | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Fine-Grained Access Control is implemented Description Fine-Grained Access Control (FGAC) on Amazon DynamoDB allows you to controlaccess to data at the row level. Using IAM policies, you can restrict access based onthe content within the request. Here is how you can implement FGAC: Rationale Fine-Grained access control helps users to create and allow specific permission withinthat DB. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure DynamoDB Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure DynamoDB Encryption in Transit Description Use the SSL/TLS protocol to encrypt data in transit between your applications andDynamoDB. Amazon DynamoDB encrypts data in transit by default using TransportLayer Security (TLS) encryption. Here is a step-by-step guide on how to ensureencryption in transit for your DynamoDB: Rationale Amazon DynamoDB uses TLS to encrypt data during transit. To secure your data intransit the individual should identify their client application and what is supported by TLSto configure it correctly. Impact If the user does not have the code configured correctly it would not be able to connectto the DynamoDB. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Secure Access to ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Secure Access to ElastiCache Description Securing access to Amazon ElastiCache involves implementing appropriateauthentication and authorization mechanisms. Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Network Security is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Security is Enabled_ElastiCache Description Implementing network security for Amazon ElastiCache involves configuring your VirtualPrivate Cloud (VPC), security groups, and network access controls to control access toyour ElastiCache clusters. Rationale This helps ensure that the data is safe and protected from any threats and ormisconfigurations within the network. This helps to keep a potential hacker getting intothe system and compromising the data. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Encryption at Rest and in Transit is configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Encryption at Rest and in Transit is configured Description Enabling encryption at rest and in transit for Amazon ElastiCache helps protect yourdata when it is stored and transmitted. Rationale Enabling encryption at rest secured the users data where it is stored. Enablingencryption in transit helps that the data is protected when it is moving from one locationto another. Impact If the user did not enable encryption and rest and during transit, there is a possibility of the data being vulnerable to a ransomware attack. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Automatic Updates and Patching are Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Automatic Updates and Patching are Enabled Description Enabling automatic updates and patching for Amazon ElastiCache ensures that yourElastiCache clusters run the latest software versions with important security fixes andenhancements. Rationale Automatic updates help the software be updated and address any vulnerabilities withinthe software that can help business with any potential exists that can impact thebusiness and prevent any unauthorized access. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Virtual Private Cloud (VPC) is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Virtual Private Cloud (VPC) is Enabled Description Implementing VPC security best practices for Amazon ElastiCache involves configuringyour Virtual Private Cloud (VPC) and associated resources to enhance the security ofyour ElastiCache clusters. Rationale This ensures that only authorized users can access their platforms and prevents anymistakes that can lead to a data breach due to the level of security. Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Monitoring and Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring and Logging is Enabled_ElastiCache Description Implementing monitoring and logging for Amazon ElastiCache allows you to gainvisibility into the performance, health, and behavior of your ElastiCache clusters. Rationale This helps the individual know what is being logged within the activity and determine what next step they should take to address any suspicious activity. Impact If the individual is not monitoring and logging their activity it allows the attacker to attackthe system and extract or destroy data. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Security Configurations are Reviewed Regularly_ElastiCache Description Regularly updating and reviewing the security configuration of your AmazonElastiCache clusters helps ensure that your clusters are protected against potentialvulnerabilities and aligned with your security requirements. Rationale This ensures that the clusters are being regularly updated and protected from anypotential vulnerabilities as well as meeting the security requirements. Impact Updating the system and being updated with security configurations keeps everythingsecure and prevents it from an attack. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Authentication and Access Control is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Authentication and Access Control is Enabled_ElastiCache Description Individual creates IAM roles that would give specific permission to what the user canand cannot do within that database. The Access Control List (ACLs) allows only specificindividuals to access the resources. Rationale Impact Use specific client's applications or tools that allow the authorized personnel to connectto the database. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Audit Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Audit Logging is Enabled_ElastiCache Description To manage your enterprise caching solution, it is important that you know how yourclusters are performing and the resources they are consuming. It is also important thatyou know the events that are being generated and the costs of your deployment.Amazon CloudWatch provides metrics for monitoring your cache performance. Inaddition, cost allocation tags help you monitor and manage costs. Rationale Impact Reduce the risk of any fraud or inconsistency within the database because onlyauthorized user has access to it. Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Security Configurations are Reviewed Regularly_ElastiCache Description Regularly updating and reviewing the security configuration of your AmazonElastiCache clusters helps ensure that your clusters are protected against potentialvulnerabilities and aligned with your security requirements. Rationale This ensures that the clusters are being regularly updated and protected from anypotential vulnerabilities as well as meeting the security requirements. Impact Updating the system and being updated with security configurations keeps everythingsecure and prevents it from an attack. Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Network Security is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Security is Enabled_MemoryDB for Redis Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Data at Rest and in Transit is Encrypted_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data at Rest and in Transit is Encrypted_MemoryDB for Redis Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Authentication and Access Control is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Authentication and Access Control is Enabled_MemoryDB for Redis Description Rationale Users should select whether they like to enable authentication. If they want toauthenticate a password would be required, which would only allow the authorizedperson to access the cluster. Defining access control allows specific workers in abusiness access to the database. Impact Allowing authentication verifies the identity of the person and who has appropriate access to a company's data. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Audit Logging is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Audit Logging is Enabled_MemoryDB for Redis Description Enabling audit logging on Amazon MemoryDB allows you to capture and store logs ofactivities performed on your clusters. Rationale It captures and saves logs of activities that took place in the cluster. Impact Reduces risks of any fraud since worker activity is being monitored and tracked. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Security Configurations are Reviewed Regularly_MemoryDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Security Configurations are Reviewed Regularly_MemoryDB Description This helps by removing or updating any IAM roles, security networks, encryptionsettings, audit logging, and authentication. By updating or removing a few things fromthese lists it helps tighten security and ensures that the users do not have excessivepermissions. Rationale Impact By regularly checking these settings in the database the user is preventing the databasefrom a cyber threat. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Monitoring and Alerting is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring and Alerting is Enabled_MemoryDB for Redis Description Implementing monitoring and alerting on Amazon MemoryDB allows you to proactivelydetect and respond to any performance issues, security events, or operationalanomalies. Rationale This helps in ensuring that everything in the system is secure and if there is an unusualactivity that takes place it addresses the issues quickly and efficiently. Impact Enabling monitoring and alerting has a positive impact in the business operations whenthe issue is identified and addressed accordingly. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Network Architecture Planning | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Architecture Planning Description Plan the network architecture to isolate your DocumentDB instances within a secureVirtual Private Cloud (VPC). Configure appropriate security groups and network accesscontrol lists (ACLs) to control inbound and outbound traffic to your DocumentDBinstances. Rationale Depending on how the network is established between devices, which then helpssecure data when transferring it from one server to another. Impact The way the users design their network sets the performance for the system and how itwould interact with servers. Recommendation and Steps Associated Items
Affected Objects |
| Ensure VPC Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure VPC Security is Configured Description Creating a VPC, configuring subnets, and creating security groups help isolate yourDocumentDB instances within your virtual network and control inbound and outboundtraffic. Rationale Setting up a Virtual Private Cloud (VPC) protects the private network that has beenestablished from any external networks from interfering. It allows internal networks tocommunicate with one another with the network that has been established. Impact Builds a strong connection between internal networks, has a strong connection with theinternet, and it secures your data from getting into the hands of an unauthorized party. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Encryption at Rest is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Encryption at Rest is Enabled Description Rationale This helps ensure that the data is kept secure and protected when at rest. The usermust choose from two key options which then determine when the data is encrypted atrest. Impact If an unauthorized user steals the data, it would be unreadable for them because a keywould be required to decrypt the message into plaintext. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Encryption in Transit is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Encryption in Transit is Enabled Description Rationale Amazon Database DB uses SSL/TLS to encrypt data during transit. To secure your datain transit the individual should identify their client application and what is supported byTLS to configure it correctly. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Implement Access Control and Authentication_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Access Control and Authentication_DocumentDB Description Configure authentication mechanisms for your DocumentDB instances, such as usingAWS Identity and Access Management (IAM) users or database users. Defineappropriate user roles and permissions to control access to the DocumentDB instancesand databases. Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Audit Logging is Enabled_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Audit Logging is Enabled_DocumentDB Description Enable audit logging to capture database activities, including login attempts, queries,and modifications. Send the logs to Amazon CloudWatch or a centralized logmanagement system for analysis and monitoring. Rationale It captures and saves logs of activities that took place in the cluster, by recording loginattempts, queries, and any changes within the database. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Regular Updates and Patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Regular Updates and Patches Description Stay informed about the latest security updates and patches released by Amazon forDocumentDB. Regularly apply updates and patches to your DocumentDB instances toprotect against known vulnerabilities. Rationale Impact Helps the organization reduce their security risk by regularly updating and patching theirdatabase and database engine. Regularly updating and scanning for any weaknessesin the company can bring up vulnerabilities that could have led to potential cyber-attack. Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Implement Monitoring and Alerting | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Monitoring and Alerting Description This helps by alerting the system if any unusual event has occurred or if a particularthreshold has been achieved because the user is able to set a desired interval or thecluster. This then allows system administrators to swiftly correct the situation and avoidsubsequent complications if something unusual is happening. Rationale Impact Has a positive impact in the business operations when the issue is identified andaddressed accordingly. Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Implement Backup and Disaster Recovery | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Backup and Disaster Recovery Description Set up automated backups for your DocumentDB instances to ensure data durabilityand recoverability. Consider implementing a disaster recovery plan that includes datareplication across different availability zones or regions. Rationale Having the data backed up ensures that all the crucial information is stored securely itdefends against any human errors and system errors that resulted in data loss. Anorganization that has a disaster recovery plan is prepared for any disruption that wouldimpact business operations. Impact If a business does not have a backup and recovery plan it would have a negative impacton the business, which would result in less productivity, data loss that cannot berestored, and loss of revenue. Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Configure Backup Window | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Configure Backup Window Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Conduct Security Assessments | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Conduct Security Assessments Description Periodically perform security assessments, including vulnerability assessments andpenetration testing, to identify and address any security weaknesses. Review yoursecurity configuration against best practices and industry standards. Rationale This helps ensure that any vulnerabilities that might lie dormant be addressed promptly,which would reduce the risk of a malicious attack. Reviewing and making sure thesecurity policies are authentic ensures the safety of the organization data. Impact Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Keyspace Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Keyspace Security is Configured Description To access Amazon Keyspaces, the user would be required to log in with their AWScredentials. Once logged in the user can access the AWS resources and can explorethe resources that Amazon Keyspaces offers. Amazon Keyspaces offers a lot ofsecurity that can mitigate a potential attack. Rationale Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Network Security is Enabled_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Security is Enabled_Keyspaces Description In order to access Amazon Keyspaces the user is required to set specific networkingparameters and security measurements without these extra steps they will not be ableto access it. Users are required to create or select a virtual private cloud (VPC) anddefine their inbound and outbound rules accordingly. Rationale Impact Only authorized users have access to the database which limits and controls any risk ofan attack. This ensures better performance of the system to a private network andbetter security. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Data at Rest and in Transit is Encrypted_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data at Rest and in Transit is Encrypted_Keyspaces Description Once a user is logged in to their AWS account and has access to their AmazonKeyspaces they are encouraged to choose from the following two options to encrypttheir data. Depending on which key they select for encryption at rest would store thedata according to their preference. For encryption in transit the user is also encouragedto choose from two options depending on if the data needs to be encrypted duringtransit. Rationale Impact Prevents any unauthorized user from accessing the database and provides securitywhen transferring the data from one location to another. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Data at Rest is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Data at Rest is Encrypted_Neptune Description This helps ensure that the data is kept secure and protected when at rest. The usermust choose from two key options which then determine when the data is encrypted atrest. Rationale Impact If an unauthorized user steals the data, it would be unreadable for them because a keywould be required to decrypt the message into plaintext Recommendation and Steps 1. Sign into the AWS Management Console ? Sign into the AWS Management Console at https://console.aws.amazon.com/ with your AWS account credentials. 2. Open the Amazon Neptune Console ? Navigate to the service using the Find Services search bar or by directly accessing the console at https://console.aws.amazon.com/neptune/. 3. Select the Neptune Cluster ? Choose the Amazon Neptune cluster for which you want to enable encryption at rest. ? Click on the cluster name to access its details page. 4. Enable Encryption at Rest ? In the cluster details page, navigate to the Configuration or Encryption at Rest section. ? Under Encryption at Rest, click on Modify. ? In the Encryption at Rest dialog box, select the encryption option you prefer: o AWS managed key (default): Choose this option to use the default AWS managed key for encryption. o Customer-managed key (CMK): Choose this option if you want to use your own AWS Key Management Service (KMS) customer-managed key for encryption. Select the appropriate CMK from the dropdown menu. Click Apply Changes to enable encryption at rest for the Neptune cluster. 5. Verify Encryption Status ? Wait a few minutes for the changes and configuration to take effect. ? Refresh the cluster details page to see the updated encryption status. ? Verify that encryption at rest is enabled for the Neptune cluster. Associated Items
Affected Objects
|
| Ensure Data in Transit is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Data in Transit is Encrypted_Neptune Description Enabling encryption in transit helps that the data is protected when it is moving from onelocation to another. Rationale Impact If an unauthorized user steals the data, it would be unreadable for them because a keywould be required to decrypt the message into plaintext. Recommendation and Steps 1. Sign into the AWS Management Console ? Sign into the AWS Management Console at https://console.aws.amazon.com/ with your AWS account credentials. 2. Open the Amazon Neptune Console ? Navigate to the service using the Find Services search bar or by directly accessing the console at https://console.aws.amazon.com/neptune/. 3. Select the Neptune Cluster ? Choose the Amazon Neptune cluster for which you want to implement encryption in transit. ? Click on the cluster name to access its details page. 4. Enable SSL/TLS Encryption ? In the cluster details page, navigate to the Configuration or Encryption in Transit section. ? Under Encryption in Transit, ensure that the Enable option is selected. ? Optionally, you can also select the Enforce option to require SSL/TLS encryption for all client connections to the Neptune cluster. ? Click Apply Changes to enable SSL/TLS encryption for the Neptune cluster. 5. Update Client Applications ? When connecting to the Neptune cluster, update your client applications to establish an SSL/TLS-encrypted connection. ? Consult your client drivers or libraries documentation or configuration settings to enable SSL/TLS encryption. ? Configure the necessary SSL/TLS settings, such as specifying the SSL/TLS certificate to use. 6. Verify Encryption in Transit ? Test the connection to the Neptune cluster from your client application. ? Ensure that the connection is established using SSL/TLS encryption. ? Verify that all data transmitted between your client applications and the Neptune cluster is encrypted in transit. Associated Items
Affected Objects
|
| Ensure Monitoring and Alerting is Enabled_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
X TEST NAME Ensure Monitoring and Alerting is Enabled_Neptune Description Rationale Impact Recommendation and Steps 1. Sign in to the AWS Management Console ? Sign in to the AWS Management Console at https://console.aws.amazon.com/ with your AWS account credentials. 2. Open the Amazon Neptune Console ? Navigate to the service using the Find Services search bar or by directly accessing the console at https://console.aws.amazon.com/neptune/. 3. Select the Neptune Cluster ? Choose the Amazon Neptune cluster on which you want to implement monitoring and alerting. ? Click on the cluster name to access its details page. 4. Set Up Amazon CloudWatch Metrics ? In the cluster details page, navigate to the Monitoring or Metrics section. ? Enable CloudWatch metrics for the Neptune cluster by clicking Enable or Configure. ? Select the desired metrics to monitor, such as CPU utilization, storage usage, or network throughput. ? Choose the appropriate granularity and sampling intervals for the metrics. ? Click Save or Apply Changes to enable CloudWatch metrics for the Neptune cluster. 5. Configure CloudWatch Alarms ? In the CloudWatch console, navigate to Alarms in the left-side menu. ? Click Create alarm to configure alarms based on specific metric thresholds. ? Select the desired metric to monitor and set the threshold values for triggering an alarm. ? Define the actions to be taken when the alarm state changes, such as sending notifications or triggering automated actions. ? Configure the alarm settings, including alarm name, description, and notification recipients. ? Click Create alarm to save the alarm configuration. 6. Set Up Amazon EventBridge Rules ? In the Amazon EventBridge console, navigate to Rules in the left-side menu. ? Click on Create rule to set up rules for specific events or log entries related to Neptune. ? Define the event pattern or log filter to match the desired events. ? Configure the target actions to be taken when the rule matches an event, such as sending notifications or invoking AWS Lambda functions. ? Specify the rule settings, including rule name, description, and event source. ? Click Create to save the rule configuration. 7. Review and Customize Metrics and Alarms ? Periodically review the metrics and alarms configured for your Neptune cluster. ? Adjust the metric thresholds and alarm settings based on your performance and alerting requirements. ? Consider adding more metrics or alarms as needed to monitor additional aspects of your Neptune environment. 8. Regularly Monitor and Respond to Alerts ? Continuously monitor the CloudWatch metrics and alarm states for your Neptune cluster. ? Respond promptly to any alarms triggered by critical or abnormal conditions. ? Investigate the root causes of the alerts and take appropriate actions to mitigate issues. 9. Utilize Additional Monitoring Tools ? Explore and leverage additional monitoring and observability tools available in the AWS ecosystem, such as Amazon CloudWatch Logs Insights, AWS X-Ray, or third-party monitoring solutions. ? Configure these tools to gather insights and detect any performance or security issues in your Neptune environment. Associated Items
Affected Objects
|
| Ensure Network Security is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Security is Enabled_Neptune Description This helps ensure that all the necessary security measurements are taken to prevent acyber-attack. Such as utilizing VPC, creating certain inbound and outbound rules, andACLs. Rationale Impact Provides privacy and lets the user customize their security preferences. Preventsprivate network from interfering with public networks. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Authentication and Access Control is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Authentication and Access Control is Enabled_Neptune Description This helps ensure that there are specific IAM roles and policies that are given thenecessary information within a Neptune DB cluster to operate as needed. Rationale Impact Allowing authentication verifies the identity of the person and who has appropriateaccess to a company's data. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Audit Logging is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Audit Logging is Enabled_Neptune Description This control is important because it helps ensure activity within the cluster and identifieswho has last modified the document and who has access to it, in case of breaches. Italso ensures compliance with regulation requirements. Rationale Impact Reduces risks of any fraud since worker activity is being monitored and tracked. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Security Configurations are Reviewed Regularly_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Security Configurations are Reviewed Regularly_Neptune Description This helps by removing or updating any IAM roles, security networks, encryptionsettings, audit logging, and authentication. By updating or removing a few things fromthese lists it helps tighten security and ensures that the users do not have excessivepermissions. Rationale Impact By updating and revising the control within our Amazon Neptune cluster it would keepthe system as secure as possible. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Data Ingestion is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data Ingestion is Secure Description Rationale This helps ensure that the system is updated with any potential vulnerabilities that mightpose a threat to the organization. Helps authenticate the sources that are coming to the database and ensures that only authorized users have the credential to access thedata. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Data at Rest is Encrypted_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data at Rest is Encrypted_Timestream Description Enable encryption at rest for Amazon Timestream to protect your data while it is stored.Utilize AWS Key Management Service (KMS) to manage and control the encryptionkeys used for data encryption. Configure Timestream to encrypt your data using AWS-managed keys or customer-managed keys. Rationale This helps ensure that the data is kept secure and protected when at rest. The usermust choose from two key options which then determine when the data is encrypted atrest. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure Encryption in Transit is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Encryption in Transit is Configured Description Configure your applications or tools to use secure communication protocols wheninteracting with Amazon Timestream. Utilize endpoints to establish private and secureconnections to Timestream. Rationale The database uses HTTPS/TLS to encrypt data during transit. To secure your data intransit the individual should identify their client application and what is supported byHTTPS/TLS in order to configure it correctly. Also has an option for leverage, whichcreates a private connection between virtual private code (VPC) without interfering withpublic networks. Impact If the client does not have the code configured correctly it would not be able to connectto the server. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Access Control and Authentication is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Access Control and Authentication is Enabled Description Utilize AWS Identity and Access Management (IAM) to control access to your Amazon Timestream resources. Define IAM policies that grant or deny permissions for specificTimestream actions and resources. Rationale Users should select whether they like to enable authentication. If they want toauthenticate the user would be required to implement IAM roles would grant or denypermissions within that database. Users also have an option to enable multi-factorauthentication, which adds an extra layer of security restricting access to unauthorizedusers. Impact Allowing authentication verifies the identity of the person and who has appropriateaccess to a company's data. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Fine-Grained Access Control is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Fine-Grained Access Control is Enabled Description Leverage Timestream's fine-grained access control capabilities to control table or row level access. Define access policies that limit access to specific tables, columns, or rows based on user roles or conditions. Implement data filtering and row-level security to restrict access to sensitive information. Rationale This helps by having specific permissions which can be denied due to multiple conditions of the database. This allows the user to control certain aspects of the database. Impact This adds an extra layer for users to sign into with their credentials to the database. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Audit Logging is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Audit Logging is Enabled_Timestream Description Enable AWS CloudTrail to capture and log API calls and activities related to Amazon Timestream. Configure CloudTrail to store the logs in a secure location and regularly review the logs for any unauthorized or suspicious activities. Rationale This captures and saves logs of activities that took place in the database. Impact This reduces risks of any fraud since worker activity is being monitored and tracked. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Regular Updates and Patches are Installed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Regular Updates and Patches are Installed Description Stay updated with the latest security patches and updates provided by AWS for Amazon Timestream. Follow AWS security best practices and recommendations to ensure your Timestream implementation remains secure. Rationale Impact This helps the organization reduce their security risk by regularly updating and patching their database and database engine. Regularly updating and scanning for any weaknesses in the company can bring up possible vulnerabilities that could have led topotential cyber-attack. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Monitoring and Alerting is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring and Alerting is Enabled_Timestream Description Utilize Amazon CloudWatch to monitor key metrics, events, and logs related to Amazon Timestream. Set up appropriate alarms and notifications to detect security incidents or abnormal behavior proactively. Rationale This helps the individual know what is being logged within the activity and determinewhat the next step should be if they spot any anomalies. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Review and Update the Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Review and Update the Security Configuration Description Conduct regular security reviews and assessments of your Amazon Timestream implementation. Evaluate access permissions, encryption settings, and security controls to ensure they align with your organization's security requirements. Rationale By regularly reviewing security configuration it helps the businesses to detect any threat they might be hindering and address the threat in a timely manner. Impact This helps by reviewing the database factors from database engine, review instancedetails, security networks, encryption settings, audit logging, and authentication. Byupdating or removing a few things from these lists it helps tighten security and ensuresthat the users do not have excessive permissions. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure to Implement Identity and Access Management (IAM) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Identity and Access Management (IAM) Description This control is important because by having IAM roles implemented in the database itonly allows certain people who are authenticated into the database to modify the database and would not give access to unauthorized personnel. This ensures that thedata is being protected from any threat actor. Rationale Impact Only authorized personnel can access the database and configure the applications byusing their IAM credentials. If the user credentials are compromised by an unauthorizeduser, it would limit them to access specific areas within the database due to theleverage IAM roles established. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Network Access is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Network Access is Secure Description By applying certain network access such as Virtual Private Cloud (VPC) it protects theprivate network that has been established from any external networks from interfering. Itallows internal networks to communicate with one another with the network that hasbeen established. The Access Control List (ACLs) allows only specific individuals toaccess the resources. Also, by monitoring and logging the activity within the database ithelps the individual know what is being logged within the activity and determine whatnext step they should take to address it. Rationale Impact Setting these certain rules in your network provides a strong security and prevents theorganization suffering a ransomware attack. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Data at Rest is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data at Rest is Encrypted_OLDB Description This helps ensure that the data is kept secure and protected when at rest. The usermust choose from two key options which then determine when the data is encrypted atrest. Rationale Impact If an unauthorized user steals the data, it would be unreadable for them because a keywould be required to decrypt the message into plaintext. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Data in Transit is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Data in Transit is Encrypted_OLDB Description Use Transport Layer Security (TLS) to encrypt communications between clients andyour QLDB instance. QLDB provides TLS support by default, allowing securecommunication over the network. Configure your client applications to use TLS whenconnecting to QLDB. Rationale Amazon Quantum Ledger Database (QLDB), uses TLS to encrypt data during transit.To secure your data in transit the individual should identify their client application andwhat is supported by TLS in order to configure it correctly. Impact If the user does not have the code configured correctly it would not be able to connectto the server. Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Implement Access Control and Authentication_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Implement Access Control and Authentication_QLDB Description Utilize QLDB's built-in authentication and access control mechanisms. Define IAMpolicies to control which users or roles can perform specific actions on QLDB resources.Leverage IAM roles for cross-service access, securely integrating QLDB with otherAWS services. Rationale Users should select whether they like to enable authentication. If they want toauthenticate the user would be required to implement IAM roles would grant or denypermissions within that database. Impact Allowing authentication verifies the identity of the person and who has appropriateaccess to a company's data. Recommendation and Steps Associated Items
Affected Objects |
| Ensure Monitoring and Logging is Enabled_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure Monitoring and Logging is Enabled_QLDB Description Enable QLDB's built-in logging to capture important system events and databaseactivity. Monitor the logs for any suspicious activities or errors. Leverage AmazonCloudWatch to collect and analyze logs, set up alarms, and receive notifications forpotential security incidents. Rationale This helps the individual know what is being logged within the activity and determinewhat next step they should take to address it. Impact Recommendation and Steps Associated Items
Affected Objects |
| Ensure to Enable Backup and Recovery_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
X TEST NAME Ensure to Enable Backup and Recovery_QLDB Description Having the data backed up ensures that all the crucial information is stored securely itdefends against any human errors and system errors that resulted in data loss. Anorganization that has a disaster recovery plan is prepared for any disruption that wouldimpact business operations. Rationale Impact If a business does not have a backup and recovery plan it would have a negative impacton the business, which would result in less productivity, suffer data loss that cannot berestored, and loss of revenue. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure Amazon SNS topics do not allow unknown cross account access | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Amazon SNS topics do not allow unknown cross account access Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure SNS topics do not allow Everyone to publish | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure SNS topics do not allow Everyone to publish Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure SNS topics do not allow Everyone to subscribe | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure SNS topics do not allow Everyone to subscribe Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Enable Server-Side Encryption for AWS SNS Topics | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Enable Server-Side Encryption for AWS SNS Topics Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that Amazon SNS topics are encrypted with KMS Customer Master Keys | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that Amazon SNS topics are encrypted with KMS Customer Master Keys Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure SNS topics are not exposed to everyone | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure SNS topics are not exposed to everyone Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure CloudFormation service is in use for defining your cloud architectures on Amazon Web Services | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure CloudFormation service is in use for defining your cloud architectures on Amazon Web Services Description Rationale Impact Recommendation and Steps Ensure that Amazon CloudFormation is used within your AWS account to automate your cloud infrastructure management and deployment. CloudFormation is the AWS service that promotes the concept of Infrastructure as Code (IaC), which practically means writing code using a descriptive language (JSON or YAML) to manage configurations and automate provisioning of AWS infrastructures in addition to deployments
This rule can help you with the following compliance standards:
APRA
MAS
Associated Items
Affected Objects
|
| Ensure a deletion policy is used for your Amazon CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure a deletion policy is used for your Amazon CloudFormation stacks Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that Amazon CloudFormation stacks have not been drifted | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that Amazon CloudFormation stacks have not been drifted Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFormation stack policies are set to prevent accidental updates to stack resources | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFormation stack policies are set to prevent accidental updates to stack resources Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFormation stacks are integrated with SNS to receive notifications about stack events | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFormation stacks are integrated with SNS to receive notifications about stack events Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Termination Protection feature is enabled for your AWS CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Termination Protection feature is enabled for your AWS CloudFormation stacks Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure IAM role with CloudFormation Use least privilege | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure IAM role with CloudFormation Use least privilege Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure AWS CloudFormation stacks are not in Failed mode for more than 6 hours | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure AWS CloudFormation stacks are not in Failed mode for more than 6 hours Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure CloudFront global content delivery network (CDN) service is in use | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure CloudFront global content delivery network (CDN) service is in use Description Rationale Impact Recommendation and Steps Ensure that the Amazon CloudFront Content Delivery Network (CDN) service is used within your AWS account to secure and accelerate the delivery of your web content, media files, or static resources (e.g., CSS files, Javascript files, image files) handled by your websites/web applications. Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are configured to use a custom SSL-TLS certificate | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure that CloudFront distributions are configured to use a custom SSL-TLS certificate Description Rationale Impact Recommendation and Steps 01 Sign in to the AWS Management Console. 02 Navigate to Amazon CloudFront console at https://console.aws.amazon.com/cloudfront/v3/. 03 In the left navigation panel, under CloudFront, choose Distributions. 04 Click on the ID (link) of the Amazon CloudFront distribution that you want to configure. 05 Select the General tab to access the general settings available for the selected distribution. 06 Choose Edit from the Settings section to modify the distribution configuration. 07 Ensure that your custom domain name is added to the Alternate domain name (CNAME) - optional list. 08 Select the custom SSL/TLS certificate that you want to use for your custom domain name from the Custom SSL certificate ? optional dropdown list. You can also choose Request certificate to request or import a custom SSL/TLS certificate from Amazon Certificate Manager (ACM). 09 For Security policy, choose the latest (recommended) TLS security group provided by Amazon CloudFront. 10 Choose Save changes to apply the configuration changes. 11 Repeat steps no. 4 ? 10 for each Amazon CloudFront distribution available in your AWS cloud account. Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are configured to use Server Name Indication (SNI) | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure that CloudFront distributions are configured to use Server Name Indication (SNI) Description Rationale Impact Recommendation and Steps 01 Sign in to the AWS Management Console. 02 Navigate to Amazon CloudFront console at https://console.aws.amazon.com/cloudfront/v3/. 03 In the left navigation panel, under CloudFront, choose Distributions. 04 Click on the ID (link) of the Amazon CloudFront distribution that you want to configure. 05 Select the General tab to access the general settings available for the selected distribution. 06 Choose Edit from the Settings section to modify the distribution configuration. 07 Ensure that a custom SSL/TLS certificate is selected from the Custom SSL certificate ? optional dropdown list. 08 Deselect the Enabled checkbox, available under Legacy clients support - $600/month prorated charge applies. Most customers do not need this. to disable allocating dedicated IP addresses and enable Server Name Indication (SNI). 09 Choose Save changes to apply the configuration changes. 10 Repeat steps no. 4 ? 9 for each Amazon CloudFront distribution available in your AWS cloud account. Associated Items
Affected Objects
|
| Ensure CloudFront distributions are configured to automatically compress content | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFront distributions are configured to automatically compress content Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure Geo Restriction is enabled for CloudFront CDN distributions | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Geo Restriction is enabled for CloudFront CDN distributions Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFront origins dont use insecure SSL protocols | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFront origins dont use insecure SSL protocols Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFront is integrated with WAF to protect web applications from exploit attempts | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFront is integrated with WAF to protect web applications from exploit attempts Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFront logging is enabled | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFront logging is enabled Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure AWS CloudFront distributions are using improved security policies for HTTPS connections | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure AWS CloudFront distributions are using improved security policies for HTTPS connections Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure traffic between a CloudFront distribution and the origin is encrypted | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure traffic between a CloudFront distribution and the origin is encrypted Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure CloudFront Viewer Protocol Policy enforces encryption | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure CloudFront Viewer Protocol Policy enforces encryption Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are configured to use a default root object | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that CloudFront distributions are configured to use a default root object Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are using an origin access control configuration for their origin S3 buckets | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that CloudFront distributions are using an origin access control configuration for their origin S3 buckets Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are using the Origin Failover feature to maintain high availability | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that CloudFront distributions are using the Origin Failover feature to maintain high availability Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that Amazon CloudFront distributions are using the Origin Shield feature | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that Amazon CloudFront distributions are using the Origin Shield feature Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that CloudFront distributions are using the Real-Time Logging feature | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that CloudFront distributions are using the Real-Time Logging feature Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Enable Field-Level Encryption for CloudFront Distributions | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Enable Field-Level Encryption for CloudFront Distributions Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure that CloudFront distributions do not point to non-existent S3 origins | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure that CloudFront distributions do not point to non-existent S3 origins Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| Ensure to Use Amazon CloudFront Content Distribution Network for secure web content delivery | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure to Use Amazon CloudFront Content Distribution Network for secure web content delivery Description Rationale Impact Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure AWS WAF is in use to protect your web applications from common web exploits | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure AWS WAF is in use to protect your web applications from common web exploits Description Rationale Impact Recommendation and Steps Ensure that Amazon Web Application Firewall (WAF) service is currently in use in order to protect your AWS-powered web applications from security exploits that could affect their availability and overall security, or consume excessive resources (resource starvation attacks). Amazon WAF is a web application firewall service that lets you monitor any HTTP(S) requests that are forwarded to AWS CloudFront or AWS ELB. To enable AWS WAF protection you simply create web Access Control Lists (ACLs), define the ACLs rules, which reference one or more conditions, and the actions to take when each rule is satisfied. Then the newly created WAF ACLs can be attached, for example, to the Amazon CloudFront CDN distribution used by your web applications. To quickly get started with AWS WAF you can also use AWS Pre-configured Protections, an automated solution that consists of a pre-configured AWS WAF template that includes a set of predefined ACL rules, which can be customized to best fit your requirements, designed to block common web-based attacks such as bad bots, Cross-Site Scripting and SQL Injection. Associated Items
Affected Objects
|
| Ensure that logging is enabled for Amazon WAF Web Access Control Lists | High | Status:Not Configured correctly | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure that logging is enabled for Amazon WAF Web Access Control Lists Description Rationale Impact Recommendation and Steps 01 Sign in to the AWS Management Console.
02 Before you can enable logging for your Web ACLs, you need to create a delivery stream in Amazon Kinesis Firehose whose name starts with aws-waf-logs-. To get started, navigate to Amazon Kinesis Firehose console at https://console.aws.amazon.com/kinesis/.
03 In the navigation panel, choose Data Firehose, and select Create delivery stream.
04 On the Kinesis Data Firehose - Create delivery stream setup page, perform the following actions:
Enter a unique name for your new delivery stream that starts with aws-waf-logs- and choose Direct PUT or other sources for the Source.
For Destination, choose Amazon S3 and select the name of the destination bucket from the S3 bucket dropdown list.
Configure the rest of the available options based on your application requirements, then choose Create delivery stream to create your new Amazon Kinesis Firehose delivery stream.
05 Navigate to Amazon WAF console at https://console.aws.amazon.com/wafv2/.
06 In the left navigation panel, under AWS WAF section, choose Web ACLs.
07 Click on the name of the Web ACL that you want to reconfigure, available in the Name column.
08 Select the Logging and metrics tab and choose Enable logging within the Logging section.
09 On the Enable logging configuration page, perform the following actions:
Under Amazon Kinesis Data Firehose Delivery Stream, choose Select a delivery stream, and choose the delivery stream created at the previous steps.
(Optional) Under Redacted fields, select the data fields that you want to hide from the logs.
Choose Enable logging to apply the changes. This will enable logging for the selected Amazon WAF Web Access Control List (Web ACL). When you enable logging, Amazon WAF creates a service linked role with the necessary permissions to write logs to the Amazon Kinesis Data Firehose delivery stream.
10 Repeat steps no. 7 ? 9 for each Web ACL created within your AWS cloud account.
Associated Items
Affected Objects
|
#TABLE_Identity-and-Access-Management1#TABLE_Simple-Storage-Service-(S3)2#TABLE_Elastic-Compute-Cloud-(EC2)3#TABLE_Elastic-File-System-(EFS)4#TABLE_Logging5#TABLE_Monitoring6#TABLE_Networking7#TABLE_Amazon-Machine-Images-(AMI)8#TABLE_Lightsail9#TABLE_Lambda10#TABLE_Batch11#TABLE_Elastic-Beanstalk12#TABLE_AWS-App-Runner13#TABLE_AWS-SimSpace-Weaver14#TABLE_Introduction15#TABLE_Elastic-Block-Store-(EBS)16#TABLE_Elastic-Disaster-Recovery-(EDR)17#TABLE_Amazon-Aurora18#TABLE_Amazon-RDS19#TABLE_Amazon-DynamoDB20#TABLE_Amazon-ElastiCache21#TABLE_Amazon-MemoryDB-for-Redis22#TABLE_Amazon-DocumentDB23#TABLE_Amazon-Keyspaces-(formerly-Amazon-Managed-Apache-Cassandra-Service)24#TABLE_Amazon-Neptune25#TABLE_Amazon-Timestream26#TABLE_Amazon-Ledger-Database-Services-(QLDB)27#TABLE_Amazon-Simple-Notification-Service-(SNS)28#TABLE_AWS-CloudFormation29#TABLE_Amazon-CloudFront30#TABLE_Amazon-Web-Application-Firewall31
All Tests Table
Assessment Table satus contains status for both CIS Benchmark and Internal Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure security contact information is registered | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure security questions are registered in the AWS account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure hardware MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM password policy requires minimum length of 14 or greater | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM password policy prevents password reuse | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM Users Receive Permissions Only Through Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure that IAM Access analyzer is enabled for all regions | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure EBS Volume Encryption is Enabled in all Regions | High | Status: Not Configured | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure Implementation of EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EFS and VPC Integration | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure controlling Network access to EFS Services | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure File-Level Access Control with Mount Targets | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure managing mount target security groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure using VPC endpoints - EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure managing AWS EFS access points | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure accessing Points and IAM Policies | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuring IAM for AWS Elastic Disaster Recovery | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Security Hub is enabled | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure securing AWS Backups | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EBS volume encryption is enabled | High | Status:Not Configured correctly | N/A | Level 2 | CIS v1.0.0 | NO |
|
| Ensure Tag Policies are Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure no AWS EC2 Instances are Older than 180 days | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuring Security Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure the proper configuration of EBS storage | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure the Creation of IAM Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Granular Policy Creation | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Resource Access via Tag-based Policies | High | Status: Not Configured | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Elastic Disaster Recovery is Configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Disaster Recovery Configuration | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure functionality of Endpoint Detection and Response (EDR) | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuration of replication settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure proper configuration of the Launch Settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a recovery drill | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure the Use of Security Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data at Rest is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data in Transit is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure IAM Roles and Policies are Created | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Database Audit Logging is Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Automatic Backups and Retention Policies are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Multi-Factor Authentication (MFA) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Enable Amazon Aurora Backtrack | High | Status: Not Configured | N/A | N/A | OP 1.0 | NO |
|
| Enable event notifications for RDS | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Enable Event Subscriptions for DB Security Groups Events | High | Status: Not Configured | N/A | N/A | OP 1.0 | NO |
|
| Ensure AWS Identity and Access Management (IAM) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure DynamoDB Encryption at Rest | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure VPC Endpoints are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure DynamoDB Streams and AWS Lambda for Automated Compliance Checking is Enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Monitor and Audit Activity is enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data at Rest is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data in Transit is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Monitoring and Alerting is Enabled_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure CloudFormation service is in use for defining your cloud architectures on Amazon Web Services | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure CloudFront global content delivery network (CDN) service is in use | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure that CloudFront distributions are configured to use a custom SSL-TLS certificate | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure that CloudFront distributions are configured to use Server Name Indication (SNI) | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure AWS WAF is in use to protect your web applications from common web exploits | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure that logging is enabled for Amazon WAF Web Access Control Lists | High | Status:Not Configured correctly | N/A | N/A | OP 1.0 | NO |
|
| Ensure an Organizational EC2 Tag Policy has been Created | Medium | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure creating EC2 instance with EBS | Medium | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Maintain current contact details | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no root user account access key exists | Passed | Status:Configured correctly | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Eliminate use of the root user for administrative and daily tasks | Passed | Status:Configured correctly:0 | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Do not setup access keys during initial user setup for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure there is only one active access key available for any single IAM user | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access keys are rotated every 90 days or less | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policies that allow full *-* administrative privileges are not attached | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure a support role has been created to manage incidents with AWS Support | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM instance roles are used for AWS resource access from instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that all the expired SSL-TLS certificates stored in AWS IAM are removed | Passed | Status: Configured Correctly | By default, expired certificates won't get deleted. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access to AWSCloudShellFullAccess is restricted | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 Bucket Policy is set to deny HTTP requests | Passed | Status:Configured correctly | Both HTTP and HTTPS Request are allowed | Level 1 | CIS v3.0.0 | YES |
|
| Ensure MFA Delete is enabled on S3 buckets | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure all data in Amazon S3 has been discovered- classified and secured when required | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that S3 Buckets are configured with Block public access (bucket settings) | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Amazon Simple Storage Service | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure direct data addition to S3 | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Storage Classes are Configured | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption is enabled for EFS file systems | Passed | Status:Configured correctly: | EFS file system data is encrypted at rest by default when creating a file system via theConsole. Encryption at rest is not enabled by default when creating a new file systemusing the AWS CLI, API, and SDKs. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure using Security Groups for VPC | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Ports | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure CloudTrail is enabled in all regions | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail log file validation is enabled | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config is enabled in all regions | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket | Passed | Status:Configured correctly: | Logging is disabled. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail logs are encrypted at rest using KMS CMKs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure rotation for customer-created symmetric CMKs is enabled | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC flow logging is enabled in all VPCs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for write events is enabled for S3 bucket | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for read events is enabled for S3 bucket | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure unauthorized API calls are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure management console sign-in without MFA is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure usage of root account is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Management Console authentication failures are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure disabling or scheduled deletion of customer created CMKs is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure security group changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Network Access Control Lists (NACL) changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure changes to network gateways are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure route table changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Organizations changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no Network ACLs allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no security groups allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure the default security group of every VPC restricts all traffic | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure routing tables for VPC peering are least access | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that EC2 Metadata Service only allows IMDSv2 | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Consistent Naming Convention is used for Organizational AMI | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Images (AMIs) are encrypted | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Only Approved AMIs (Images) are Used | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images (AMI) are not older than 90 days | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images are not Publicly Available | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Apply updates to any apps running in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change default Administrator login names and passwords for applications | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable SSH and RDP ports for Lightsail instances when not needed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure SSH is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure RDP is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable IPv6 Networking if not in use within your organization | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure you are using an IAM policy to manage access to buckets in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lightsail instances are attached to the buckets | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that your Lightsail buckets are not publicly accessible | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable storage bucket access logging | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure your Windows Server based lightsail instances are updated with the latest security patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change the auto-generated password for Windows based instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Config is Enabled for Lambda and Serverless | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Cloudwatch Lambda insights is enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Secrets manager is configured and being used by Lambda for databases | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure least privilege is used with Lambda function access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure every Lambda function has its own IAM Role | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are not exposed to everyone | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are referencing active execution roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that Code Signing is enabled for Lambda functions | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure there are no Lambda functions with admin privileges within your AWS account | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Batch roles are configured for cross-service confused deputy prevention | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Managed Platform updates is configured | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Persistent logs is setup and configured to S3 | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure access logs are enabled | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure that HTTPS is enabled on load balancer | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure you are using VPC Endpoints for source code access | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure communications between your applications and clients is encrypted | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| AWS Storage Backups | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create backup template and name | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create AWS IAM Policies | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create IAM roles for Backup | Passed | Status: Configured Correctly | When using the AWS Backup console for the first time, you can choose to have AWS Backup create a default service role for you. This role has the permissions that AWS Backup needs to create and restore backups on your behalf. | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Backup with Service Linked Roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Public Access to EBS Snapshots is Disabled | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure EBS volume snapshots are encrypted | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure unused EBS volumes are removed | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure detailed monitoring is enable for production EC2 Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Default EC2 Security groups are not being used | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the Use of IMDSv2 is Enforced on All Existing Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure use of AWS Systems Manager to manage EC2 instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure unused ENIs are removed | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure instances stopped for over 90 days are removed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the creation of a new volume | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating snapshots of EBS volumes | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Proper IAM Configuration for EC2 Instances | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Secure Password Policy Implementation | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Monitoring EC2 and EBS with CloudWatch | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating an SNS subscription | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure installation of the AWS Replication Agent | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Amazon VPC (Virtual Private Cloud) has been created | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Passwords are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Keys are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Least Privilege Access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption-at-rest is enabled for RDS Instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that public access is not given to RDS Instance | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure to Choose the Appropriate Database Engine | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create The Appropriate Deployment Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create a Virtual Private Cloud (VPC) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Security Groups | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption at Rest | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Patch Systems | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Review Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure no Underutilized RDS Instances | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Amazon RDS Public Snapshots | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that Amazon Aurora clusters are configured to use database activity streams | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that all database instances within an Amazon Aurora cluster have the same accessibility | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Enable AWS RDS Cluster Deletion Protection | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure you always use the latest generation of DB instances to get better performance with lower cost | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Identify overutilized RDS instances and upgrade them in order to optimize database workload and response time | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Enable AWS RDS Performance Insights | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure automated backups are enabled for RDS instances | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Enable RDS Copy Tags to Snapshots | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Amazon RDS database instances are not using the default ports | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure RDS instances are encrypted with CMKs to have full control over encrypting and decrypting data | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure encryption is setup for RDS instances to fulfill compliance requirements for data-at-rest encryption | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure RDS instances are using General Purpose SSD storage | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that no AWS RDS database instances are provisioned inside VPC public subnets | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure AWS RDS instances are using secure and unique master usernames for their databases | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure RDS instances are launched into Multi-AZ | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure RDS instances are not public facing to minimise security risks | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Amazon RDS Reserved Instances (RI) are renewed before expiration | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure AWS RDS Reserved Instance purchases have not failed | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Amazon RDS Reserved Instance purchases are not pending | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure RDS instances have sufficient backup retention period for compliance purposes | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure there are not any unrestricted DB security groups assigned to your RDS instances | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that Amazon Backup service is used to manage AWS RDS database snapshots | Passed | Status: Configured Correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Fine-Grained Access Control is implemented | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure DynamoDB Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Access to ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest and in Transit is configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Automatic Updates and Patching are Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Virtual Private Cloud (VPC) is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_MemoryDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Architecture Planning | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure VPC Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Monitoring and Alerting | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Backup and Disaster Recovery | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Backup Window | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Conduct Security Assessments | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Keyspace Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data Ingestion is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Control and Authentication is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Fine-Grained Access Control is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches are Installed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Review and Update the Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Identity and Access Management (IAM) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Access is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data in Transit is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Amazon SNS topics do not allow unknown cross account access | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure SNS topics do not allow Everyone to publish | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure SNS topics do not allow Everyone to subscribe | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Enable Server-Side Encryption for AWS SNS Topics | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that Amazon SNS topics are encrypted with KMS Customer Master Keys | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure SNS topics are not exposed to everyone | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure a deletion policy is used for your Amazon CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that Amazon CloudFormation stacks have not been drifted | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFormation stack policies are set to prevent accidental updates to stack resources | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFormation stacks are integrated with SNS to receive notifications about stack events | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Termination Protection feature is enabled for your AWS CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure IAM role with CloudFormation Use least privilege | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure AWS CloudFormation stacks are not in Failed mode for more than 6 hours | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFront distributions are configured to automatically compress content | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure Geo Restriction is enabled for CloudFront CDN distributions | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFront origins dont use insecure SSL protocols | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFront is integrated with WAF to protect web applications from exploit attempts | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFront logging is enabled | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure AWS CloudFront distributions are using improved security policies for HTTPS connections | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure traffic between a CloudFront distribution and the origin is encrypted | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure CloudFront Viewer Protocol Policy enforces encryption | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that CloudFront distributions are configured to use a default root object | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that CloudFront distributions are using an origin access control configuration for their origin S3 buckets | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that CloudFront distributions are using the Origin Failover feature to maintain high availability | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that Amazon CloudFront distributions are using the Origin Shield feature | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that CloudFront distributions are using the Real-Time Logging feature | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Enable Field-Level Encryption for CloudFront Distributions | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure that CloudFront distributions do not point to non-existent S3 origins | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure to Use Amazon CloudFront Content Distribution Network for secure web content delivery | Passed | Status:Configured correctly | N/A | N/A | OP 1.0 | YES |
|
| Ensure credentials unused for 45 days or greater are disabled | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure no security groups allow ingress from ---0 to remote server administration ports | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure Lambda functions do not allow unknown cross account access via permission policies | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure encryption is enabled for Lambda function variables | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Batch is configured with AWS Cloudwatch Logs | Manual Check | NONE | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure creating IAM User | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure proper IAM configuration for AWS Elastic Disaster Recovery | Manual Check | NONE | Configure IAM Credentials for AWS Elastic Disaster Recovery. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Continuous Disaster Recovery Operations | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a Disaster Recovery Failover | Manual Check | NONE | Implement a disaster recovery failover. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a failback | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure CloudWatch Metrics for AWS EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure working of EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
CIS Assessment Status Table
Assessment Table satus contains status for CIS Benchmark Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure security contact information is registered | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure security questions are registered in the AWS account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure hardware MFA is enabled for the root user account | High | Status:Not Configured correctly | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM password policy requires minimum length of 14 or greater | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM password policy prevents password reuse | High | Status:Not Configured correctly: | N/A | Level 2 | CIS v3.0.0 | NO |
|
| Ensure IAM Users Receive Permissions Only Through Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure that IAM Access analyzer is enabled for all regions | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments | High | Status:Not Configured correctly | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure EBS Volume Encryption is Enabled in all Regions | High | Status: Not Configured | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure Implementation of EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EFS and VPC Integration | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure controlling Network access to EFS Services | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure File-Level Access Control with Mount Targets | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure managing mount target security groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure using VPC endpoints - EFS | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure managing AWS EFS access points | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure accessing Points and IAM Policies | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuring IAM for AWS Elastic Disaster Recovery | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Security Hub is enabled | High | Status:Not Configured correctly: | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure securing AWS Backups | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EBS volume encryption is enabled | High | Status:Not Configured correctly | N/A | Level 2 | CIS v1.0.0 | NO |
|
| Ensure Tag Policies are Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure no AWS EC2 Instances are Older than 180 days | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuring Security Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure the proper configuration of EBS storage | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure the Creation of IAM Groups | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Granular Policy Creation | High | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Resource Access via Tag-based Policies | High | Status: Not Configured | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure Elastic Disaster Recovery is Configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Disaster Recovery Configuration | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure functionality of Endpoint Detection and Response (EDR) | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure configuration of replication settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure proper configuration of the Launch Settings | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a recovery drill | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure the Use of Security Groups | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data at Rest is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data in Transit is Encrypted_Aurora | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure IAM Roles and Policies are Created | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Database Audit Logging is Enabled | High | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Automatic Backups and Retention Policies are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Multi-Factor Authentication (MFA) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Identity and Access Management (IAM) is in use | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure DynamoDB Encryption at Rest | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure VPC Endpoints are configured | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure DynamoDB Streams and AWS Lambda for Automated Compliance Checking is Enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Monitor and Audit Activity is enabled | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data at Rest is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Data in Transit is Encrypted_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Monitoring and Alerting is Enabled_Neptune | High | Status: Not Configured | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure an Organizational EC2 Tag Policy has been Created | Medium | Status:Not Configured correctly | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure creating EC2 instance with EBS | Medium | Status:Not Configured correctly | N/A | N/A | CIS v1.0.0 | NO |
|
| Maintain current contact details | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no root user account access key exists | Passed | Status:Configured correctly | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Eliminate use of the root user for administrative and daily tasks | Passed | Status:Configured correctly:0 | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Do not setup access keys during initial user setup for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure there is only one active access key available for any single IAM user | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access keys are rotated every 90 days or less | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policies that allow full *-* administrative privileges are not attached | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure a support role has been created to manage incidents with AWS Support | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM instance roles are used for AWS resource access from instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that all the expired SSL-TLS certificates stored in AWS IAM are removed | Passed | Status: Configured Correctly | By default, expired certificates won't get deleted. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access to AWSCloudShellFullAccess is restricted | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 Bucket Policy is set to deny HTTP requests | Passed | Status:Configured correctly | Both HTTP and HTTPS Request are allowed | Level 1 | CIS v3.0.0 | YES |
|
| Ensure MFA Delete is enabled on S3 buckets | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure all data in Amazon S3 has been discovered- classified and secured when required | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that S3 Buckets are configured with Block public access (bucket settings) | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Amazon Simple Storage Service | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure direct data addition to S3 | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Storage Classes are Configured | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption is enabled for EFS file systems | Passed | Status:Configured correctly: | EFS file system data is encrypted at rest by default when creating a file system via theConsole. Encryption at rest is not enabled by default when creating a new file systemusing the AWS CLI, API, and SDKs. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure using Security Groups for VPC | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Ports | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure CloudTrail is enabled in all regions | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail log file validation is enabled | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config is enabled in all regions | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket | Passed | Status:Configured correctly: | Logging is disabled. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail logs are encrypted at rest using KMS CMKs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure rotation for customer-created symmetric CMKs is enabled | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC flow logging is enabled in all VPCs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for write events is enabled for S3 bucket | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for read events is enabled for S3 bucket | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure unauthorized API calls are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure management console sign-in without MFA is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure usage of root account is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Management Console authentication failures are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure disabling or scheduled deletion of customer created CMKs is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure security group changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Network Access Control Lists (NACL) changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure changes to network gateways are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure route table changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Organizations changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no Network ACLs allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no security groups allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure the default security group of every VPC restricts all traffic | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure routing tables for VPC peering are least access | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that EC2 Metadata Service only allows IMDSv2 | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Consistent Naming Convention is used for Organizational AMI | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Images (AMIs) are encrypted | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Only Approved AMIs (Images) are Used | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images (AMI) are not older than 90 days | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images are not Publicly Available | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Apply updates to any apps running in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change default Administrator login names and passwords for applications | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable SSH and RDP ports for Lightsail instances when not needed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure SSH is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure RDP is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable IPv6 Networking if not in use within your organization | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure you are using an IAM policy to manage access to buckets in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lightsail instances are attached to the buckets | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that your Lightsail buckets are not publicly accessible | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable storage bucket access logging | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure your Windows Server based lightsail instances are updated with the latest security patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change the auto-generated password for Windows based instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Config is Enabled for Lambda and Serverless | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Cloudwatch Lambda insights is enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Secrets manager is configured and being used by Lambda for databases | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure least privilege is used with Lambda function access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure every Lambda function has its own IAM Role | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are not exposed to everyone | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are referencing active execution roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that Code Signing is enabled for Lambda functions | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure there are no Lambda functions with admin privileges within your AWS account | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Batch roles are configured for cross-service confused deputy prevention | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Managed Platform updates is configured | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Persistent logs is setup and configured to S3 | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure access logs are enabled | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure that HTTPS is enabled on load balancer | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure you are using VPC Endpoints for source code access | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure communications between your applications and clients is encrypted | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| AWS Storage Backups | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create backup template and name | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create AWS IAM Policies | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create IAM roles for Backup | Passed | Status: Configured Correctly | When using the AWS Backup console for the first time, you can choose to have AWS Backup create a default service role for you. This role has the permissions that AWS Backup needs to create and restore backups on your behalf. | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Backup with Service Linked Roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Public Access to EBS Snapshots is Disabled | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure EBS volume snapshots are encrypted | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure unused EBS volumes are removed | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure detailed monitoring is enable for production EC2 Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Default EC2 Security groups are not being used | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the Use of IMDSv2 is Enforced on All Existing Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure use of AWS Systems Manager to manage EC2 instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure unused ENIs are removed | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure instances stopped for over 90 days are removed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the creation of a new volume | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating snapshots of EBS volumes | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Proper IAM Configuration for EC2 Instances | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Secure Password Policy Implementation | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Monitoring EC2 and EBS with CloudWatch | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating an SNS subscription | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure installation of the AWS Replication Agent | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Amazon VPC (Virtual Private Cloud) has been created | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Passwords are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Keys are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Least Privilege Access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption-at-rest is enabled for RDS Instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that public access is not given to RDS Instance | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure to Choose the Appropriate Database Engine | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create The Appropriate Deployment Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create a Virtual Private Cloud (VPC) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Security Groups | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption at Rest | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Patch Systems | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Review Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Fine-Grained Access Control is implemented | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure DynamoDB Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Access to ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest and in Transit is configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Automatic Updates and Patching are Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Virtual Private Cloud (VPC) is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_MemoryDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Architecture Planning | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure VPC Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Monitoring and Alerting | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Backup and Disaster Recovery | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Backup Window | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Conduct Security Assessments | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Keyspace Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data Ingestion is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Control and Authentication is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Fine-Grained Access Control is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches are Installed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Review and Update the Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Identity and Access Management (IAM) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Access is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data in Transit is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure credentials unused for 45 days or greater are disabled | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure no security groups allow ingress from ---0 to remote server administration ports | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure Lambda functions do not allow unknown cross account access via permission policies | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure encryption is enabled for Lambda function variables | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Batch is configured with AWS Cloudwatch Logs | Manual Check | NONE | N/A | N/A | CIS v1.0.0 | NO |
|
| Ensure creating IAM User | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure proper IAM configuration for AWS Elastic Disaster Recovery | Manual Check | NONE | Configure IAM Credentials for AWS Elastic Disaster Recovery. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Continuous Disaster Recovery Operations | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a Disaster Recovery Failover | Manual Check | NONE | Implement a disaster recovery failover. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a failback | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure CloudWatch Metrics for AWS EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure working of EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
SmartProfiler Assessment Tests Status Table
Assessment Table satus contains status for SmartProfiler Tests.
All Passed Checks Table
Contains Passed Checks for both CIS Benchmark and SmartProfiler Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Maintain current contact details | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no root user account access key exists | Passed | Status:Configured correctly | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Eliminate use of the root user for administrative and daily tasks | Passed | Status:Configured correctly:0 | N/A | Level 2 | CIS v3.0.0 | YES |
|
| Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Do not setup access keys during initial user setup for all IAM users that have a console password | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure there is only one active access key available for any single IAM user | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access keys are rotated every 90 days or less | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policies that allow full *-* administrative privileges are not attached | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure a support role has been created to manage incidents with AWS Support | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM instance roles are used for AWS resource access from instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that all the expired SSL-TLS certificates stored in AWS IAM are removed | Passed | Status: Configured Correctly | By default, expired certificates won't get deleted. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure access to AWSCloudShellFullAccess is restricted | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 Bucket Policy is set to deny HTTP requests | Passed | Status:Configured correctly | Both HTTP and HTTPS Request are allowed | Level 1 | CIS v3.0.0 | YES |
|
| Ensure MFA Delete is enabled on S3 buckets | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure all data in Amazon S3 has been discovered- classified and secured when required | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that S3 Buckets are configured with Block public access (bucket settings) | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Amazon Simple Storage Service | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure direct data addition to S3 | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Storage Classes are Configured | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption is enabled for EFS file systems | Passed | Status:Configured correctly: | EFS file system data is encrypted at rest by default when creating a file system via theConsole. Encryption at rest is not enabled by default when creating a new file systemusing the AWS CLI, API, and SDKs. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure using Security Groups for VPC | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Ports | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure CloudTrail is enabled in all regions | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail log file validation is enabled | Passed | Status:Configured correctly: | Not Enabled | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config is enabled in all regions | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket | Passed | Status:Configured correctly: | Logging is disabled. | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail logs are encrypted at rest using KMS CMKs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure rotation for customer-created symmetric CMKs is enabled | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC flow logging is enabled in all VPCs | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for write events is enabled for S3 bucket | Passed | Status:Configured correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that Object-level logging for read events is enabled for S3 bucket | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure unauthorized API calls are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure management console sign-in without MFA is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure usage of root account is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure IAM policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure CloudTrail configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Management Console authentication failures are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure disabling or scheduled deletion of customer created CMKs is monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure S3 bucket policy changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Config configuration changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure security group changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Network Access Control Lists (NACL) changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure changes to network gateways are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure route table changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure VPC changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure AWS Organizations changes are monitored | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no Network ACLs allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure no security groups allow ingress from 0000-0 to remote server administration ports | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure the default security group of every VPC restricts all traffic | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure routing tables for VPC peering are least access | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that EC2 Metadata Service only allows IMDSv2 | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Consistent Naming Convention is used for Organizational AMI | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Images (AMIs) are encrypted | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Only Approved AMIs (Images) are Used | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images (AMI) are not older than 90 days | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure Images are not Publicly Available | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Apply updates to any apps running in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change default Administrator login names and passwords for applications | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable SSH and RDP ports for Lightsail instances when not needed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure SSH is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure RDP is restricted to only IP address that should have this access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Disable IPv6 Networking if not in use within your organization | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure you are using an IAM policy to manage access to buckets in Lightsail | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lightsail instances are attached to the buckets | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that your Lightsail buckets are not publicly accessible | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable storage bucket access logging | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure your Windows Server based lightsail instances are updated with the latest security patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Change the auto-generated password for Windows based instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Config is Enabled for Lambda and Serverless | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Cloudwatch Lambda insights is enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Secrets manager is configured and being used by Lambda for databases | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure least privilege is used with Lambda function access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure every Lambda function has its own IAM Role | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are not exposed to everyone | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Lambda functions are referencing active execution roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that Code Signing is enabled for Lambda functions | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure there are no Lambda functions with admin privileges within your AWS account | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Batch roles are configured for cross-service confused deputy prevention | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Managed Platform updates is configured | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Persistent logs is setup and configured to S3 | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure access logs are enabled | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure that HTTPS is enabled on load balancer | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure you are using VPC Endpoints for source code access | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure communications between your applications and clients is encrypted | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| AWS Storage Backups | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create backup template and name | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create AWS IAM Policies | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure to create IAM roles for Backup | Passed | Status: Configured Correctly | When using the AWS Backup console for the first time, you can choose to have AWS Backup create a default service role for you. This role has the permissions that AWS Backup needs to create and restore backups on your behalf. | Level 1 | CIS v1.0.0 | YES |
|
| Ensure AWS Backup with Service Linked Roles | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Public Access to EBS Snapshots is Disabled | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure EBS volume snapshots are encrypted | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure unused EBS volumes are removed | Passed | Status:Configured correctly | N/A | Level 2 | CIS v1.0.0 | YES |
|
| Ensure detailed monitoring is enable for production EC2 Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Default EC2 Security groups are not being used | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the Use of IMDSv2 is Enforced on All Existing Instances | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure use of AWS Systems Manager to manage EC2 instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure unused ENIs are removed | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure instances stopped for over 90 days are removed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure the creation of a new volume | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating snapshots of EBS volumes | Passed | Status:Configured correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Proper IAM Configuration for EC2 Instances | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Secure Password Policy Implementation | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure Monitoring EC2 and EBS with CloudWatch | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure creating an SNS subscription | Passed | Status: Configured Correctly | N/A | N/A | CIS v1.0.0 | YES |
|
| Ensure installation of the AWS Replication Agent | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Amazon VPC (Virtual Private Cloud) has been created | Passed | Status:Configured correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Passwords are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Keys are Regularly Rotated | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Least Privilege Access | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure that encryption-at-rest is enabled for RDS Instances | Passed | Status:Configured correctly: | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure that public access is not given to RDS Instance | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v3.0.0 | YES |
|
| Ensure to Choose the Appropriate Database Engine | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create The Appropriate Deployment Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Create a Virtual Private Cloud (VPC) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Security Groups | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption at Rest | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Enable Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Patch Systems | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_RDS | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Regularly Review Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure no Underutilized RDS Instances | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Amazon RDS Public Snapshots | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that Amazon Aurora clusters are configured to use database activity streams | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that all database instances within an Amazon Aurora cluster have the same accessibility | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Enable AWS RDS Cluster Deletion Protection | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure you always use the latest generation of DB instances to get better performance with lower cost | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Identify overutilized RDS instances and upgrade them in order to optimize database workload and response time | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Enable AWS RDS Performance Insights | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure automated backups are enabled for RDS instances | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Enable RDS Copy Tags to Snapshots | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Amazon RDS database instances are not using the default ports | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure RDS instances are encrypted with CMKs to have full control over encrypting and decrypting data | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure encryption is setup for RDS instances to fulfill compliance requirements for data-at-rest encryption | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure RDS instances are using General Purpose SSD storage | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure fewer Amazon RDS instances than the established limit in your AWS account | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that no AWS RDS database instances are provisioned inside VPC public subnets | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure AWS RDS instances are using secure and unique master usernames for their databases | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure RDS instances are launched into Multi-AZ | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure RDS instances are not public facing to minimise security risks | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Amazon RDS Reserved Instances (RI) are renewed before expiration | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure AWS RDS Reserved Instance purchases have not failed | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Amazon RDS Reserved Instance purchases are not pending | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure RDS instances have sufficient backup retention period for compliance purposes | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure there are not any unrestricted DB security groups assigned to your RDS instances | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that Amazon Backup service is used to manage AWS RDS database snapshots | Passed | Status: Configured Correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Fine-Grained Access Control is implemented | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure DynamoDB Encryption in Transit | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Secure Access to ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest and in Transit is configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Automatic Updates and Patching are Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Virtual Private Cloud (VPC) is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_ElastiCache | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_MemoryDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_MemoryDB for Redis | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Architecture Planning | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure VPC Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption at Rest is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_DocumentDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Monitoring and Alerting | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Backup and Disaster Recovery | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Configure Backup Window | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Conduct Security Assessments | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Keyspace Security is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest and in Transit is Encrypted_Keyspaces | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Security is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Authentication and Access Control is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Security Configurations are Reviewed Regularly_Neptune | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data Ingestion is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Encryption in Transit is Configured | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Access Control and Authentication is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Fine-Grained Access Control is Enabled | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Audit Logging is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Regular Updates and Patches are Installed | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Alerting is Enabled_Timestream | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Review and Update the Security Configuration | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Identity and Access Management (IAM) | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Network Access is Secure | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data at Rest is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Data in Transit is Encrypted_OLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Implement Access Control and Authentication_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Monitoring and Logging is Enabled_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure to Enable Backup and Recovery_QLDB | Passed | Status: Configured Correctly | N/A | Level 1 | CIS v1.0.0 | YES |
|
| Ensure Amazon SNS topics do not allow unknown cross account access | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure SNS topics do not allow Everyone to publish | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure SNS topics do not allow Everyone to subscribe | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Enable Server-Side Encryption for AWS SNS Topics | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that Amazon SNS topics are encrypted with KMS Customer Master Keys | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure SNS topics are not exposed to everyone | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure a deletion policy is used for your Amazon CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that Amazon CloudFormation stacks have not been drifted | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFormation stack policies are set to prevent accidental updates to stack resources | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFormation stacks are integrated with SNS to receive notifications about stack events | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Termination Protection feature is enabled for your AWS CloudFormation stacks | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure IAM role with CloudFormation Use least privilege | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure AWS CloudFormation stacks are not in Failed mode for more than 6 hours | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFront distributions are configured to automatically compress content | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure Geo Restriction is enabled for CloudFront CDN distributions | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFront origins dont use insecure SSL protocols | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFront is integrated with WAF to protect web applications from exploit attempts | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFront logging is enabled | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure AWS CloudFront distributions are using improved security policies for HTTPS connections | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure traffic between a CloudFront distribution and the origin is encrypted | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure CloudFront Viewer Protocol Policy enforces encryption | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that CloudFront distributions are configured to use a default root object | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that CloudFront distributions are using an origin access control configuration for their origin S3 buckets | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that CloudFront distributions are using the Origin Failover feature to maintain high availability | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that Amazon CloudFront distributions are using the Origin Shield feature | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that CloudFront distributions are using the Real-Time Logging feature | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Enable Field-Level Encryption for CloudFront Distributions | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure that CloudFront distributions do not point to non-existent S3 origins | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
|
| Ensure to Use Amazon CloudFront Content Distribution Network for secure web content delivery | Passed | Status:Configured correctly | N/A | N/A | SP v1.0 | YES |
All Affected Objects Table
Contains Affected Objects Items for both CIS Benchmark and SmartProfiler Tests. You can find tests that have affected objects.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
All Manual Checks Table
Contains Manual Checks for both CIS Benchmark and SmartProfiler Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Ensure credentials unused for 45 days or greater are disabled | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure no security groups allow ingress from ---0 to remote server administration ports | Manual Check | NONE | N/A | Level 1 | CIS v3.0.0 | NO |
|
| Ensure Lambda functions do not allow unknown cross account access via permission policies | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure encryption is enabled for Lambda function variables | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure AWS Batch is configured with AWS Cloudwatch Logs | Manual Check | NONE | N/A | CIS v1.0.0 | NO |
||
| Ensure creating IAM User | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure proper IAM configuration for AWS Elastic Disaster Recovery | Manual Check | NONE | Configure IAM Credentials for AWS Elastic Disaster Recovery. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure Continuous Disaster Recovery Operations | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a Disaster Recovery Failover | Manual Check | NONE | Implement a disaster recovery failover. | Level 1 | CIS v1.0.0 | NO |
|
| Ensure execution of a failback | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure CloudWatch Metrics for AWS EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |
|
| Ensure working of EDR | Manual Check | NONE | N/A | Level 1 | CIS v1.0.0 | NO |