Skip to main content

💼 CIS AWS v1.3.0

  • ID: /frameworks/cis-aws-v1.3.0

Stats​

not available

Description​

Empty...

Similar​

  • Internal
    • ID: dec-a-c6733a31

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 1 Identity and Access Management221220no data
 💼 1.1 Maintain current contact details1no data
 💼 1.2 Ensure security contact information is registered1no data
 💼 1.3 Ensure security questions are registered in the AWS accountno data
 💼 1.4 Ensure no root user account access key exists11no data
 💼 1.5 Ensure MFA is enabled for the "root user" account1no data
 💼 1.6 Ensure hardware MFA is enabled for the "root user" account1no data
 💼 1.7 Eliminate use of the root user for administrative and daily tasks11no data
 💼 1.8 Ensure IAM password policy requires minimum length of 14 or greater1no data
 💼 1.9 Ensure IAM password policy prevents password reuse11no data
 💼 1.10 Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password1no data
 💼 1.11 Do not setup access keys during initial user setup for all IAM users that have a console password11no data
 💼 1.12 Ensure credentials unused for 90 days or greater are disabledno data
 💼 1.13 Ensure there is only one active access key available for any single IAM user11no data
 💼 1.14 Ensure access keys are rotated every 90 days or less11no data
 💼 1.15 Ensure IAM Users Receive Permissions Only Through Groups11no data
 💼 1.16 Ensure IAM policies that allow full ":" administrative privileges are not attached11no data
 💼 1.17 Ensure a support role has been created to manage incidents with AWS Support1no data
 💼 1.18 Ensure IAM instance roles are used for AWS resource access from instances11no data
 💼 1.19 Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed11no data
 💼 1.20 Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'11no data
 💼 1.21 Ensure that IAM Access analyzer is enabled11no data
 💼 1.22 Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments1no data
💼 2 Storage222no data
 💼 2.1 Simple Storage Service (S3)211no data
  💼 2.1.1 Ensure all S3 buckets employ encryption-at-restno data
  💼 2.1.2 Ensure S3 Bucket Policy allows HTTPS requests11no data
 💼 2.2 Elastic Compute Cloud (EC2)111no data
  💼 2.2.1 Ensure EBS volume encryption is enabled11no data
💼 3 Logging1149no data
 💼 3.1 Ensure CloudTrail is enabled in all regions11no data
 💼 3.2 Ensure CloudTrail log file validation is enabled11no data
 💼 3.3 Ensure the S3 bucket used to store CloudTrail logs is not publicly accessibleno data
 💼 3.4 Ensure CloudTrail trails are integrated with CloudWatch Logsno data
 💼 3.5 Ensure AWS Config is enabled in all regions1no data
 💼 3.6 Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket1no data
 💼 3.7 Ensure CloudTrail logs are encrypted at rest using KMS CMKs1no data
 💼 3.8 Ensure rotation for customer created CMKs is enabled11no data
 💼 3.9 Ensure VPC flow logging is enabled in all VPCs11no data
 💼 3.10 Ensure that Object-level logging for write events is enabled for S3 bucket1no data
 💼 3.11 Ensure that Object-level logging for read events is enabled for S3 bucket1no data
💼 4 Monitoring1515no data
 💼 4.1 Ensure a log metric filter and alarm exist for unauthorized API calls1no data
 💼 4.2 Ensure a log metric filter and alarm exist for Management Console sign-in without MFA1no data
 💼 4.3 Ensure a log metric filter and alarm exist for usage of 'root' account1no data
 💼 4.4 Ensure a log metric filter and alarm exist for IAM policy changes1no data
 💼 4.5 Ensure a log metric filter and alarm exist for CloudTrail configuration changes1no data
 💼 4.6 Ensure a log metric filter and alarm exist for AWS Management Console authentication failures1no data
 💼 4.7 Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs1no data
 💼 4.8 Ensure a log metric filter and alarm exist for S3 bucket policy changes1no data
 💼 4.9 Ensure a log metric filter and alarm exist for AWS Config configuration changes1no data
 💼 4.10 Ensure a log metric filter and alarm exist for security group changes1no data
 💼 4.11 Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)1no data
 💼 4.12 Ensure a log metric filter and alarm exist for changes to network gateways1no data
 💼 4.13 Ensure a log metric filter and alarm exist for route table changes1no data
 💼 4.14 Ensure a log metric filter and alarm exist for VPC changes1no data
 💼 4.15 Ensure a log metric filter and alarm exists for AWS Organizations changes1no data
💼 5 Networking414no data
 💼 5.1 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports1no data
 💼 5.2 Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports11no data
 💼 5.3 Ensure the default security group of every VPC restricts all traffic1no data
 💼 5.4 Ensure routing tables for VPC peering are "least access"1no data