Skip to main content

๐Ÿ’ผ 2 Storage

  • Contextual name: ๐Ÿ’ผ 2 Storage
  • ID: /frameworks/cis-aws-v1.5.0/02
  • Located in: ๐Ÿ’ผ CIS AWS v1.5.0

Descriptionโ€‹

This section contains recommendations for configuring AWS Storage.

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 2.1 Simple Storage Service (S3)5
ย ย ย ย ๐Ÿ’ผ 2.1.1 Ensure all S3 buckets employ encryption-at-rest - Level 2 (Automated)
ย ย ย ย ๐Ÿ’ผ 2.1.2 Ensure S3 Bucket Policy is set to deny HTTP requests - Level 2 (Automated)11
ย ย ย ย ๐Ÿ’ผ 2.1.3 Ensure MFA Delete is enabled on S3 buckets - Level 1 (Automated)11
ย ย ย ย ๐Ÿ’ผ 2.1.4 Ensure all data in Amazon S3 has been discovered, classified and secured when required. - Level 2 (Manual)1
ย ย ย ย ๐Ÿ’ผ 2.1.5 Ensure that S3 Buckets are configured with 'Block public access (bucket settings)' - Level 1 (Automated)11
๐Ÿ’ผ 2.2 Elastic Compute Cloud (EC2)1
ย ย ย ย ๐Ÿ’ผ 2.2.1 Ensure EBS Volume Encryption is Enabled in all Regions - Level 1 (Automated)11
๐Ÿ’ผ 2.3 Relational Database Service (RDS)3
ย ย ย ย ๐Ÿ’ผ 2.3.1 Ensure that encryption is enabled for RDS Instances - Level 1 (Automated)11
ย ย ย ย ๐Ÿ’ผ 2.3.2 Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances - Level 1 (Automated)11
ย ย ย ย ๐Ÿ’ผ 2.3.3 Ensure that public access is not given to RDS Instance - Level 1 (Automated)11
๐Ÿ’ผ 2.4 Elastic File System (EFS)1
ย ย ย ย ๐Ÿ’ผ 2.4.1 Ensure that encryption is enabled for EFS file systems - Level 1 (Manual)1