πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [APIGateway.2] API Gateway REST API stages should be configured to use SSL certificates for backend authentication" | | 1 | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [APIGateway.5] API Gateway REST API cache data should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CloudFront.3] CloudFront distributions should require encryption in transit | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CloudFront.7] CloudFront distributions should use custom SSL/TLS certificates | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CloudFront.8] CloudFront distributions should use SNI to serve HTTPS requests | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CloudFront.10] CloudFront distributions should not use deprecated SSL protocols between edge locations and custom origins | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CloudTrail.2] CloudTrail should have encryption at-rest enabled | | | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [CodeBuild.3] CodeBuild S3 logs should be encrypted | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [DocumentDB.1] Amazon DocumentDB clusters should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [DynamoDB.3] DynamoDB Accelerator (DAX) clusters should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [EC2.3] Attached Amazon EBS volumes should be encrypted at-rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [EC2.7] EBS default encryption should be enabled | | 1 | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [EFS.1] Elastic File System should be configured to encrypt file data at-rest using AWS KMS | | 1 | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ElastiCache.4] ElastiCache replication groups should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ElastiCache.5] ElastiCache replication groups should be encrypted in transit | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ELB.1] Application Load Balancer should be configured to redirect all HTTP requests to HTTPS | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ELB.2] Classic Load Balancers with SSL/HTTPS listeners should use a certificate provided by AWS Certificate Manager | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ELB.3] Classic Load Balancer listeners should be configured with HTTPS or TLS termination | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ELB.8] Classic Load Balancers with SSL listeners should use a predefined security policy that has strong AWS Configuration | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ELB.17] Application and Network Load Balancers with listeners should use recommended security policies | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ES.1] Elasticsearch domains should have encryption at-rest enabled | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [ES.8] Connections to Elasticsearch domains should be encrypted using the latest TLS security policy | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Kinesis.1] Kinesis streams should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Neptune.1] Neptune DB clusters should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Opensearch.1] OpenSearch domains should have encryption at rest enabled | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Opensearch.8] Connections to OpenSearch domains should be encrypted using the latest TLS security policy | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [RDS.3] RDS DB instances should have encryption at-rest enabled | | 1 | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [RDS.4] RDS cluster snapshots and database snapshots should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [RDS.27] RDS DB clusters should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Redshift.10] Redshift clusters should be encrypted at rest | | | | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [S3.5] S3 general purpose buckets should require requests to use SSL | | 1 | 1 | |
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [SQS.1] Amazon SQS queues should be encrypted at rest | | | | |