NIST

National Institute of Standards and Technology (NIST) SP 800-53 Rev. 5

[Work In Progress] The NIST Special Publication 800-53 Revision 5 provides a catalog of security and privacy controls for federal information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats including hostile cyber attacks, natural disasters, structural failures, and human errors.
Read more

Summary: [Not available:173] | [Compliant:64] | [Need Attention:32]

Breakdown

Framework. National Institute of Standards and Technology (NIST) SP 800-53 Rev. 5

CategoryRule IDCompliance StatusDescriptionReference
Account.1Compliant
[hasAlternateContact]
Account.2Compliant
[hasOrganization]
ACM.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
APIGateway.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Appsync.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Autoscaling.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Backup.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.1Compliant
[defaultRootObject]
CloudFront.3Compliant
[viewerPolicyHttps]
CloudFront.4Compliant
[originFailover]
CloudFront.5Compliant
[accessLogging]
CloudFront.6Compliant
[WAFAssociation]
CloudFront.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.10Compliant
[DeprecatedSSLProtocol]
CloudFront.12Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.13Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudFront.14Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudTrail.1Compliant
[HasOneMultiRegionTrail]
CloudTrail.2Need Attention
[RequiresKmsKey] - Enable SSE
  • [ap-northeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE, Cloudtrail::aws-controltower-BaselineCloudTrail
Encrypt CloudTrail using AWS KMS
CloudTrail Security Best Practices
CloudTrail.4Compliant
[LogFileValidationEnabled]
CloudTrail.5Need Attention
[CloudWatchLogsLogGroupArn] - CloudWatch for CloudTrail
  • [ap-northeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
Using CloudWatch Logs with CloudTrail
CloudWatch.15Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudWatch.16Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CloudWatch.17Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CodeBuild.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CodeBuild.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CodeBuild.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
CodeBuild.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Config.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DMS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DMS.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DMS.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DMS.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DMS.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DocumentDB.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DocumentDB.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DocumentDB.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DocumentDB.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DocumentDB.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DynamoDB.1Compliant
[autoScalingStatus]
DynamoDB.2Need Attention
[disabledPointInTimeRecovery] - Point In Time Recovery backup is disabled
  • [us-east-1]Dynamodb::SpringClean-XUG3HH5R-SpringCleanDDBTable-4DMHX1YQNK31
DDB PITR
DynamoDB.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DynamoDB.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
DynamoDB.5Compliant
[resourcesWithoutTags]
DynamoDB.6Need Attention
[deleteTableProtection] - Delete table protection is disabled.
  • [us-east-1]Dynamodb::SpringClean-XUG3HH5R-SpringCleanDDBTable-4DMHX1YQNK31
Turn on DDB delete protection
EC2.1Compliant
[EBSSnapshotIsPublic]
EC2.2Need Attention
[SGDefaultDisallowTraffic] - Default Security Group with Rules
  • [ap-northeast-1]SG::sg-0a9a9f1599f78e648
  • [ap-northeast-2]SG::sg-0e2f6a031113c6c65
  • [ap-northeast-3]SG::sg-0f1c015386fdeaef2
  • [ap-south-1]SG::sg-0ce181aa24e2327a0
  • [ap-southeast-1]SG::sg-0c82e152ce9347073, SG::sg-0442088071f74e66b
  • [ap-southeast-2]SG::sg-06a87caeacb9bdc1c
  • [ap-southeast-3]SG::sg-09c69789992976af0, SG::sg-07d450b94849d4deb
  • [ap-southeast-5]SG::sg-0340a45e7f6dfdeef, SG::sg-0cdece98aec7d1e6c
  • [ca-central-1]SG::sg-0807269705e2a7bce
  • [eu-central-1]SG::sg-061edeb40615f37d8
  • [eu-north-1]SG::sg-0224dd542e0e0a188
  • [eu-west-1]SG::sg-0ee2cf797712225c6
  • [eu-west-2]SG::sg-0d712926de8d430e0
  • [eu-west-3]SG::sg-0d057db4a24c667d8
  • [sa-east-1]SG::sg-06a16f5c401b779ea
  • [us-east-1]SG::sg-0f4d456d65b49cbcc, SG::sg-0562190d9d9c154da, SG::sg-0fe800a9602ab25ff
  • [us-east-2]SG::sg-05b1211873efb1066
  • [us-west-1]SG::sg-0ac2b6884d3c7f382
  • [us-west-2]SG::sg-037dcb16366f739b8
VPC default security group rules
EC2.3Need Attention
[EBSInUse]
[EBSEncrypted] - Enable EBS Encryption
  • [ap-southeast-5]EBS::vol-088df622bcebd7a03
  • [us-west-2]EBS::vol-058a9449d61cf9461
Best practices for Amazon EC2
EC2.4Compliant
[EC2Active]
EC2.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.7Need Attention
[EBSEncrypted] - Enable EBS Encryption
  • [ap-southeast-5]EBS::vol-088df622bcebd7a03
  • [us-west-2]EBS::vol-058a9449d61cf9461
Best practices for Amazon EC2
EC2.8Compliant
[ASGIMDSv2]
EC2.9Need Attention
[EC2InstancePublicIP] - EC2 with Public IP
  • [ap-southeast-5]EC2::i-0d3a7302b927b49bb
Amazon EC2 public IP
EC2.10Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.12Need Attention
[EC2EIPNotInUse] - Elastic IP In Use
  • [ap-southeast-1]ElasticIP::eipalloc-09d7799aa3aa4df1f
Elastic IP Charges
EC2.13Need Attention
[SGSensitivePortOpenToAll] - Sensitive port open to all.
  • [ap-southeast-5]SG::sg-0d56232f5bc4a6a0d
[SGAllPortOpenToAll] - All ports open to all
  • [ap-southeast-5]SG::sg-0d56232f5bc4a6a0d
Best practices for Amazon EC2
Best practices for Amazon EC2
EC2.15Need Attention
[EC2SubnetAutoPublicIP] - EC2 Subnet with Auto Assign IP
  • [ap-southeast-5]EC2::i-0d3a7302b927b49bb
  • [us-west-2]EC2::i-0b59b7cd02dba50a8
Amazon EC2 public IP
EC2.16Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.17Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.18Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.19Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.20Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.21Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.23Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.24Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.25Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.28Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EC2.51Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECR.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECR.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECR.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.10Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ECS.12Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EFS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EFS.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EFS.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EFS.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EKS.1Compliant
[eksEndpointPublicAccess]
EKS.2Compliant
[eksClusterVersionEol]
EKS.8Compliant
[eksClusterLogging]
ElastiCache.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElastiCache.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElastiCache.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElastiCache.4Compliant
[EncInTransitAndRest]
ElastiCache.5Compliant
[EncInTransitAndRest]
ElastiCache.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElastiCache.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElasticBeanstalk.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ElasticBeanstalk.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.7Compliant
[ELBConnectionDraining]
ELB.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.9Compliant
[ELBCrossZone]
ELB.10Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.12Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.13Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.14Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ELB.16Need Attention
[ELBEnableWAF] - ALB Web Application Firewall
  • [ap-southeast-5]ELB::ecs-te-Publi-06Wsj9bSgyQF
AWS WAF for Applicatoin Load Balancers
EMR.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EMR.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
ES.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EventBridge.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
EventBridge.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
FSx.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
GuardDuty.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
IAM.1Need Attention
[FullAdminAccess] - Limit permissions.
  • [GLOBAL]Role::Admin, Role::AWSReservedSSO_AWSAdministratorAccess_ac7e558480de85c0, Role::ww_augnhtrole, Group::admin-group
AWS Docs
Organization GuardRail Blog
IAM.2Need Attention
[userNotUsingGroup]
[InlinePolicy] - Use managed policies
  • [GLOBAL]Role::AccessAnalyzerTrustedService, Role::AthenaCURdailyStack-AWSCURCrawlerComponentFunction-XX4CHL7H96MD, Role::AthenaCURdailyStack-AWSCURCrawlerLambdaExecutor-18PJXDZOQVUT8, Role::AthenaCURdailyStack-AWSS3CURLambdaExecutor-91GHL63BKDPJ, Role::AthenaCURMonthlyStack-AWSCURCrawlerComponentFuncti-1AJFUSIA0NX5X, Role::AthenaCURMonthlyStack-AWSCURCrawlerLambdaExecutor-17MUZETRCHEGM, Role::AthenaCURMonthlyStack-AWSS3CURLambdaExecutor-19ZYBIKM90TK9, Role::AVMContainersUserRole, Role::aws-security-hub-automate-orchestratorRole12B410FD-1VFCRA5D658CQ, Role::aws-security-hub-automate-SNS2DeliveryStatusLoggin-1XB1ER18ZZ6IV, Role::awslogs.prod.kelex.molecule.toppatterns, Role::AWSReservedSSO_AWSServiceCatalogEndUserAccess_2f1286af87fe02c6, Role::AWSSupportPatchwork-ap-northeast-1-AutomationRole, Role::AWSSupportPatchwork-ap-northeast-2-AutomationRole, Role::AWSSupportPatchwork-ap-south-1-AutomationRole, Role::AWSSupportPatchwork-ap-southeast-1-AutomationRole, Role::AWSSupportPatchwork-ap-southeast-2-AutomationRole, Role::AWSSupportPatchwork-ca-central-1-AutomationRole, Role::AWSSupportPatchwork-eu-central-1-AutomationRole, Role::AWSSupportPatchwork-eu-north-1-AutomationRole, Role::AWSSupportPatchwork-eu-west-1-AutomationRole, Role::AWSSupportPatchwork-eu-west-2-AutomationRole, Role::AWSSupportPatchwork-eu-west-3-AutomationRole, Role::AWSSupportPatchwork-sa-east-1-AutomationRole, Role::AWSSupportPatchwork-us-east-1-AutomationRole, Role::AWSSupportPatchwork-us-east-2-AutomationRole, Role::AWSSupportPatchwork-us-west-1-AutomationRole, Role::AWSSupportPatchwork-us-west-2-AutomationRole, Role::CID-CUR-Destination-CIDLambdaAnalyticsRole-4lnxU3a60sr4, Role::CidExecRole, Role::CidQuickSightDataSourceRole, Role::Cloud-Intelligence-Dashboar-InitLambdaExecutionRole-ZassKR4B4CY8, Role::Cloud-Intelligence-Dashboards-CidCURCrawlerRole-6n5acUHm6w0r, Role::CloudSecAuditRole, Role::CloudSeerTrustedServiceRole, Role::CodeGuruProfilerForwardToAmazonProfiler, Role::CURathenaStack-AWSCURCrawlerComponentFunction-Y25X9I4YKV02, Role::CURathenaStack-AWSCURCrawlerLambdaExecutor-WYW3Y5BXZGA, Role::CURathenaStack-AWSS3CURLambdaExecutor-YH390THQNEJX, Role::IMDSv2-automigrator, Role::OrthancRole, Role::SaltyTrustedService, Role::security-hub-format-LambdaExecutionRole-nFM8xh5M3MeA, Role::ShadowTrooperRole, Role::SO0111-CloudTrailToCloudWatchLogs, Role::SO0111-ConfigureS3BucketLogging, Role::SO0111-ConfigureS3BucketPublicAccessBlock, Role::SO0111-ConfigureS3PublicAccessBlock, Role::SO0111-ConfigureSNSTopicForStack, Role::SO0111-CreateAccessLoggingBucket, Role::SO0111-CreateCloudTrailMultiRegionTrail, Role::SO0111-CreateIAMSupportRole, Role::SO0111-CreateLogMetricFilterAndAlarm, Role::SO0111-DisablePublicAccessForSecurityGroup, Role::SO0111-DisablePublicAccessToRDSInstance, Role::SO0111-DisablePublicAccessToRedshiftCluster, Role::SO0111-DisablePublicIPAutoAssign, Role::SO0111-EnableAutomaticSnapshotsOnRedshiftCluster, Role::SO0111-EnableAutomaticVersionUpgradeOnRedshiftCluster, Role::SO0111-EnableAutoScalingGroupELBHealthCheck, Role::SO0111-EnableAWSConfig, Role::SO0111-EnableCloudTrailEncryption, Role::SO0111-EnableCloudTrailLogFileValidation, Role::SO0111-EnableCloudTrailToCloudWatchLogging, Role::SO0111-EnableCopyTagsToSnapshotOnRDSCluster, Role::SO0111-EnableDefaultEncryptionS3, Role::SO0111-EnableDeliveryStatusLoggingForSNSTopic, Role::SO0111-EnableEbsEncryptionByDefault, Role::SO0111-EnableEncryptionForSNSTopic, Role::SO0111-EnableEncryptionForSQSQueue, Role::SO0111-EnableEnhancedMonitoringOnRDSInstance, Role::SO0111-EnableKeyRotation, Role::SO0111-EnableMinorVersionUpgradeOnRDSDBInstance, Role::SO0111-EnableMultiAZOnRDSInstance, Role::SO0111-EnableRDSClusterDeletionProtection, Role::SO0111-EnableRDSInstanceDeletionProtection, Role::SO0111-EnableRedshiftClusterAuditLogging, Role::SO0111-EnableVPCFlowLogs, Role::SO0111-EnableVPCFlowLogs-remediationRole, Role::SO0111-EncryptRDSSnapshot, Role::SO0111-MakeEBSSnapshotsPrivate, Role::SO0111-MakeRDSSnapshotPrivate, Role::SO0111-RDSMonitoring-remediationRole, Role::SO0111-RemoveLambdaPublicAccess, Role::SO0111-RemoveVPCDefaultSecurityGroupRules, Role::SO0111-ReplaceCodeBuildClearTextCredentials, Role::SO0111-RevokeUnrotatedKeys, Role::SO0111-RevokeUnusedIAMUserCredentials, Role::SO0111-S3BlockDenylist, Role::SO0111-SetIAMPasswordPolicy, Role::SO0111-SetSSLBucketPolicy, Role::SO0111-SHARR-Orchestrator-Member, Role::SpringClean-XUG3HH5R-AutoUpdateElevatedRole-1IM6AYMGMCA35, Role::SpringClean-XUG3HH5R-AutoUpdateRole-20LWKR871KYY, Role::SpringClean-XUG3HH5R-FeatureCheckerFunctionRole-1AH36Y9VYP822, Role::SpringClean-XUG3HH5R-SesVerifyEmailFunctionRole-1TXMG47957RRG, Role::SpringClean-XUG3HH5R-SpringCleanRole-LMVT7YWUT75Y, Role::SpringClean-XUG3HH5R-SpringCleanStackSetAdministra-QIMZ48DM5OFV, Role::SpringClean-XUG3HH5R-SpringCleanStackSetExecutionR-D9DWX0EX1ZOA, Role::testCarbonRole, Role::TurtleRoleManagement, Role::vpcflowCWrole
AWS Docs
IAM.3Compliant
[hasAccessKeyNoRotate90days]
IAM.4Compliant
[rootHasAccessKey]
IAM.5Compliant
[mfaActive]
IAM.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
IAM.7Compliant
[passwordPolicyWeak]
IAM.8Compliant
[consoleLastAccess90]
[consoleLastAccess365]
IAM.9Need Attention
[rootMfaActive] - Enable MFA on root user
  • [GLOBAL]User::root_id
AWS MFA
IAM Best Practices
IAM.19Compliant
[mfaActive]
IAM.21Need Attention
[ManagedPolicyFullAccessOneServ] - Limit permissions.
  • [GLOBAL]Role::AthenaCURdailyStack-AWSCURCrawlerComponentFunction-XX4CHL7H96MD, Role::AthenaCURMonthlyStack-AWSCURCrawlerComponentFuncti-1AJFUSIA0NX5X, Role::AWSReservedSSO_AWSPowerUserAccess_00098b9536c9ffa7, Role::Cloud-Intelligence-Dashbo-ProcessPathLambdaExecutio-4v29TjzrvQTv, Role::Cloud-Intelligence-Dashboar-InitLambdaExecutionRole-ZassKR4B4CY8, Role::Cloud-Intelligence-Dashboards-CidCURCrawlerRole-6n5acUHm6w0r, Role::CURathenaStack-AWSCURCrawlerComponentFunction-Y25X9I4YKV02, Role::MarketplaceFullAccess, Role::OrthancRole
AWS Docs
Kinesis.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
KMS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
KMS.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
KMS.3Compliant
[KeyInPendingDeletion]
KMS.4Need Attention
[KeyRotationEnabled] - Enable Key Rotation
  • [ap-southeast-1]5d1b8bdf-8f89-42e1-85be-32f95811c17d
  • [us-east-1]a2b67230-2e44-41c3-9176-ae9abaa920a0
Enable CMK Rotation
Lambda.1Compliant
[lambdaPublicAccess]
Lambda.2Compliant
[lambdaRuntimeUpdate]
Lambda.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Lambda.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Macie.1Need Attention
[MacieToEnable] - Enable Macie
  • [ap-northeast-1]Macie
  • [ap-northeast-2]Macie
  • [ap-northeast-3]Macie
  • [ap-south-1]Macie
  • [ap-southeast-2]Macie
  • [ca-central-1]Macie
  • [eu-central-1]Macie
  • [eu-north-1]Macie
  • [eu-west-1]Macie
  • [eu-west-2]Macie
  • [eu-west-3]Macie
  • [sa-east-1]Macie
  • [us-east-1]Macie
  • [us-east-2]Macie
  • [us-west-1]Macie
  • [us-west-2]Macie
Getting started with Amazon Macie
Macie.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
MSK.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
MSK.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
MQ.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
MQ.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Neptune.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
NetworkFirewall.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Opensearch.1Compliant
[EncyptionAtRest]
Opensearch.2Compliant
[DomainWithinVPC]
Opensearch.3Compliant
[NodeToNodeEncryption]
Opensearch.4Compliant
[ApplicationLogs]
Opensearch.5Compliant
[AuditLogs]
Opensearch.6Compliant
[DataNodes]
Opensearch.7Compliant
[FineGrainedAccessControl]
Opensearch.8Compliant
[TLSEnforced]
Opensearch.10Compliant
[ServiceSoftwareVersion]
PCA.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.1Compliant
[SnapshotRDSIsPublic]
RDS.2Compliant
[PubliclyAccessible]
RDS.3Compliant
[StorageEncrypted]
RDS.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.5Need Attention
[MultiAZ] - Enable MultiAZ
  • [us-east-1]aurora-mysql::Cluster=myaurora-mysql-ww
What Is MultiAZ
Guide
RDS.6Need Attention
[EnhancedMonitor] - Enable Enhanced Monitoring
  • [us-east-1]aurora-mysql::Cluster=myaurora-mysql-ww
Enable Enhanced Monitoring
RDS.7Compliant
[DeleteProtection]
RDS.8Compliant
[DeleteProtection]
RDS.9Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.10Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.11Compliant
[Backup]
RDS.12Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.13Compliant
[AutoMinorVersionUpgrade]
RDS.14Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.15Need Attention
[MultiAZ] - Enable MultiAZ
  • [us-east-1]aurora-mysql::Cluster=myaurora-mysql-ww
What Is MultiAZ
Guide
RDS.16Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.17Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.18Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.19Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.20Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.21Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.22Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.23Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.24Need Attention
[DefaultMasterAdmin] - Rename Admin
  • [us-east-1]aurora-mysql::Cluster=myaurora-mysql-ww
RDS Master Accounts
RDS.25Need Attention
[DefaultMasterAdmin] - Rename Admin
  • [us-east-1]aurora-mysql::Cluster=myaurora-mysql-ww
RDS Master Accounts
RDS.26Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.27Compliant
[StorageEncrypted]
RDS.34Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
RDS.35Compliant
[AutoMinorVersionUpgrade]
Redshift.1Compliant
[PubliclyAcessible]
Redshift.2Compliant
[EncryptedInTransit]
Redshift.3Compliant
[AutomaticSnapshots]
Redshift.4Compliant
[AuditLogging]
Redshift.6Compliant
[AutomaticUpgrades]
Redshift.7Compliant
[EnhancedVPCRouting]
Redshift.8Compliant
[DefaultAdminUsername]
Redshift.9Compliant
[DefaultDatabaseName]
Redshift.10Compliant
[EncryptedAtRest]
Route53.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
S3.1Compliant
[S3AccountPublicAccessBlock]
S3.2Compliant
[PublicAccessBlock]
S3.3Compliant
[PublicAccessBlock]
S3.5Need Attention
[TlsEnforced] - Enforce Encryption of Data in Transit
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
S3.7Compliant
[CrossRegionReplication]
S3.8Compliant
[PublicAccessBlock]
S3.9Need Attention
[BucketLogging] - Enable Server Access Logging
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
S3.10Need Attention
[BucketVersioning] - Enable Versioning
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
[BucketLifecycle] - Configure Lifecycle Policies
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
Manage Versioning Example
AWS Docs
S3.11Need Attention
[EventNotification] - Enable Event Notification
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
S3.12Need Attention
[AccessControlList] - Enable SSE
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
Protecting data with IAM
S3.13Need Attention
[BucketLifecycle] - Configure Lifecycle Policies
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
S3.14Need Attention
[BucketVersioning] - Enable Versioning
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
Manage Versioning Example
S3.15Need Attention
[ObjectLock] - Enable Object Lock
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
AWS Docs
S3.17Compliant
[ServerSideEncrypted]
[SSEWithKMS]
S3.19Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
S3.20Need Attention
[MFADelete] - Enable MFA Delete
  • [ap-southeast-1]Bucket::aws-athena-query-results-769655955296-ap-southeast-1, Bucket::aws-cloudtrail-logs-769655955296-b457067d, Bucket::cf-templates-axtacndawvmi-ap-southeast-1, Bucket::config-bucket-769655955296, Bucket::tgw-flow-log-s3, Bucket::wwcurbucket, Bucket::wws3inventory
  • [us-east-1]Bucket::aws-athena-query-results-cid-769655955296-us-east-1, Bucket::cf-templates-axtacndawvmi-us-east-1, Bucket::cid-769655955296-shared, Bucket::cloudtrail-awslogs-769655955296-fhklab3h-isengard-do-not-delete, Bucket::sagemaker-studio-769655955296-hn1cxm2eq5, Bucket::sagemaker-studio-edt80ljq4, Bucket::sagemaker-studio-nifj1w84os, Bucket::sagemaker-us-east-1-769655955296, Bucket::security-hub-format-s3bucketname-7uxkruwhbbhe, Bucket::securityhubcsvmanagerstac-securityhubexportbucket0-a2e5yuo0rpvs, Bucket::testcurver2bucket, Bucket::wwsagemakerbucket
  • [us-west-2]Bucket::do-not-delete-gatedgarden-audit-769655955296
Prevention for Accidental Deletions on S3
AWS Docs
Sagemaker.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Sagemaker.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
Sagemaker.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SecretsManager.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SecretsManager.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SecretsManager.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SecretsManager.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SNS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SQS.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SSM.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SSM.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SSM.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
SSM.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.1Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.2Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.3Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.4Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.5Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.6Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.7Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.8Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.10Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.11Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.
WAF.12Not availablePlease refer to the NIST control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective NIST control.