LAMBDA

17

Resources

124

Total Findings

221

Rules Executed

15

Unique Rules

0

Exception

23.168s

Timespent

Summary

Filter

lambdaReservedConcurrencyDisabled

Performance Efficiency

lambdaRoleReused

Security
Description
Execution Role Reused: 2 of your Lambda function is having the same execution role. Please create isolated execution role to provide least privilege permission to the Lambda function.
Resources
us-east-1: Lambda::SecHubExportStack_545171356966_sh_csv_exporter | Lambda::SecHubExportStack_545171356966_sh_csv_updater
Label
Testing Required
Recommendation
Lambda execution role
Detail
ap-southeast-1

1. AthenaCURMonthlyStack-AWSS3CURNotification-q651HK0jLpgE

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

2. AthenaCURdailyStack-AWSCURInitializer-vLgwN5me52VP

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

3. CURathenaStack-AWSCURInitializer-WmxJnth9Od47

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

4. AthenaCURdailyStack-AWSS3CURNotification-t7HCb9uvReM9

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

5. CURathenaStack-AWSS3CURNotification-jTY5a4Z3lgcA

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

6. AthenaCURMonthlyStack-AWSCURInitializer-gyhMOAhcBfJE

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
us-east-1

7. CidCustomResourceDashboard

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days

8. CidProcessPath-DoNotRun

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

9. SpringClean-XUG3HH5R-FeatureCheckerFunction-3k0VXgENM2bp

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

10. cid-CID-Analytics

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

11. SecHubExportStack_545171356966_sh_csv_exporter

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaRoleReused arn:aws:iam::769655955296:role/SecurityHub_CSV_Exporter Execution Role Reused
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaNotInUsed30Days Function not in used for 30 days
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

12. SpringClean-XUG3HH5R-SpringCleanLambda-0qeMWlCDlvit

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

13. SendSecurityHubFullReportEmail

CheckCurrent ValueRecommendation
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled

14. SpringClean-XUG3HH5R-SesVerifyEmailFunction-IVk9Ime4YTt0

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

15. SecHubExportStack_545171356966_sh_csv_updater

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaRoleReused arn:aws:iam::769655955296:role/SecurityHub_CSV_Exporter Execution Role Reused
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

16. CidInitialSetup-DoNotRun

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled
lambdaNotInUsed30Days Function not in used for 30 days

17. SpringClean-XUG3HH5R-AutoUpdateLambda-snXPd3AyenOf

CheckCurrent ValueRecommendation
UseArmArchitecture x86_64 Use Arm64 Architecture
lambdaEnhancedMonitoringDisabled Disabled Enhanced Monitoring Disabled
lambdaCMKEncryptionDisabled Disabled Customer Managed Key Not In Used
lambdaTracingDisabled Disabled Tracing Disabled
lambdaCodeSigningDisabled Disabled Code Signing Disabled
lambdaReservedConcurrencyDisabled Disabled Provisioned Concurrency Disabled
lambdaDeadLetterQueueDisabled Disabled Dead Letter Queue Disabled