CloudTrail. | 1 | Compliant | - [NeedToEnableCloudTrail]
- [HasOneMultiRegionTrail]
| |
CloudTrail. | 2 | Need Attention | - [RequiresKmsKey] - Enable SSE
- [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
| Encrypt CloudTrail using AWS KMS CloudTrail Security Best Practices |
CloudTrail. | 4 | Compliant | - [LogFileValidationEnabled]
| |
CloudTrail. | 5 | Need Attention | - [CloudWatchLogsLogGroupArn] - CloudWatch for CloudTrail
- [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
| Using CloudWatch Logs with CloudTrail |
CloudTrail. | 6 | Compliant | - [EnableS3PublicAccessBlock]
| |
CloudTrail. | 7 | Need Attention | - [EnableTrailS3BucketLogging] - Enable S3 Bucket Logging
- [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
| Configure S3 Logging Resilience in CloudTrail |
CloudWatch. | 1 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAroot1]
| CIS Cloudwatch Controls |
CloudWatch. | 4 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAalarm4]
| CIS Cloudwatch Controls |
CloudWatch. | 5 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMATrail5]
| CIS Cloudwatch Controls |
CloudWatch. | 6 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAAuthFail6]
| CIS Cloudwatch Controls |
CloudWatch. | 7 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMACMK7]
| CIS Cloudwatch Controls |
CloudWatch. | 8 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAS3Policy8]
| CIS Cloudwatch Controls |
CloudWatch. | 9 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAConfig9]
| CIS Cloudwatch Controls |
CloudWatch. | 10 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMASecGroup10]
| CIS Cloudwatch Controls |
CloudWatch. | 11 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMANACL11]
| CIS Cloudwatch Controls |
CloudWatch. | 12 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAGateway12]
| CIS Cloudwatch Controls |
CloudWatch. | 13 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMARouteTable13]
| CIS Cloudwatch Controls |
CloudWatch. | 14 | Need Attention | - [NeedToEnableCloudTrail]
- [trailWithoutCWLogs] - CloudTrail to have CloudWatch Log
- [us-east-1]ctLog::arn:aws:cloudtrail:us-east-1:961319563195:trail/IsengardTrail-DO-NOT-DELETE
- [trailWithCWLogsWithoutMetrics]
- [trailWOMAVPC14]
| CIS Cloudwatch Controls |
Config. | 1 | Need Attention | - [EnableConfigService]
- [PartialEnableConfigService] - Enable AWS Config
| Enable AWS Config |
EC2. | 2 | Need Attention | - [SGDefaultDisallowTraffic] - Default Security Group with Rules
- [ap-southeast-1]SG::sg-34753642
- [us-east-1]SG::sg-9b3e45a4
| VPC default security group rules |
EC2. | 6 | Need Attention | - [VPCFlowLogEnabled] - Enable VPC Flow Log
- [ap-southeast-1]VPC::vpc-0229dd64
- [us-east-1]VPC::vpc-8d976df0
| Amazon Elastic Compute Cloud controls |
EC2. | 7 | Compliant | - [EBSEncrypted]
| |
EC2. | 21 | Compliant | - [NACLSensitivePort]
| |
IAM. | 1 | Need Attention | - [FullAdminAccess] - Limit permissions.
- [GLOBAL]Role::AWSReservedSSO_AWSAdministratorAccess_fae89f7963febc98, Role::DojoEC2AdminRole, Role::EC2AdminRole, Role::itadmin, Role::OrganizationAccountAccessRole, Role::PACICloudFormationStackSetExecutionRole, Role::ServiceScreenerAutomationRole, Role::stacksets-exec-7ca18804340a75b25a831ca17fba8659
| AWS Docs Organization GuardRail Blog |
IAM. | 3 | Compliant | - [hasAccessKeyNoRotate90days]
| |
IAM. | 4 | Compliant | - [rootHasAccessKey]
| |
IAM. | 5 | Compliant | - [mfaActive]
| |
IAM. | 9 | Need Attention | - [rootMfaActive] - Enable MFA on root user
| AWS MFA IAM Best Practices |
IAM. | 15 | Compliant | - [passwordPolicyLength]
| |
IAM. | 16 | Compliant | - [passwordPolicyReuse]
| |
IAM. | 18 | Not available | Please refer to the CIS control section for further details. Kindly provide evidence or artifacts demonstrating compliance with the respective CIS control. | |
IAM. | 22 | Compliant | - [consoleLastAccess45]
- [consoleLastAccess90]
- [consoleLastAccess365]
| |
KMS. | 4 | Compliant | - [KeyRotationEnabled]
| |
RDS. | 3 | Compliant | - [StorageEncrypted]
| |
S3. | 1 | Compliant | - [S3AccountPublicAccessBlock]
| |
S3. | 5 | Need Attention | - [TlsEnforced] - Enforce Encryption of Data in Transit
- [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
- [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
| AWS Docs |
S3. | 8 | Compliant | - [PublicAccessBlock]
| |
S3. | 20 | Need Attention | - [MFADelete] - Enable MFA Delete
- [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
- [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
| Prevention for Accidental Deletions on S3 AWS Docs |