Foundational Technical Review
Assesses an AWS Partner's solution against a specific set of Amazon Web Services (AWS) best practices around security, performance, and operational processes that are most critical for customer success.
Read more
Read more
Summary: [Not available:37] | [Compliant:9] | [Need Attention:7]
Breakdown
Framework. Foundational Technical Review
Category | Rule ID | Compliance Status | Description | Reference |
---|---|---|---|---|
Partner hosted | HOST-001 | Not available | ||
Support level | SUP-001 | Need Attention |
| AWS Support Plan Guide |
Architecture review | WAFR-001 | Not available | ||
Architecture review | WAFR-002 | Not available | ||
AWS root account | ARC-001 | Not available | ||
AWS root account | ARC-002 | Not available | ||
AWS root account | ARC-003 | Need Attention |
| AWS MFA IAM Best Practices |
AWS root account | ARC-004 | Compliant |
| |
AWS root account | ARC-005 | Not available | ||
Communications from AWS | ACOM-001 | Need Attention |
| Alternate Contact |
Communications from AWS | ACOM-002 | Not available | ||
AWS CloudTrail | CTL-001 | Not available | ||
AWS CloudTrail | CTL-002 | Not available | ||
AWS CloudTrail | CTL-003 | Not available | ||
AWS CloudTrail | CTL-004 | Not available | ||
Identity and Access Management | IAM-001 | Compliant |
| |
Identity and Access Management | IAM-002 | Compliant |
| |
Identity and Access Management | IAM-003 | Need Attention |
| IAM Password Policy |
Identity and Access Management | IAM-004 | Compliant |
| |
Identity and Access Management | IAM-005 | Not available | ||
Identity and Access Management | IAM-006 | Need Attention |
| AWS Docs AWS Docs AWS Docs Organization GuardRail Blog |
Identity and Access Management | IAM-007 | Need Attention |
| AWS Blog |
Identity and Access Management | IAM-008 | Not available | ||
Identity and Access Management | IAM-009 | Not available | ||
Identity and Access Management | IAM-010 | Not available | ||
Identity and Access Management | IAM-011 | Not available | ||
Identity and Access Management | IAM-012 | Compliant |
| |
Operational security | SECOPS-001 | Not available | ||
Network security | NETSEC-001 | Compliant |
| |
Network security | NETSEC-002 | Not available | ||
Backups and recovery | BAR-001 | Compliant |
| |
Backups and recovery | BAR-002 | Not available | ||
Resiliency | RES-001 | Not available | ||
Resiliency | RES-002 | Not available | ||
Resiliency | RES-003 | Not available | ||
Resiliency | RES-004 | Not available | ||
Resiliency | RES-005 | Not available | ||
Resiliency | RES-006 | Not available | ||
Resiliency | RES-007 | Not available | ||
Amazon S3 bucket access | S3-001 | Not available | ||
Amazon S3 bucket access | S3-002 | Compliant |
| |
Amazon S3 bucket access | S3-003 | Not available | ||
Cross-account access | CAA-001 | Not available | ||
Cross-account access | CAA-002 | Not available | ||
Cross-account access | CAA-003 | Not available | ||
Cross-account access | CAA-004 | Not available | ||
Cross-account access | CAA-005 | Not available | ||
Cross-account access | CAA-006 | Not available | ||
Cross-account access | CAA-007 | Not available | ||
Sensitive data | SDAT-001 | Not available | ||
Sensitive data | SDAT-002 | Compliant |
| |
Sensitive data | SDAT-003 | Need Attention |
| Data protection in Amazon EC2 AWS Docs |
Regulatory compliance validation process | RCVP-001 | Not available |