MSR

MSR baseline checks

At AWS, security is our top priority. Partner Migration Security Requirements (MSR) is an APJ Core team initiative to help our partners migrate their custom's workloads securely to AWS.

MSR details security requirements that partners should implement controls for, in line with 5 core security themes of identity and access management, 61 logging and monitoring, infrastructure security, data protection, and incident response. clubbed with additional best practices. MSR will be used by both internal stakeholders like Migration PSA's, relevant account teams and external stakeholders like consulting, migration, and GSI partners to elevate the security posture of workloads being migrated to cloud and ensure ongoing elevated security posture.
Read more

Summary: [Not available:34] | [Compliant:20] | [Need Attention:15]

Breakdown

Framework. MSR baseline checks

CategoryRule IDCompliance StatusDescriptionReference
CW.1Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
CW.2Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
CW.3Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
CW.4Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
CD.1Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IAM.1Need Attention
[ManagedPolicyFullAccessOneServ] - Limit permissions.
  • [GLOBAL]Role::CodeStarWorker-dojo-ToolChain, Role::OrthancRole
[FullAdminAccess] - Limit permissions.
  • [GLOBAL]Role::AWSReservedSSO_AWSAdministratorAccess_fae89f7963febc98, Role::DojoEC2AdminRole, Role::EC2AdminRole, Role::itadmin, Role::OrganizationAccountAccessRole, Role::PACICloudFormationStackSetExecutionRole, Role::ServiceScreenerAutomationRole, Role::stacksets-exec-7ca18804340a75b25a831ca17fba8659
[InlinePolicyFullAccessOneServ] - Limit access in policy
  • [GLOBAL]Role::Cognito_dojoIdPAuth_Role, Role::Cognito_dojoIdPUnauth_Role
[InlinePolicyFullAdminAccess]
AWS Docs
AWS Docs
Organization GuardRail Blog
AWS Docs
IAM.2Compliant
[rootConsoleLogin30days]
[rootConsoleLoginFail3x]
IAM.3Compliant
[rootHasAccessKey]
IAM.4Need Attention
[rootMfaActive] - Enable MFA on root user
  • [GLOBAL]User::root_id
AWS MFA
IAM Best Practices
IAM.5Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IAM.6Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
DP.1Need Attention
[MacieToEnable] - Enable Macie
  • [ap-southeast-1]Macie
  • [us-east-1]Macie
Getting started with Amazon Macie
DP.2Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
DP.3Compliant
[PublicAccessBlock]
DP.4Need Attention
[BucketVersioning] - Enable Versioning
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
AWS Docs
Manage Versioning Example
DP.5Need Attention
[MFADelete] - Enable MFA Delete
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
Prevention for Accidental Deletions on S3
AWS Docs
DP.6Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
DP.7Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
DP.8Compliant
[DBwithoutSecretManager]
[DBwithSomeSecretsManagerOnly]
[Secret__NoRotation]
[Secret__NotUsed7days]
DP.9Compliant
[ServerSideEncrypted]
DP.10Compliant
[lambdaPublicAccess]
DP.11Compliant
[KeyRotationEnabled]
DP.12Compliant
[AdminIsGrantor]
DP.13Compliant
[SnapshotRDSIsPublic]
[snapshotEBSIsPublic]
DP.14Compliant
[ELBSGRulesMatch]
DP.15Compliant
[SQLServerEOL]
DP.16Compliant
[PubliclyAccessible]
[SecurityGroupIPRangeNotPrivateCidr]
LM.1Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
LM.2Compliant
[NeedToEnableCloudTrail]
LM.3Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
LM.4Need Attention
[CloudWatchLogsLogGroupArn] - CloudWatch for CloudTrail
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
Using CloudWatch Logs with CloudTrail
LM.5Compliant
[HasOneMultiRegionTrail]
LM.6Need Attention
[MacieToEnable] - Enable Macie
  • [ap-southeast-1]Macie
  • [us-east-1]Macie
Getting started with Amazon Macie
LM.7Need Attention
[EnableTrailS3BucketLogging] - Enable S3 Bucket Logging
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
Configure S3 Logging
Resilience in CloudTrail
LM.8Need Attention
[EnableTrailS3BucketMFADelete] - Enable MFA delete
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
S3 Enable MFA Delete
Delete with MFA enabled file in S3
LM.9Compliant
[ServerSideEncrypted]
LM.10Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
LM.11Need Attention
[supportPlanLowTier] - Subscribe to the AWS Business Support tier (or higher)
  • [GLOBAL]Account::Config
AWS Support Plan
Guide
LM.12Need Attention
[BucketLogging] - Enable Server Access Logging
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
AWS Docs
LM.13Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
LM.14Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
LM.15Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.1Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.2Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.3Compliant
[enableGuardDuty]
IP.4Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.5Compliant
[EC2InstanceAutoPublicIP]
IP.6Compliant
[EC2SubnetAutoPublicIP]
IP.7Need Attention
[WAFAssociation] - Use Web Application Firewall (WAF) for enhanced security.
  • [GLOBAL]Cloudfront::E2X390QMMYIRUF
[ELBEnableWAF]
AWS Docs
Developer Guide
IP.8Need Attention
[EnableTrailS3BucketMFADelete] - Enable MFA delete
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
S3 Enable MFA Delete
Delete with MFA enabled file in S3
IP.9Compliant
[DBwithoutSecretManager]
[DBwithSomeSecretsManagerOnly]
[Secret__NoRotation]
[Secret__NotUsed7days]
IP.10Need Attention
[SGDefaultDisallowTraffic] - Default Security Group with Rules
  • [ap-southeast-1]SG::sg-34753642
  • [us-east-1]SG::sg-9b3e45a4
[SecurityGroupDefault]
VPC default security group rules
IP.11Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.12Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.13Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.14Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IP.15Compliant
[ASGIMDSv2]
IP.16Need Attention
[lambdaRuntimeUpdate] - Runtime Update Available
  • [ap-southeast-1]Lambda::isengard-create-vpc-endpoints-for-ssm, Lambda::webScrapNew, Lambda::webScrapper, Lambda::isengard-create-inventory-association, Lambda::testFunction, Lambda::isengard-set-default-instance-role, Lambda::isengard-set-default-patch-baseline
  • [us-east-1]Lambda::isengard-set-default-instance-role, Lambda::isengard-create-vpc-endpoints-for-ssm, Lambda::isengard-set-default-patch-baseline, Lambda::isengard-create-inventory-association
Lambda runtimes
IR.1Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.2Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.3Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.4Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.5Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.6Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.7Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.8Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.9Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.10Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.
IR.11Not availablePlease refer to the Partner Security Requirement (PSR) ID section for further details in the main sheet in the Partner Migration Security Requirements (MSR) sheet. Kindly upload the artefacts in the Artefacts tabs in the MSR sheet corresponding to the respective PSR ID.