SPIP

AWS Security Posture Improvement Program(SPIP)

Encompasses a thorough review across six critical phases of cloud security posture management: Infrastructure Protection and Visibility, Identity Protection, Asset Management, Detection & Mitigation, DevSecOps, and Centralization.
Read more

Summary: [Not available:10] | [Compliant:9] | [Need Attention:11]

Breakdown

Framework. AWS Security Posture Improvement Program(SPIP)

CategoryRule IDCompliance StatusDescriptionReference
Identity ProtectionP1.1Need Attention
[rootMfaActive] - Enable MFA on root user
  • [GLOBAL]User::root_id
[mfaActive]
AWS MFA
IAM Best Practices
Identity ProtectionP1.2Compliant
[hasAccessKeyNoRotate30days]
[hasAccessKeyNoRotate90days]
Identity ProtectionP1.3Need Attention
[passwordPolicy] - Set a custom password policy.
  • [GLOBAL]Account::Config
[passwordPolicyWeak]
[passwordPolicyReuse]
[passwordPolicyLength]
IAM Password Policy
Identity ProtectionP1.4Compliant
[hasSSORoles]
[hasExternalIdentityProvider]
Identity ProtectionP1.5Compliant
[SCPEnabled]
[hasOrganization]
Identity ProtectionP1.6Not available
Identity ProtectionP1.7Not available
Data ProtectionP2.1Compliant
[PublicAccessBlock]
[PublicReadAccessBlock]
[PublicWriteAccessBlock]
Data ProtectionP2.2Compliant
[EBSSnapshot]
[Backup]
[backupStatus]
[enabledContinuousBackup]
[AutomatedBackup]
[AutomaticSnapshots]
Data ProtectionP2.3Need Attention
[ServerSideEncrypted]
[SSEWithKMS]
[EBSEncrypted]
[EncryptedAtRest]
[StorageEncrypted]
[EncryptedAtRest]
[EncryptedWithKMS]
[fieldLevelEncryption] - Set-up field-level encryption for your CloudFront distributions.
  • [GLOBAL]Cloudfront::E2X390QMMYIRUF
[EncryptionAtRest]
[EncryptionInTransit]
AWS Docs
Data ProtectionP2.4Need Attention
[MacieToEnable] - Enable Macie
  • [ap-southeast-1]Macie
  • [us-east-1]Macie
Getting started with Amazon Macie
Data ProtectionP2.5Need Attention
[TlsEnforced]
[EncryptedInTransit]
[MSSQLorPG__TransportEncrpytionDisabled]
[NodeToNodeEncryption]
[TLSEnforced]
[EncInTransitAndRest]
[SGEncryptionInTransit] - Encryption in Transit
  • [ap-southeast-1]SG::sg-34753642
  • [us-east-1]SG::sg-9b3e45a4
[viewerPolicyHttps] - Configure one or more cache behaviors in your CloudFront distribution to require HTTPS for communication between viewers and CloudFront.
  • [GLOBAL]Cloudfront::E2X390QMMYIRUF
Data protection in Amazon EC2
AWS Docs
Infrastructure Protection and VisibilityP3.1Need Attention
[SGDefaultInUsed]
[SGSensitivePortOpenToAll]
[SGAllTCPOpen]
[SGAllUDPOpen]
[SGAllPortOpen] - All ports open.
  • [ap-southeast-1]SG::sg-34753642
  • [us-east-1]SG::sg-9b3e45a4
Best practices for Amazon EC2
Infrastructure Protection and VisibilityP3.2Need Attention
[WAFAssociation] - Use Web Application Firewall (WAF) for enhanced security.
  • [GLOBAL]Cloudfront::E2X390QMMYIRUF
AWS Docs
Developer Guide
Infrastructure Protection and VisibilityP3.3Need Attention
[defaultRootObject] - Specify a default root object for your distribution.
  • [GLOBAL]Cloudfront::E2X390QMMYIRUF
AWS Docs
Infrastructure Protection and VisibilityP3.4Not available
Infrastructure Protection and VisibilityP3.5Compliant
[SGSensitivePortOpenToAll]
Infrastructure Protection and VisibilityP3.6Compliant
[WAFWACL]
Detection & MitigationP4.1Compliant
[NeedToEnableCloudTrail]
[EnableCloudTrailLogging]
[LogFileValidationEnabled]
Detection & MitigationP4.2Need Attention
[UsageStat] - UsageStat
  • [ap-southeast-1]Detector::24ba5f8bf5889388602c37a54a1069fb
  • [us-east-1]Detector::c2ba5f8bde481aa20a05199471e24808
[Findings] - Findings
  • [ap-southeast-1]Detector::24ba5f8bf5889388602c37a54a1069fb
  • [us-east-1]Detector::c2ba5f8bde481aa20a05199471e24808

Detection & MitigationP4.3Need Attention
[EnableTrailS3BucketLogging] - Enable S3 Bucket Logging
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
Configure S3 Logging
Resilience in CloudTrail
Detection & MitigationP4.4Need Attention
[EnableTrailS3BucketMFADelete] - Enable MFA delete
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
[EnableTrailS3BucketVersioning] - Enable S3 Bucket versioning
  • [ap-southeast-1]Cloudtrail::IsengardTrail-DO-NOT-DELETE
[MFADelete] - Enable MFA Delete
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
[BucketVersioning] - Enable Versioning
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
[ObjectLock] - Enable Object Lock
  • [ap-southeast-1]Bucket::aws-codestar-ap-southeast-1-961319563195, Bucket::aws-codestar-ap-southeast-1-961319563195-dojo-pipe, Bucket::codepipeline-ap-southeast-1-183991447891, Bucket::config-bucket-961319563195, Bucket::documentunderstandingsolutioncic-artifacts3bucket-dtr9a8q6yj2h, Bucket::documentunderstandingsolutioncicd-devoutputbucket-1m11zxjc9fhd6, Bucket::dojo-logs, Bucket::kuettai-solutions-bucket-ap-southeast-1
  • [us-east-1]Bucket::cloudtrail-awslogs-961319563195-pyvnhwtz-isengard-do-not-delete, Bucket::kuettai-dojo01
S3 Enable MFA Delete
Delete with MFA enabled file in S3
Configure S3 bucket versioning
Resilience in CloudTrail
Prevention for Accidental Deletions on S3
AWS Docs
AWS Docs
Manage Versioning Example
AWS Docs
Detection & MitigationP4.5Not available
Detection & MitigationP4.6Not available
Detection & MitigationP4.7Not available
AppSec & DevSecOpsP5.1Compliant
[DBwithoutSecretManager]
AppSec & DevSecOpsP5.2Not available
AppSec & DevSecOpsP5.3Not available
AppSec & DevSecOpsP5.4Not available
AppSec & DevSecOpsP5.5Not available