AWS Services

Ensure CloudFront Origin Access Identity Enabled
Description: An Origin Access Identity (OAI) is used for sharing private content via CloudFront. The OAI is a virtual user identity that will be used to gi...
Mon, 27 Mar, 2023 at 8:42 AM
Ensure Amazon Elasticsearch Encrypted at Rest
Description:  Elasticsearch Service(ES) is a managed service that makes it easy to deploy, operate, and scale Elasticsearch, a popular open-source search, ...
Tue, 28 Mar, 2023 at 3:45 AM
Ensure Cloud Watch Log Groups Encryption Enabled
Description: AWS Cloud Watch Logs is a web service that stores logs from various AWS services, including Lambda function runs and ECS tasks. A log group is...
Wed, 30 Mar, 2022 at 4:09 AM
Ensure Secrets Manager Rotation Enabled
Description:  This policy checks whether AWS Secrets Manager secret has rotation enabled. The rule also checks an optional maximumAllowedRotationFrequency ...
Wed, 6 Oct, 2021 at 2:24 AM
Ensure Secrets Manager Scheduled Rotation was Enabled
Description: Secrets Manager enables you to replace hardcoded credentials in your code, including passwords, with an API call to Secrets Manager to retriev...
Wed, 29 Mar, 2023 at 1:45 AM
Ensure Secrets Manager Secrets are Encrypted with KMS
Description: Secrets Manager uses envelope encryption with AWS KMS keys and data keys to protect each secret value. Whenever the secret value secret change...
Tue, 4 Apr, 2023 at 8:20 AM
Ensure Amazon Elasticsearch In VPC (Not Public) Check
Description: Elasticsearch is a distributed search and analytics engine built on Apache Lucene. It is the most popular search engine and is commonly used f...
Mon, 27 Mar, 2023 at 7:51 AM
Ensure ELB Cross AZ Load Balancing Enabled
Description: Elastic Load Balancing automatically distributes incoming applications traffic across multiple targets, such as Amazon EC2 instances, containe...
Tue, 21 Mar, 2023 at 8:52 AM
Ensure SageMaker Endpoint KMS Encryption Enabled
Description: Amazon SageMaker is a fully managed machine learning service. With SageMaker, data scientists and developers can quickly and easily build and ...
Thu, 28 Oct, 2021 at 12:55 AM
Ensure API Gateway has logging enabled
DESCRIPTION: Enabling the custom access logging option in API Gateway allows delivery of custom logs to Cloud Watch Logs, which can be analyzed using Cloud...
Fri, 31 Mar, 2023 at 9:00 AM