Policy Updates

Ensure session disconnect timeout is set to 5 minutes or less.
Description: This policy ensures that users' AWS sessions are disconnected after 5 minutes of inactivity. This helps to mitigate the risk of unauthoriz...
Thu, 20 Jul, 2023 at 12:11 PM
Ensure session idle disconnect timeout is set to 10 minutes or less.
Description: This policy ensures that users' AWS sessions are disconnected after 10 minutes of inactivity. This helps to mitigate the risk of unauthori...
Thu, 20 Jul, 2023 at 12:13 PM
Ensure default Internet Access from your Amazon AppStream fleet streaming instances should remain unchecked.
Description: This policy ensures that default Internet Access is unchecked for Amazon AppStream fleet streaming instances. This helps to mitigate the risk ...
Thu, 20 Jul, 2023 at 12:15 PM
Ensure ECR repositories have lifecycle policies enabled
Description: This policy ensures that lifecycle policies are enabled for all Amazon Elastic Container Registry (ECR) repositories. This helps to mitigate t...
Thu, 20 Jul, 2023 at 12:17 PM
Ensure CodeArtifact internal packages do not allow external public source publishing
Description: This policy ensures that CodeArtifact internal packages do not allow external public source publishing. This helps to mitigate the risk of sen...
Thu, 20 Jul, 2023 at 12:20 PM
Ensure there are no secrets in EC2 Auto Scaling Launch Configuration
Description: This policy ensures that there are no secrets in EC2 Auto Scaling Launch Configuration. This helps to mitigate the risk of sensitive informati...
Thu, 20 Jul, 2023 at 12:22 PM
Ensure VPC security groups not wide-open public IPv4 CIDR ranges (non-RFC1918)
Description: This policy ensures that VPC security groups do not allow ingress traffic from public IPv4 CIDR ranges (non-RFC1918). This helps to mitigate t...
Thu, 20 Jul, 2023 at 12:24 PM
Ensure Amazon OpenSearch Service domains (formerly known as Elasticsearch or ES) has either Amazon Cognito authentication or SAML authentication for Kibana enabled
Description: Amazon OpenSearch Service (OpenSearch) domains use Kibana as the default web interface for managing and exploring data. Kibana can be accessed...
Thu, 20 Jul, 2023 at 12:27 PM
Ensure Amazon Elasticsearch Service (ES) domains has encryption at-rest enabled
Description: Amazon Elasticsearch Service (ES) domains store data on disk. If this data is not encrypted, it could be accessed by unauthorized users if the...
Thu, 20 Jul, 2023 at 12:30 PM
Ensure Amazon Elasticsearch Service (ES) domains has node-to-node encryption enabled
Description: Amazon Elasticsearch Service (ES) domains use node-to-node encryption to protect data in transit between nodes in a cluster. If node-to-node e...
Thu, 20 Jul, 2023 at 2:07 PM