AWS New Checks

Ensure Default Action for Full Packets in Network Firewall is Set to Drop or Forward
Profile Applicability Level 1 Description: In AWS, Network Firewalls provide essential traffic filtering between VPCs, subnets, and external networks. ...
Mon, 15 Sep, 2025 at 10:38 AM
Ensure Default Action for Fragmented Packets is Set to Drop or Forward
Profile Applicability Level 1 Description: In a network, fragmented packets are packets that have been split into smaller pieces for transmission acros...
Mon, 15 Sep, 2025 at 7:23 AM
Ensure CloudFront Distributions Have Origin Failover Enabled
Profile Applicability: Level 2 Description Amazon CloudFront origin failover ensures high availability by automatically switching to a secondary origin if...
Wed, 10 Sep, 2025 at 1:09 AM
Ensure EFS Access Points Should Enforce a Root Directory
Profile Applicability: Level 1 Description: Amazon Elastic File System (EFS) provides scalable and elastic network file storage that can be used with...
Thu, 11 Sep, 2025 at 3:56 AM
Ensure CloudFront Distributions Use Custom SSL/TLS Certificates
Profile Applicability:  Level 2 Description Using custom SSL/TLS certificates for Amazon CloudFront distributions enhances security by ensuring that your ...
Wed, 10 Sep, 2025 at 1:21 AM
Ensure Deletion Protection Safety Feature is Enabled for Amazon VPC Network Firewalls
Profile Applicability: Level 1 Description: Amazon VPC Network Firewalls are essential for protecting your network and controlling traffic between your...
Mon, 15 Sep, 2025 at 7:09 AM
Ensure Network Firewall Logging is Enabled
Profile Applicability: Level 1 Description: AWS Network Firewall is a managed network security service that provides protection for your Amazon Virtual...
Mon, 15 Sep, 2025 at 7:09 AM
Ensure All Network Firewall Firewalls Are Deployed Across Multiple Availability Zones (AZs)
Profile Applicability: Level 1 Description: AWS Network Firewall is a managed network security service that protects your Amazon Virtual Private Cloud ...
Mon, 15 Sep, 2025 at 6:57 AM
Ensure CloudFront Distributions Do Not Point to Non-Existent S3 Origins Without Static Website Hosting
Profile Applicability:  Level 2 Description Amazon CloudFront distributions should be correctly configured to point to existing S3 origins with static we...
Wed, 10 Sep, 2025 at 1:29 AM
Check if Internet-Facing Application Load Balancers Are Protected by AWS Shield Advanced
Profile Applicability: Level 1 Description: Application Load Balancers (ALBs) are used to distribute incoming application traffic across multiple targe...
Tue, 25 Mar, 2025 at 2:52 AM