AWS New Checks

Ensure Default Action for Full Packets in Network Firewall is Set to Drop or Forward
Profile Applicability Level 1 Description: In AWS, Network Firewalls provide essential traffic filtering between VPCs, subnets, and external networks. ...
Tue, 25 Mar, 2025 at 1:42 AM
Ensure Default Action for Fragmented Packets is Set to Drop or Forward
Profile Applicability Level 1 Description: In a network, fragmented packets are packets that have been split into smaller pieces for transmission acros...
Tue, 25 Mar, 2025 at 1:50 AM
Ensure CloudFront Distributions Have Origin Failover Enabled
Profile Applicability: Level 2 Description Amazon CloudFront origin failover ensures high availability by automatically switching to a secondary origin if...
Tue, 25 Mar, 2025 at 1:52 AM
Ensure EFS Access Points Should Enforce a Root Directory
Profile Applicability: Level 1 Description: Amazon Elastic File System (EFS) provides scalable and elastic network file storage that can be used with...
Fri, 23 May, 2025 at 3:14 AM
Ensure CloudFront Distributions Use Custom SSL/TLS Certificates
Profile Applicability: Level 2 Description Using custom SSL/TLS certificates for Amazon CloudFront distributions enhances security by ensuring that your u...
Tue, 25 Mar, 2025 at 2:31 AM
Ensure Deletion Protection Safety Feature is Enabled for Amazon VPC Network Firewalls
Profile Applicability: Level 1 Description: Amazon VPC Network Firewalls are essential for protecting your network and controlling traffic between your...
Tue, 25 Mar, 2025 at 2:31 AM
Ensure Network Firewall Logging is Enabled
Profile Applicability: Level 1 Description: AWS Network Firewall is a managed network security service that provides protection for your Amazon Virtual...
Tue, 25 Mar, 2025 at 2:38 AM
Ensure All Network Firewall Firewalls Are Deployed Across Multiple Availability Zones (AZs)
Profile Applicability: Level 1 Description: AWS Network Firewall is a managed network security service that protects your Amazon Virtual Private Cloud ...
Tue, 25 Mar, 2025 at 2:46 AM
Ensure CloudFront Distributions Do Not Point to Non-Existent S3 Origins Without Static Website Hosting
Profile Applicability:  Level 2 Description Amazon CloudFront distributions should be correctly configured to point to existing S3 origins with static we...
Tue, 25 Mar, 2025 at 2:46 AM
Check if Internet-Facing Application Load Balancers Are Protected by AWS Shield Advanced
Profile Applicability: Level 1 Description: Application Load Balancers (ALBs) are used to distribute incoming application traffic across multiple targe...
Tue, 25 Mar, 2025 at 2:52 AM