AWS New Checks

Ensure Unused Network Access Control Lists (NACLs) Are Removed
Profile Applicability:  Level 2 Description Network Access Control Lists (NACLs) are used to control inbound and outbound traffic at the subnet level in ...
Wed, 26 Mar, 2025 at 3:14 AM
Ensure Kafka Cluster Encryption at Rest Uses Customer Managed Keys (CMK)
Profile Applicability Level 2 Description Encryption at rest protects sensitive data stored in Kafka clusters by encrypting it on disk. Using Customer ...
Wed, 26 Mar, 2025 at 3:16 AM
Ensure Enhanced Monitoring is Enabled for MSK (Kafka) Brokers
Profile Applicability Level 2 Description Enhanced Monitoring for Amazon MSK brokers provides additional insights into the operations of your Kafka clu...
Wed, 26 Mar, 2025 at 3:22 AM
Ensure MSK Clusters Use the Latest Version
Profile Applicability Level 2 Description Amazon MSK supports multiple versions of Apache Kafka, and using the latest version ensures that your cluster...
Wed, 26 Mar, 2025 at 3:28 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Ports 20 or 21 (FTP)
Profile Applicability:  Level 2 Description TCP ports 20 and 21 are used for FTP (File Transfer Protocol) to transfer files over a network. Allowing unre...
Wed, 26 Mar, 2025 at 3:40 AM
Ensure Unassigned Elastic IPs Are Identified and Removed
Profile Applicability:  Level 2 Description Elastic IP addresses (EIPs) are public IPv4 addresses designed for use in Amazon Web Services (AWS). An EIP t...
Wed, 26 Mar, 2025 at 4:01 AM
Ensure Amazon EFS Protects Sensitive Data with Encryption at Rest
Profile Applicability: Level 1 Description: Amazon Elastic File System (EFS) provides scalable, elastic file storage for use with AWS Cloud services ...
Wed, 26 Mar, 2025 at 4:15 AM
Ensure no security groups allow ingress from 0.0.0.0/0 or ::/0 to high risk ports
Profile Applicability:  Level 2 Description: This check ensures that no security groups in your AWS environment allow ingress (incoming) traffic from 0.0...
Wed, 26 Mar, 2025 at 4:20 AM
Ensure Amazon EFS File Systems are Configured with Multi-AZ
Profile Applicability: Level 1 Description: Amazon Elastic File System (EFS) is a fully managed, scalable file storage service that provides storage ...
Wed, 26 Mar, 2025 at 4:29 AM
Find trust boundaries in VPC endpoint connections.
Profile Applicability: Level 1 Description: A VPC endpoint allows private connections between a VPC (Virtual Private Cloud) and supported AWS services ...
Wed, 26 Mar, 2025 at 4:38 AM