AWS New Checks

Ensure that AWS Organizations opt-out of AI services policy is enabled and disallow child-accounts to overwrite this policy
Profile Applicability: Level 1 Description: AWS Organizations provides the ability to manage and control access to AWS services across multiple account...
Thu, 27 Mar, 2025 at 4:28 AM
Check if AWS Regions are restricted with SCP policies
Profile Applicability: Level 1 Description: Service Control Policies (SCPs) are a feature of AWS Organizations that allow administrators to control the...
Thu, 27 Mar, 2025 at 4:37 AM
Ensure Network Policy is Enabled and Set as Appropriate
Profile Applicability: Level 1 Description: In Kubernetes, a Network Policy is a set of rules that controls the communication between pods and/or ser...
Thu, 27 Mar, 2025 at 4:41 AM
Ensure Kubernetes Secrets are encrypted using Customer Master Keys (CMKs)
Profile Applicability: Level 1 Description: In Kubernetes, Secrets are used to store and manage sensitive information such as passwords, OAuth tokens, SS...
Thu, 27 Mar, 2025 at 4:53 AM
Ensure Clusters are created with Private Nodes
Profile Applicability: Level 1  Description: In Amazon Elastic Kubernetes Service (EKS) or other Kubernetes environments, private nodes are Kubernete...
Thu, 27 Mar, 2025 at 5:22 AM
Check if account is part of an AWS Organizations
Profile Applicability: Level 1 Description: AWS Organizations allows you to centrally manage and govern multiple AWS accounts. An AWS account can be ...
Thu, 27 Mar, 2025 at 5:50 AM
DataSync tasks should have logging enabled
Profile Applicability: Level 1 Description: AWS DataSync is a service that automates the transfer of large amounts of data between on-premises storage ...
Thu, 27 Mar, 2025 at 5:56 AM
Check for medium and high risks identified in workloads defined in the AWS Well-Architected Tool
Profile Applicability: Level 1 Description: The AWS Well-Architected Tool helps you review your workloads against AWS best practices in five pillars: O...
Thu, 27 Mar, 2025 at 6:03 AM
Check if AWS WAFv2 WebACL logging is enabled
Profile Applicability: Level 1 Description: AWS WAFv2 (Web Application Firewall) provides robust protection for your web applications by filtering tr...
Thu, 27 Mar, 2025 at 6:09 AM
Check if API Gateway Public Endpoint Has an Authorizer Configured
Profile Applicability: Level 1 Description: Amazon API Gateway allows you to create and manage APIs for accessing AWS services, and it supports both pu...
Thu, 27 Mar, 2025 at 6:17 AM