AWS New Checks

Ensure that your Amazon Cognito user pool blocks potential malicious sign-in attempts
Profile Applicability: Level 1 Description: Amazon Cognito provides user authentication and management services, and securing sign-ins is crucial for p...
Fri, 28 Mar, 2025 at 1:44 AM
Ensure cognito user pools deletion protection enabled to prevent accidental deletion
Profile Applicability: Level 1 Description: Amazon Cognito is a fully managed service that provides authentication, authorization, and user management ...
Fri, 28 Mar, 2025 at 1:49 AM
Ensure AWS AppSync should have field-level logging enabled
Profile Applicability: Level 1 Description: AWS AppSync is a fully managed service that simplifies developing GraphQL APIs by handling complex tasks ...
Fri, 23 May, 2025 at 5:15 AM
Ensure that Amazon Cognito User Pool is associated with a WAF Web ACL
Profile Applicability: Level 1 Description: Amazon Cognito is a managed service that provides user authentication, authorization, and user management f...
Fri, 28 Mar, 2025 at 2:35 AM
Ensure that CodeBuild projects have S3 or CloudWatch logging enabled
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and ...
Fri, 28 Mar, 2025 at 2:41 AM
Ensure Disaster Recovery Service(DRS) is enabled with jobs.
Profile Applicability: Level 1 Description: Disaster Recovery Service (DRS) is a managed service that automates the process of disaster recovery for ...
Fri, 28 Mar, 2025 at 2:49 AM
Ensure CodeBuild projects do not contain secrets on plaintext environment variables
Profile Applicability: Level 1 Description: AWS CodeBuild allows you to define environment variables to be used during the build process. These environ...
Fri, 28 Mar, 2025 at 2:49 AM
Ensure CodeBuild project source repository URLs do not contain sensitive credentials
Profile Applicability: Level 1 Description: In AWS CodeBuild, projects are linked to source code repositories, which are typically hosted on Amazon Cod...
Fri, 28 Mar, 2025 at 2:55 AM
Ensure CodeBuild Project has been invoked in the last 90 days
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed build service that compiles source code, runs tests, and produces software...
Fri, 28 Mar, 2025 at 3:02 AM
Ensure S3 Logs for CodeBuild Projects are encrypted at rest
Profile Applicability: Level 1 Description: Amazon CodeBuild stores build logs in Amazon S3 by default. These logs can contain sensitive information, s...
Fri, 28 Mar, 2025 at 3:12 AM