AWS New Checks

Ensure that your Amazon Cognito user pool blocks potential malicious sign-in attempts
Profile Applicability: Level 1 Description: Amazon Cognito provides user authentication and management services, and securing sign-ins is crucial for p...
Fri, 19 Sep, 2025 at 7:20 AM
Ensure cognito user pools deletion protection enabled to prevent accidental deletion
Profile Applicability: Level 1 Description: Amazon Cognito is a fully managed service that provides authentication, authorization, and user management ...
Thu, 18 Sep, 2025 at 6:53 AM
Ensure AWS AppSync should have field-level logging enabled
Profile Applicability: Level 1 Description: AWS AppSync is a fully managed service that simplifies developing GraphQL APIs by handling complex tasks ...
Mon, 15 Sep, 2025 at 3:15 AM
Ensure that Amazon Cognito User Pool is associated with a WAF Web ACL
Profile Applicability: Level 1 Description: Amazon Cognito is a managed service that provides user authentication, authorization, and user management f...
Thu, 18 Sep, 2025 at 6:50 AM
Ensure that CodeBuild projects have S3 or CloudWatch logging enabled
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and ...
Fri, 28 Mar, 2025 at 2:41 AM
Ensure Disaster Recovery Service(DRS) is enabled with jobs.
Profile Applicability: Level 1 Description: Disaster Recovery Service (DRS) is a managed service that automates the process of disaster recovery ...
Fri, 12 Sep, 2025 at 2:19 AM
Ensure CodeBuild projects do not contain secrets on plaintext environment variables
Profile Applicability: Level 1 Description: AWS CodeBuild allows you to define environment variables to be used during the build process. These environ...
Fri, 28 Mar, 2025 at 2:49 AM
Ensure CodeBuild project source repository URLs do not contain sensitive credentials
Profile Applicability: Level 1 Description: In AWS CodeBuild, projects are linked to source code repositories, which are typically hosted on Amazon Cod...
Fri, 28 Mar, 2025 at 2:55 AM
Ensure CodeBuild Project has been invoked in the last 90 days
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed build service that compiles source code, runs tests, and produces software...
Thu, 18 Sep, 2025 at 6:38 AM
Ensure S3 Logs for CodeBuild Projects are encrypted at rest
Profile Applicability: Level 1 Description: Amazon CodeBuild stores build logs in Amazon S3 by default. These logs can contain sensitive information, s...
Thu, 18 Sep, 2025 at 6:29 AM