AWS New Checks

Ensure that CodeBuild projects have S3 or CloudWatch logging enabled
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and ...
Fri, 28 Mar, 2025 at 2:41 AM
Ensure Disaster Recovery Service(DRS) is enabled with jobs.
Profile Applicability: Level 1 Description: Disaster Recovery Service (DRS) is a managed service that automates the process of disaster recovery for ...
Fri, 28 Mar, 2025 at 2:49 AM
Ensure CodeBuild projects do not contain secrets on plaintext environment variables
Profile Applicability: Level 1 Description: AWS CodeBuild allows you to define environment variables to be used during the build process. These environ...
Fri, 28 Mar, 2025 at 2:49 AM
Ensure CodeBuild project source repository URLs do not contain sensitive credentials
Profile Applicability: Level 1 Description: In AWS CodeBuild, projects are linked to source code repositories, which are typically hosted on Amazon Cod...
Fri, 28 Mar, 2025 at 2:55 AM
Ensure CodeBuild Project has been invoked in the last 90 days
Profile Applicability: Level 1 Description: AWS CodeBuild is a fully managed build service that compiles source code, runs tests, and produces software...
Fri, 28 Mar, 2025 at 3:02 AM
Ensure S3 Logs for CodeBuild Projects are encrypted at rest
Profile Applicability: Level 1 Description: Amazon CodeBuild stores build logs in Amazon S3 by default. These logs can contain sensitive information, s...
Fri, 28 Mar, 2025 at 3:12 AM
Ensure CodeBuild Project uses a controlled buildspec
Profile Applicability: Level 1 Description: In AWS CodeBuild, the buildspec file defines the build commands and settings for the project. This file is ...
Fri, 28 Mar, 2025 at 3:17 AM
CodeBuild report group exports are encrypted at rest
Profile Applicability: Level 1 Description: Amazon CodeBuild allows you to create report groups to track and manage the results of your builds. Report ...
Fri, 28 Mar, 2025 at 3:22 AM
Check if DocumentDB Clusters have backup enabled
Profile Applicability: Level 1 Description: Amazon DocumentDB automatically creates backups of your clusters by enabling automated backups. These backu...
Fri, 28 Mar, 2025 at 3:27 AM
Check if DocumentDB Clusters has deletion protection enabled
Profile Applicability: Level 1 Description: Amazon DocumentDB provides deletion protection to prevent accidental deletion of clusters. When deletion pr...
Fri, 28 Mar, 2025 at 3:32 AM