AWS New Checks

Ensure S3 buckets have Object-level logging for read events enabled in CloudTrail
Profile Applicability: Level 1 Description: This control ensures that Amazon S3 object-level (data event) logging for read events is enabled in AW...
Thu, 9 Oct, 2025 at 4:35 AM
Ensure that Object-level logging for write events is enabled in CloudTrail for S3 buckets
Profile Applicability: Level 1 Description: This control ensures that Amazon S3 object-level (data event) logging for write events is enabled in A...
Thu, 9 Oct, 2025 at 4:50 AM
Ensure AWS Config is enabled in all regions
Profile Applicability: Level 1 Description: This control ensures that AWS Config is enabled in all AWS regions to record configuration changes and re...
Thu, 9 Oct, 2025 at 5:22 AM
Ensure internet facing Elastic Load Balancers are checked
Profile Applicability: Level 1 Description: This control ensures that all Internet-facing Elastic Load Balancers (ELBs) — including Application Lo...
Mon, 13 Oct, 2025 at 5:06 AM
Ensure DocumentDB instances storage is encrypted
Profile Applicability: Level 1 Description: This control ensures that Amazon DocumentDB (with MongoDB compatibility) clusters have storage encryption ena...
Mon, 13 Oct, 2025 at 5:18 AM
Ensure VPCs are present in multiple regions
Profile Applicability: Level 1 Description: This control ensures that Amazon Virtual Private Clouds (VPCs) are provisioned across multiple AWS regions to...
Mon, 13 Oct, 2025 at 5:23 AM
Ensure routing tables for VPC peering have least access
Profile Applicability: Level 1 Description: This control ensures that routing tables associated with VPC peering connections follow the principle of lea...
Mon, 13 Oct, 2025 at 5:28 AM
Ensure VPC Flow Logging is Enabled in all VPCs
Profile Applicability: Level 1 Description: This control ensures that Amazon Virtual Private Cloud (VPC) Flow Logs are enabled for all VPCs within an AW...
Mon, 13 Oct, 2025 at 5:35 AM
Ensure SNS topics have policy set as Public
Profile Applicability: Level 1 Description: This control ensures that Amazon Simple Notification Service (SNS) topics are not publicly accessible through...
Mon, 13 Oct, 2025 at 5:42 AM
Ensure SQS queues have Server Side Encryption enabled
Profile Applicability: Level 1 Description: This control ensures that Amazon Simple Queue Service (SQS) queues have Server-Side Encryption (SSE) enabled ...
Mon, 13 Oct, 2025 at 5:47 AM