AWS New Checks

Ensure a support role has been created to manage incidents with AWS Support.
Profile Applicability: Level 1 Description: This control ensures that an AWS IAM role exists for securely managing support cases and incident response w...
Mon, 13 Oct, 2025 at 7:11 AM
Ensure IAM AWS-Managed policies that allow full "*:*" administrative privileges are not attached
Profile Applicability: Level 1 Description: This control ensures that IAM users, groups, or roles do not have AWS-managed policies granting full adminis...
Tue, 14 Oct, 2025 at 1:04 AM
Ensure access keys are rotated every 90 days or less
Profile Applicability: Level 1 Description: This control ensures that IAM user access keys are rotated every 90 days or less to reduce the risk of unaut...
Tue, 14 Oct, 2025 at 1:08 AM
Ensure there are SAML Providers then STS can be used
Profile Applicability: Level 1 Description: This control ensures that Security Assertion Markup Language (SAML) providers are properly configured in AWS ...
Tue, 14 Oct, 2025 at 1:13 AM
Ensure IAM Service Roles prevent against a cross-service confused deputy attack
Profile Applicability: Level 1 Description: This control ensures that IAM service roles include conditions that prevent cross-service confused deputy at...
Tue, 14 Oct, 2025 at 1:19 AM
Ensure that S3 buckets are not open to Everyone or Any AWS user
Profile Applicability: Level 1 Description: This control ensures that Amazon Simple Storage Service (S3) buckets do not allow public access or permi...
Mon, 13 Oct, 2025 at 7:03 AM
Ensure IAM users have Hardware MFA enabled
Profile Applicability: Level 1 Description: This control ensures that all AWS Identity and Access Management (IAM) users have Hardware Multi-Factor Authe...
Tue, 14 Oct, 2025 at 1:25 AM
Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
Profile Applicability: Level 1 Description: This control ensures that all AWS IAM users who have been assigned a console password also have Multi-Factor...
Tue, 14 Oct, 2025 at 1:30 AM
Ensure that the IAM password policy requires at least one symbol
Profile Applicability: Level 1 Description: This control ensures that the AWS Identity and Access Management (IAM) password policy requires users to inc...
Tue, 14 Oct, 2025 at 1:35 AM
Ensure there are no EBS Snapshots set as Public
Profile Applicability: Level 1 Description: This control ensures that Amazon Elastic Block Store (EBS) snapshots are not publicly shared. Public EBS ...
Tue, 14 Oct, 2025 at 3:39 AM