AWS New Checks

Ensure CloudFront distributions have logging enabled
Profile Applicability: Level 1 Description: This control ensures that Amazon CloudFront distributions have access logging enabled. CloudFront acc...
Mon, 13 Oct, 2025 at 7:12 AM
Ensure CloudFront distributions have Field Level Encryption enabled
Profile Applicability: Level 1 Description: This control ensures that Amazon CloudFront distributions have Field-Level Encryption (FLE) enabled to p...
Mon, 13 Oct, 2025 at 7:21 AM
Ensure geo restrictions are enabled in CloudFront distributions
Profile Applicability: Level 1 Description: This control ensures that Amazon CloudFront distributions have geo restrictions (geoblocking) enabled to ...
Mon, 13 Oct, 2025 at 7:33 AM
Ensure CloudFront distributions are set to HTTPS
Profile Applicability: Level 1 Description: This control ensures that Amazon CloudFront distributions are configured to use HTTPS (SSL/TLS) for secur...
Mon, 13 Oct, 2025 at 7:50 AM
Ensure API Gateway Stage has a WAF ACL attached
Profile Applicability: Level 1 Description: This control ensures that each Amazon API Gateway Stage has an AWS Web Application Firewall (WAF) Web ...
Mon, 13 Oct, 2025 at 8:00 AM
Ensure API Gateway endpoint is public or private
Profile Applicability: Level 1 Description: This control ensures that Amazon API Gateway endpoints are configured with the appropriate endpoint type ...
Mon, 13 Oct, 2025 at 8:12 AM
Ensure API Gateway Stage has client certificate enabled to access your backend endpoint
Profile Applicability: Level 1 Description: This control ensures that an API Gateway stage is configured to require client certificates for accessing the...
Tue, 14 Oct, 2025 at 4:03 AM
Ensure API Gateway V2 has configured authorizers
Profile Applicability: Level 1 Description: This control ensures that Amazon API Gateway V2 (HTTP and WebSocket APIs) has authorizers configured to a...
Mon, 13 Oct, 2025 at 9:38 AM
Ensure that no Network ACLs permit ingress from 0.0.0.0/0 to Microsoft RDP port 3389.
Profile Applicability: Level 1 Description: This control ensures that no Network Access Control Lists (NACLs) in an AWS environment allow inbound (in...
Tue, 14 Oct, 2025 at 12:50 AM
Ensure EBS Default Encryption is activated.
Profile Applicability: Level 1 Description: This control ensures that Amazon Elastic Block Store (EBS) Default Encryption is enabled for the AWS acco...
Tue, 14 Oct, 2025 at 12:58 AM