AWS New Checks

Ensure that general-purpose bucket policies restrict access to other AWS accounts
Profile Applicability: Level 1 Description: Amazon S3 bucket policies are used to control access to S3 buckets and their objects. It is essential to co...
Fri, 21 Mar, 2025 at 5:56 AM
Ensure that logging is enabled for Amazon Athena workgroups to capture query activity.
Profile Applicability: Level 1 Description: Amazon Athena is an interactive query service that makes it easy to analyze data directly in Amazon S3 us...
Fri, 21 Mar, 2025 at 6:00 AM
Ensure that encryption at rest is enabled for Amazon Athena query results stored in Amazon S3 in order to secure data and meet compliance requirements for data-at-rest encryption.
Profile Applicability: Level 1 Description: Amazon Athena is an interactive query service that makes it easy to analyze data stored in Amazon S3 usin...
Fri, 21 Mar, 2025 at 6:22 AM
Ensure that workgroup configuration is enforced so it cannot be overriden by client-side settings.
Profile Applicability: Level 1 Description: In Amazon Athena, workgroups are used to organize users and their query resources. Workgroup configuration ...
Fri, 21 Mar, 2025 at 6:47 AM
Ensure a Premium support plan is subscribed.
Profile Applicability: Level 1 Description: AWS Premium Support offers 24/7 access to AWS Cloud Support Engineers, with advanced technical support fo...
Fri, 23 May, 2025 at 2:35 AM
Ensure Amazon Elasticsearch/Opensearch Service domains have audit logging enabled
Profile Applicability: Level 1 Description: Amazon Elasticsearch Service (Amazon ES) and Amazon OpenSearch Service are managed services for running E...
Fri, 23 May, 2025 at 4:00 AM
Ensure CloudWatch Has Allowed Cross-Account Sharing
Profile Applicability: Level 2 Description: AWS CloudWatch allows you to share log groups and metrics across accounts. Cross-account sharing is essen...
Sun, 23 Mar, 2025 at 5:02 AM
Ensure a Log Metric Filter and Alarm Exist for AWS Organizations Changes
Profile Applicability: Level 1 Description: It is essential to monitor changes to your AWS Organizations for auditing and security purposes. Using AW...
Sun, 23 Mar, 2025 at 5:17 AM
Ensure Secrets Are Not Logged in CloudWatch Logs
Profile Applicability: Level 1 Description: It is crucial to monitor CloudWatch logs for any potential secrets, such as AWS credentials, passwords, o...
Fri, 23 May, 2025 at 2:53 AM
Ensure Route Table Changes are Monitored
Profile Applicability: Level 1 Description: Changes to route tables in a VPC are significant for network communication, and it is essential to monito...
Sun, 23 Mar, 2025 at 5:37 AM