CIS AWS Benchmarks

1.1 Maintain current contact details (Manual)
Profile Applicability: Level 1 Description: Ensure that the AWS account contact information, including the email address and phone number, is curren...
Wed, 16 Apr, 2025 at 3:22 AM
1.2 Ensure security contact information is registered (Manual)
Profile Applicability Level 1 Description: Ensure that the security contact information is registered and up to date in your AWS account settings. The ...
Wed, 16 Apr, 2025 at 3:27 AM
1.3 Ensure no 'root' user account access key exists (Automated)
Profile Applicability Level 1 Description: The root user account in AWS is the most privileged user and should not have access keys configured. Acces...
Wed, 16 Apr, 2025 at 3:36 AM
1.4 Ensure MFA is enabled for the 'root' user account (Automated)
Profile Applicability Level 1 Description: Multi-factor authentication (MFA) should be enabled for the root user account to add an additional layer o...
Wed, 16 Apr, 2025 at 3:47 AM
1.5 Ensure hardware MFA is enabled for the 'root' user account (Manual)
Profile Applicability Level 1 Description: The root user account in AWS should have hardware multi-factor authentication (MFA) enabled to enhance the...
Wed, 16 Apr, 2025 at 4:03 AM
1.6 Eliminate use of the 'root' user for administrative and daily tasks (Manual)
Profile Applicability Level 1 Description: The root user in AWS is the account created during the initial setup of an AWS environment. It has full ad...
Wed, 16 Apr, 2025 at 4:17 AM
5.7 Ensure that the EC2 Metadata Service Only Allows IMDSv2 (Automated)
Profile Applicability Level 1 Description Amazon EC2 instances support two versions of the Instance Metadata Service (IMDS): IMDSv1: Uses a simple req...
Wed, 16 Apr, 2025 at 4:23 AM
1.7 Ensure IAM password policy requires a minimum length of 14 or greater (Automated)
Profile Applicability Level 1 Description: IAM password policies control the strength of passwords used by IAM users in an AWS environment. Requiring...
Wed, 16 Apr, 2025 at 4:29 AM
1.8 Ensure IAM password policy prevents password reuse (Automated)
Profile Applicability Level 1 Description: Preventing password reuse ensures that IAM users cannot reuse previous passwords when changing their passw...
Wed, 16 Apr, 2025 at 4:45 AM
1.9 Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password (Automated)
Profile Applicability Level 1 Description: Multi-factor authentication (MFA) provides an additional layer of security by requiring users to present m...
Wed, 16 Apr, 2025 at 8:31 AM