CIS AWS Benchmarks

1.20 Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments (Manual)
Profile Applicability Level 1 Description: In multi-account environments, managing IAM users centrally via identity federation or AWS Organizations hel...
Thu, 17 Apr, 2025 at 5:12 AM
1.21 Ensure access to AWSCloudShellFullAccess is restricted (Manual)
Profile Applicability Level 1 Description: AWS CloudShell provides a browser-based, pre-authenticated shell to interact with AWS resources. While conve...
Thu, 17 Apr, 2025 at 5:25 AM
2.1.1 Ensure S3 Bucket Policy is set to deny HTTP requests (Automated)
Profile Applicability Level 1 Description: S3 Bucket Policies can be configured to ensure that data is only accessible through secure communication cha...
Thu, 17 Apr, 2025 at 6:28 AM
2.1.2 Ensure MFA Delete is enabled on S3 buckets (Manual)
Profile Applicability Level 1 Description: MFA Delete is a feature in Amazon S3 that provides an additional layer of protection against accidental or m...
Thu, 17 Apr, 2025 at 6:38 AM
2.1.3 Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary (Manual)
Profile Applicability Level 1 Description: Amazon S3 is widely used for storing data in AWS. To maintain data security and comply with regulatory stand...
Thu, 17 Apr, 2025 at 8:08 AM
2.1.4 Ensure that S3 is configured with 'Block Public Access' enabled (Automated)
Profile Applicability Level 1 Description: The Block Public Access feature in Amazon S3 helps prevent accidental exposure of data to the public interne...
Mon, 21 Apr, 2025 at 12:48 AM
2.2.1 Ensure that encryption-at-rest is enabled for RDS instances (Automated)
Profile Applicability Level 1 Description: Encryption-at-rest for Amazon RDS instances ensures that all data stored within the database, including back...
Mon, 21 Apr, 2025 at 12:57 AM
2.2.2 Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances (Automated)
Profile Applicability Level 1 Description: The Auto Minor Version Upgrade feature for Amazon RDS ensures that RDS instances are automatically upgraded ...
Mon, 21 Apr, 2025 at 1:14 AM
2.2.3 Ensure that RDS instances are not publicly accessible (Automated)
Profile Applicability Level 1 Description: Amazon RDS instances should not be publicly accessible to minimize the attack surface and reduce the risk of...
Mon, 21 Apr, 2025 at 1:28 AM
2.2.4 Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS (Manual)
Profile Applicability Level 1 Description: Amazon Relational Database Service (RDS) Multi-AZ deployments provide enhanced availability, fault tolerance...
Mon, 21 Apr, 2025 at 1:37 AM