CIS AWS Benchmarks

2.3.1 Ensure that encryption is enabled for EFS file systems (Automated)
Profile Applicability Level 1 Description: Amazon Elastic File System (EFS) is a scalable file storage service for use with AWS Cloud services and on-p...
Mon, 21 Apr, 2025 at 1:45 AM
3.1 Ensure CloudTrail is enabled in all regions (Manual)
Profile Applicability Level 1 Description: AWS CloudTrail is a service that captures and logs API calls made on your AWS account, providing a detailed ...
Mon, 21 Apr, 2025 at 1:54 AM
3.2 Ensure CloudTrail log file validation is enabled (Automated)
Profile Applicability Level 1 Description: CloudTrail log file validation ensures the integrity of the log files generated by AWS CloudTrail. Enabling ...
Mon, 21 Apr, 2025 at 2:02 AM
3.3 Ensure AWS Config is enabled in all regions (Automated)
Profile Applicability Level 1 Description: AWS Config is a service that provides an inventory of AWS resources, tracks resource configuration history, ...
Mon, 21 Apr, 2025 at 2:12 AM
3.4 Ensure that server access logging is enabled on the CloudTrail S3 bucket (Manual)
Profile Applicability Level 1 Description: CloudTrail logs are stored in an S3 bucket, and server access logging allows tracking of requests made to th...
Mon, 21 Apr, 2025 at 2:50 AM
3.5 Ensure CloudTrail logs are encrypted at rest using KMS CMKs (Automated)
Profile Applicability Level 1 Description: AWS CloudTrail captures and logs all API calls made in an AWS account, providing crucial audit trails and se...
Mon, 21 Apr, 2025 at 7:49 AM
3.6 Ensure rotation for customer-created symmetric CMKs is enabled (Automated)
Profile Applicability Level 1 Description: Customer Managed Keys (CMKs) are encryption keys created and managed by customers in AWS Key Management Serv...
Mon, 21 Apr, 2025 at 7:58 AM
3.7 Ensure VPC flow logging is enabled in all VPCs (Automated)
Profile Applicability Level 1 Description: VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC. Ena...
Mon, 21 Apr, 2025 at 8:36 AM
3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)
Profile Applicability: Level 1 Description: Object-level logging for write events in Amazon S3 tracks all write operations (e.g., PUT, POST, DELETE) ma...
Tue, 22 Apr, 2025 at 1:18 AM
3.9 Ensure that object-level logging for read events is enabled for S3 buckets (Automated)
Profile Applicability Level 1 Description: S3 object-level logging enables the tracking of individual read requests made to objects stored in Amazon ...
Tue, 22 Apr, 2025 at 2:09 AM