CIS AWS Benchmarks

4.1 Ensure unauthorized API calls are monitored (Manual)
Profile Applicability Level 1 Description: Monitoring unauthorized API calls is a critical step in maintaining the security of an AWS environment. Un...
Tue, 22 Apr, 2025 at 2:14 AM
4.2 Ensure management console sign-in without MFA is monitored (Manual)
Profile Applicability Level 1 Description: Multi-factor authentication (MFA) adds an extra layer of security to AWS Management Console sign-ins. Moni...
Tue, 22 Apr, 2025 at 2:21 AM
4.3 Ensure usage of the 'root' account is monitored (Manual)
Profile Applicability Level 1 Description: The AWS root account is the most privileged account in an AWS account. It has full access to all resources...
Tue, 22 Apr, 2025 at 2:26 AM
4.4 Ensure IAM policy changes are monitored (Manual)
Profile Applicability Level 1 Description: IAM (Identity and Access Management) policies define permissions for AWS users, groups, and roles, dictati...
Tue, 22 Apr, 2025 at 2:31 AM
4.5 Ensure CloudTrail configuration changes are monitored (Manual)
Profile Applicability Level 1 Description: AWS CloudTrail is a service that enables governance, compliance, and operational and risk auditing by reco...
Tue, 22 Apr, 2025 at 2:35 AM
4.6 Ensure AWS Management Console authentication failures are monitored (Manual)
Profile Applicability Level 1 Description: Monitoring AWS Management Console authentication failures is essential to detect potential security incide...
Tue, 22 Apr, 2025 at 2:43 AM
4.7 Ensure disabling or scheduled deletion of customer-created CMKs is monitored (Manual)
Profile Applicability Level 1 Description: Customer Managed Keys (CMKs) are the encryption keys created and controlled by customers in AWS Key Manage...
Tue, 22 Apr, 2025 at 3:08 AM
4.8 Ensure S3 bucket policy changes are monitored (Manual)
Profile Applicability Level 1 Description: Amazon S3 bucket policies are crucial for controlling access to data stored within S3 buckets. These polic...
Tue, 22 Apr, 2025 at 3:13 AM
4.9 Ensure AWS Config configuration changes are monitored (Manual)
Profile Applicability Level 1 Description: AWS Config is a service that provides a detailed view of the configuration of AWS resources in your accoun...
Tue, 22 Apr, 2025 at 3:18 AM
4.10 Ensure security group changes are monitored (Manual)
Profile Applicability Level 1 Description: Security groups act as virtual firewalls for instances in AWS, controlling inbound and outbound traffic at...
Tue, 22 Apr, 2025 at 3:23 AM