prowler-logo
Report Information
  • Version: 5.39.1
  • Parameters used: aws --profile dasnuve-scrivas-louis-impersonation --region us-east-2 us-east-1 -M csv json-ocsf html -o /Users/alvaro/Develop/dasnuve/scrivas/findings/prowler --no-banner
  • Date: 2026-08-19T12:40:39.730996
AWS Assessment Summary
  • AWS Account: 716468089330
  • AWS-CLI Profile: dasnuve-scrivas-louis-impersonation
  • Audited Regions: us-east-1, us-east-2
AWS Credentials
  • User Id: AIDA2NUGTOHZOHX3GWS4T
  • Caller Identity ARN: arn:aws:iam::716468089330:user/louis
Assessment Overview
  • Total Findings: 1224
  • Passed: 861
  • Passed (Muted): 0
  • Failed: 363
  • Failed (Muted): 0
  • Total Resources: 269
Status Severity Service Name Region Check ID Check Title Resource ID Resource Tags Status Extended Risk Recommendation Compliance
PASS low accessanalyzer us-east-1 accessanalyzer_enabled IAM Access Analyzer is enabled arn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zd IAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd is enabled.

Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity.

Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes.

•CIS-7.0: 2.18 •CIS-1.4: 1.20 •CIS-1.5: 1.20 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC •CIS-2.0: 1.20 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6 •CIS-5.0: 1.19 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view •CIS-3.0: 1.20 •CIS-6.0: 2.19 •CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.2.6 •ISO27001-2022: A.8.3 •AWS-AI-Security-Framework-1.0: AISF-DATA-02 •CIS-4.0.1: 1.20 •NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e

FAIL low accessanalyzer us-east-2 accessanalyzer_enabled IAM Access Analyzer is enabled arn:aws:accessanalyzer:us-east-2:716468089330:analyzer/unknown IAM Access Analyzer in account 716468089330 is not enabled.

Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity.

Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes.

•CIS-7.0: 2.18 •CIS-1.4: 1.20 •CIS-1.5: 1.20 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC •CIS-2.0: 1.20 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6 •CIS-5.0: 1.19 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view •CIS-3.0: 1.20 •CIS-6.0: 2.19 •CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.2.6 •ISO27001-2022: A.8.3 •AWS-AI-Security-Framework-1.0: AISF-DATA-02 •CIS-4.0.1: 1.20 •NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e

PASS low accessanalyzer us-east-1 accessanalyzer_enabled_without_findings IAM Access Analyzer analyzer is active and has no active findings arn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zd IAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd does not have active findings.

Unresolved Active findings indicate unintended external or internal access paths.
- Confidentiality: public/cross-account reads of data (buckets, snapshots, secrets)
- Integrity: rogue role assumption or KMS use enabling policy/data changes
- Lateral movement across accounts

Enable IAM Access Analyzer in all relevant Regions and org/account scopes. Triage every Active finding:
- Remove unintended access by tightening resource and trust policies
- Enforce least privilege and separation of duties
- Archive only validated, intended access
- Continuously monitor and automate reviews

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: AM-09.04AC, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: ov_2, ac_4, cm_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view •AWS-Foundational-Technical-Review: SECOPS-001 •CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 •SecNumCloud-3.2: 9.4 •ISO27001-2022: A.8.3 •AWS-AI-Security-Framework-1.0: AISF-DATA-02 •NIS2: 2.1.2.g, 2.1.2.h

MANUAL medium account us-east-2 account_maintain_current_contact_details AWS account contact information is current arn:aws:iam::716468089330:root Login to the AWS Console. Choose your account name on the top right of the window -> My Account -> Contact Information.

Outdated or single-person contacts delay security notifications, slow incident response, and complicate account recovery.

AWS may throttle services during abuse mitigation, reducing availability. Missed alerts enable ongoing misuse, risking data exfiltration and unauthorized changes (integrity).

Adopt:
- Primary and alternate contacts for security, billing, operations
- Shared, monitored aliases and SMS-capable phone numbers (non-personal)
- Centralized management across accounts with periodic reviews
- Least privilege for who can modify contact data
- Regular reachability tests and documented ownership

•CIS-7.0: 2.2 •CIS-1.4: 1.1 •CIS-1.5: 1.1 •KISA-ISMS-P-2023: 2.10.2 •C5-2025: IAM-03.01AS, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B •CIS-2.0: 1.1 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 •CIS-5.0: 1.1 •AWS-Account-Security-Onboarding: Billing, emergency, security contacts •CIS-3.0: 1.1 •ENS-RD2022: op.ext.7.aws.am.1 •CIS-6.0: 2.1 •ISO27001-2022: A.5.5 •AWS-AI-Security-Framework-1.0: AISF-GOV-03 •CIS-4.0.1: 1.1 •NIS2: 2.2.3, 3.5.3.a, 5.1.7.b

FAIL medium account us-east-2 account_maintain_different_contact_details_to_security_billing_and_operations AWS account has distinct Security, Billing, and Operations contact details, different from each other and from the root contact arn:aws:iam::716468089330:root SECURITY, BILLING and OPERATIONS contacts not found or they are not different between each other and between ROOT contact.

Missing or shared contacts can delay response to abuse alerts, credential compromise, or billing anomalies, reducing availability (possible AWS traffic throttling) and raising confidentiality and integrity risk through extended exposure. If AWS cannot reach you, urgent mitigation may disrupt service.

Maintain distinct, monitored Security, Billing, and Operations alternate contacts that differ from the root contact.
- Use team aliases and 24x7 phones
- Review and test contact paths regularly
- Centralize at org level for consistency

Applies operational resilience and separation of duties.

•KISA-ISMS-P-2023: 2.10.2 •C5-2025: OIS-04.03B, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B •KISA-ISMS-P-2023-korean: 2.10.2 •ISO27001-2022: A.5.6 •AWS-AI-Security-Framework-1.0: AISF-GOV-03

MANUAL medium account us-east-2 account_security_contact_information_is_registered AWS account has security alternate contact registered arn:aws:iam::716468089330:root Login to the AWS Console. Choose your account name on the top right of the window -> My Account -> Alternate Contacts -> Security Section.

Missing or outdated security contact can delay or prevent AWS advisories from reaching responders, increasing risk to:
- Confidentiality: data exfiltration from undetected compromise
- Integrity: unauthorized changes persist longer
- Availability: resource abuse (e.g., cryptomining) and outages

Define and maintain a Security alternate contact:
- Use a monitored alias (e.g., security@domain) and team phone
- Apply to every account (prefer Org-wide automation)
- Review after org/personnel changes and test delivery
- Document ownership and escalation paths
Align with incident response and least privilege principles.

•CIS-7.0: 2.3 •CIS-1.4: 1.2 •CIS-1.5: 1.2 •AWS-Foundational-Security-Best-Practices: Account.1 •KISA-ISMS-P-2023: 2.10.2 •C5-2025: OIS-06.01B, SSO-05.06B, SIM-01.03B •CIS-2.0: 1.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 •CIS-5.0: 1.2 •PCI-4.0: A1.2.3.1 •AWS-Account-Security-Onboarding: Billing, emergency, security contacts •CIS-3.0: 1.2 •ENS-RD2022: op.ext.7.aws.am.1 •CIS-6.0: 2.2 •ISO27001-2022: A.5.5 •AWS-AI-Security-Framework-1.0: AISF-GOV-03 •CIS-4.0.1: 1.2 •NIS2: 1.1.1.a, 1.2.3, 2.2.1, 3.1.2.d, 3.5.3.a, 5.1.7.b

MANUAL medium account us-east-2 account_security_questions_are_registered_in_the_aws_account [DEPRECATED] AWS root user has security challenge questions configured arn:aws:iam::716468089330:root Login to the AWS Console as root. Choose your account name on the top right of the window -> My Account -> Configure Security Challenge Questions.

Absence of these questions can limit support-assisted recovery if root credentials or MFA are lost, reducing availability and slowing incident response. Reliance on KBA also weakens confidentiality due to social engineering. Treat this as a recovery gap and adopt stronger, phishing-resistant factors.

Favor stronger recovery instead of KBA:
- Enforce MFA for root and minimize root use
- Keep alternate contacts and root email current and protected
- Establish a tightly controlled break-glass role, applying least privilege and separation of duties
- Document and test recovery procedures; monitor root activity

•CIS-1.4: 1.3 •CIS-1.5: 1.3 •KISA-ISMS-P-2023: 2.5.1, 2.5.3, 2.10.2 •CIS-2.0: 1.3 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 •CIS-3.0: 1.3 •ENS-RD2022: op.ext.7.aws.am.1 •CIS-4.0.1: 1.3

FAIL low backup us-east-2 backup_vaults_exist At least one AWS Backup vault exists arn:aws:backup:us-east-2:716468089330:backup-vault No Backup Vault exist.

Without a vault, recovery points cannot be created or retained in AWS Backup, degrading availability and integrity. Data may be irrecoverable after deletion, ransomware, or misconfiguration, and RPO/RTO targets may be missed during incidents.

Create and maintain a backup vault in each required region. Enforce least privilege access, encrypt with KMS CMKs, and enable Vault Lock to prevent tampering. Use lifecycle rules and cross-region/cross-account copies, and regularly test restores for defense in depth.

•KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, OPS-08.01B, OPS-09.02B, CRY-16.02B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: be_5, ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •ENS-RD2022: mp.info.6.aws.bcku.1 •AWS-Foundational-Technical-Review: BAR-001 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR01, CCC.Core.CN14.AR02, CCC.Core.CN14.AR03 •SecNumCloud-3.2: 12.5, 17.6 •ISO27001-2022: A.8.13 •NIS2: 3.6.2, 4.1.2.f, 4.1.2.g, 4.2.2.b, 4.2.2.e, 12.1.2.c, 12.2.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-rpl

PASS high bedrock us-east-2 bedrock_full_access_policy_attached IAM role does not have AmazonBedrockFullAccess managed policy attached arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole IAM Role AmazonEKS_EBS_CSI_DriverRole does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.

Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

•SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •SecNumCloud-3.2: 9.3 •ISO27001-2022: A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high bedrock us-east-2 bedrock_full_access_policy_attached IAM role does not have AmazonBedrockFullAccess managed policy attached arn:aws:iam::716468089330:role/IntruderReadOnlyRole IAM Role IntruderReadOnlyRole does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.

Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

•SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •SecNumCloud-3.2: 9.3 •ISO27001-2022: A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high bedrock us-east-2 bedrock_full_access_policy_attached IAM role does not have AmazonBedrockFullAccess managed policy attached arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 IAM Role SecureframeRole-f983f1e89008 does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.

Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

•SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •SecNumCloud-3.2: 9.3 •ISO27001-2022: A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

FAIL medium bedrock us-east-1 bedrock_guardrails_configured Bedrock has at least one guardrail configured in the audited region arn:aws:bedrock:us-east-1:716468089330:guardrails Bedrock has no guardrails configured in region us-east-1.

Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere.

Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
- Add sensitive information filters and denied topic policies
- Apply guardrails at the API call level using guardrailIdentifier where supported

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-AI-Security-Framework-1.0: AISF-AI-01

FAIL medium bedrock us-east-2 bedrock_guardrails_configured Bedrock has at least one guardrail configured in the audited region arn:aws:bedrock:us-east-2:716468089330:guardrails Bedrock has no guardrails configured in region us-east-2.

Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere.

Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
- Add sensitive information filters and denied topic policies
- Apply guardrails at the API call level using guardrailIdentifier where supported

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-AI-Security-Framework-1.0: AISF-AI-01

FAIL medium bedrock us-east-1 bedrock_model_invocation_logging_enabled Amazon Bedrock model invocation logging is enabled arn:aws:bedrock:us-east-1:716468089330:model-invocation-logging Bedrock Model Invocation Logging is disabled.

Without invocation logs, you lose auditability and forensic visibility into model activity.

Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response.

Enable model invocation logging and route events to CloudWatch Logs and/or S3.

Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties.

•SOC2: cc_a_1_1 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •CCC-v2025.10: CCC.GenAI.CN05.AR01 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-AI-05 •NIS2: 3.2.3.c

FAIL medium bedrock us-east-2 bedrock_model_invocation_logging_enabled Amazon Bedrock model invocation logging is enabled arn:aws:bedrock:us-east-2:716468089330:model-invocation-logging Bedrock Model Invocation Logging is disabled.

Without invocation logs, you lose auditability and forensic visibility into model activity.

Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response.

Enable model invocation logging and route events to CloudWatch Logs and/or S3.

Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties.

•SOC2: cc_a_1_1 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •CCC-v2025.10: CCC.GenAI.CN05.AR01 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-AI-05 •NIS2: 3.2.3.c

FAIL low bedrock us-east-1 bedrock_prompt_management_exists Amazon Bedrock Prompt Management prompts exist in the region arn:aws:bedrock:us-east-1:716468089330:prompt-management No Bedrock Prompt Management prompts exist in region us-east-1.

Without Prompt Management, prompts are scattered across applications with no central oversight, versioning, or auditability over instructions sent to foundation models, weakening governance and compliance posture.

Managed prompts are a governance enabler; prompt injection defenses are provided by Bedrock guardrails, covered by separate checks.

Adopt Bedrock Prompt Management to centralize prompt definitions, enforce versioning, and maintain governance over model interactions.

Use managed prompts with guardrails and apply least privilege access controls to restrict who can create or modify prompts.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-AI-Security-Framework-1.0: AISF-AI-07

PASS critical cloudformation us-east-2 cloudformation_stack_outputs_find_secrets CloudFormation stack outputs do not contain secrets arn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bdd No secrets found in CloudFormation Stack Secureframe-f983f1e89008 Outputs.

Secrets in Outputs are readable to anyone with stack metadata access, enabling credential theft, unauthorized API calls, and lateral movement. Exposure via consoles, exports, or CI logs undermines confidentiality and can lead to privilege escalation and data exfiltration.

Remove secrets from Outputs. Store credentials in Secrets Manager or Parameter Store and reference them via dynamic references; set NoEcho for sensitive parameters. Apply least privilege to view stack metadata, avoid exporting sensitive values, and add automated IaC secret scanning for defense in depth.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: DEV-02.01B •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03

FAIL medium cloudformation us-east-2 cloudformation_stacks_termination_protection_enabled CloudFormation stack has termination protection enabled arn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bdd CloudFormation Stack Secureframe-f983f1e89008 has termination protection disabled.

Without termination protection, human error or automation can delete entire stacks, causing immediate availability loss and potential data destruction of managed resources.

Attackers with delete rights can more easily trigger outages and hinder recovery.

Enable termination protection on root stacks for critical workloads. Enforce least privilege on who can alter this setting or delete stacks, require change review via change sets, and apply stack policies plus DeletionPolicy: Retain for data stores for defense in depth.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03

PASS medium cloudtrail us-east-2 cloudtrail_bedrock_logging_enabled CloudTrail logs Amazon Bedrock API calls for security auditing arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 from home region us-east-2 has an advanced management event selector to log Amazon Bedrock control-plane API calls.

Without CloudTrail logging for Bedrock control-plane operations, changes to prompts, guardrails, agents, flows, or knowledge bases can become invisible, weakening forensics and incident response. Management events do not capture InvokeModel; pair this control with bedrock_model_invocation_logging_enabled or Bedrock data event selectors for invocation visibility.

Enable CloudTrail logging for Amazon Bedrock on at least one actively logging trail. At minimum, enable management events to capture Bedrock control-plane operations. For invocation-level and other data-plane visibility, add advanced event selectors targeting Bedrock resource types or pair this control with bedrock_model_invocation_logging_enabled.

For broader region coverage, pair this control with a separate multi-region CloudTrail check. Centralize logs in an encrypted bucket or CloudWatch Logs to support defense in depth and forensic readiness for AI workloads.

•SOC2: cc_7_2 •KISA-ISMS-P-2023: 2.9.4 •C5-2025: OPS-12.01B, OPS-15.01B •HIPAA: 164_308_a_1_ii_d, 164_312_b •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-CSF-2.0: pt_1, ae_3, cm_3 •NIST-800-53-Revision-5: au_2_b, au_12_a, au_12_c •CCC-v2025.10: CCC.AuditLog.CN02.AR01 •SecNumCloud-3.2: 12.6 •FFIEC: d2-ma-ma-b-2 •ISO27001-2022: A.8.15 •FedRamp-Moderate-Revision-4: au-2-a-d, au-12-a-c

FAIL medium cloudtrail us-east-2 cloudtrail_bucket_requires_mfa_delete CloudTrail trail S3 bucket has MFA delete enabled arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 bucket (aws-cloudtrail-logs-716468089330-fb4a4f88) does not have MFA delete enabled.

Without MFA Delete, stolen or over-privileged credentials can permanently delete log versions or change versioning, compromising log integrity and availability. This enables attacker cover-ups, hinders forensics, and weakens evidence for investigations.

Enable MFA Delete on the CloudTrail log bucket with versioning enabled. Enforce least privilege so only tightly controlled identities can delete or alter logs, and require MFA for such actions. Apply defense in depth using a dedicated logging account and log file integrity validation.

•KISA-ISMS-P-2023: 2.5.3, 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-09.02B, IAM-09.01AC, COM-04.01AC, PSS-05.01B, PSS-07.02B, PSS-12.03AC •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.9.4, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_3 •ENS-RD2022: op.exp.8.r4.aws.ct.3 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN07.AR01 •SecNumCloud-3.2: 12.7 •NIS2: 11.7.2

PASS low cloudtrail us-east-2 cloudtrail_cloudwatch_logging_enabled CloudTrail trail has delivered logs to CloudWatch Logs in the last 24 hours arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Multiregion trail us-east-2 has been logging in the last 24h.

Missing or stale CloudWatch delivery weakens visibility and delays detection, impacting confidentiality and integrity. Adversaries can:
- Hide privilege escalation
- Perform unauthorized resource changes
- Exfiltrate data via API misuse

Integrate every trail with CloudWatch Logs and maintain continuous, near-real-time delivery. Enforce least privilege on the delivery role, prefer multi-Region coverage, and implement metric filters and alerts for sensitive actions. Centralize retention to support defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_a_1_1, pi_1_3 •CIS-1.4: 3.4 •CIS-1.5: 3.4 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: CloudTrail.5 •ISO27001-2013: A.12.4.Q •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.01AC, OIS-05.02B, AM-01.01AC, OPS-11.02AC, OPS-13.01B, OPS-13.02B, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-02.01B, SIM-03.07B, COM-04.01AC, PSS-04.01B, PSS-04.05B, PSS-12.03AC •HIPAA: 164_308_a_1_ii_d, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •CIS-2.0: 3.4 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-CSF-2.0: ip_8, ae_1, ae_3, cm_1, cm_3, cm_7 •NIST-800-171-Revision-2: 3_3_1, 3_3_2, 3_3_3, 3_3_5, 3_6_1, 3_6_2, 3_12_4 •PCI-4.0: 10.2.1.1.10, 10.2.1.2.8, 10.2.1.3.8, 10.2.1.4.8, 10.2.1.5.8, 10.2.1.6.8, 10.2.1.7.8, 10.2.1.8, 10.2.2.8, 10.3.1.8, 10.4.1.1.3, 10.6.3.10, 11.5.2.4, 11.6.1.4, 12.10.5.4, 5.3.4.9, A1.2.1.10, A3.3.1.6, A3.5.1.6 •NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_6_1, au_6_3, au_7_1, au_12, ca_7, si_4_2, si_4_4, si_4_5, si_4 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_4_1, au_6_1, au_6_3, au_6_4, au_6_5, au_6_6, au_6_9, au_7_1, au_8_b, au_9_7, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, au_16, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •ENS-RD2022: op.exp.8.r1.aws.ct.7, op.mon.3.aws.cwl.1 •NIST-CSF-1.1: ae_1, ae_3, cm_2, cm_5, cp_4, ra_5, sc_4, pt_1 •AWS-Well-Architected-Framework-Reliability-Pillar: REL06-BP01 •CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR02, CCC.LB.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-is-is-b-1, d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 •PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.3, 10.5.4 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-7-1, au-12-a-c, si-4-a-b-c •NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS low cloudtrail us-east-2 cloudtrail_insights_exist CloudTrail trail has Insights enabled arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 has insight selectors and it is logging.

Without Insights, abnormal API call or error rates can go unnoticed, delaying detection of credential abuse, privilege escalation, or runaway automation. Attackers may rapidly alter policies, delete resources, or exfiltrate data before response, impacting confidentiality and availability.

Enable CloudTrail Insights on all logging trails (ideally all-Region or organization trails). Activate both ApiCallRateInsight and ApiErrorRateInsight. Integrate alerts with monitoring and review anomalies regularly. Apply defense in depth and least privilege to reduce potential blast radius.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-05.02B, SIM-03.07B, COM-04.01AC, PSS-12.03AC •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: cm_1, dp_4 •PCI-4.0: 10.3.2.2, 10.3.3.4, 10.3.4.3, 10.5.1.3, 5.3.4.8, A1.2.1.8 •ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01 •SecNumCloud-3.2: 12.9 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01

FAIL medium cloudtrail us-east-2 cloudtrail_kms_encryption_enabled CloudTrail trail logs are encrypted at rest with a KMS key arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Multiregion trail us-east-2 has encryption disabled.

Absent a customer-managed KMS key, log protection relies only on storage permissions. Bucket misconfigurations or stolen credentials can expose audit data, aiding evasion and lateral movement. Missing key-level controls, rotation, and usage audit weaken confidentiality and forensic integrity.

Enable SSE-KMS on every trail using a customer-managed KMS key. Apply least privilege so only authorized roles can Decrypt, and enforce separation of duties between key admins and log readers. Rotate keys and monitor key usage to provide defense in depth for CloudTrail data.

•CISA: your-systems-3, your-data-1 •CIS-7.0: 4.5 •CIS-1.4: 3.7 •CIS-1.5: 3.7 •GDPR: article_25, article_30, article_32 •AWS-Foundational-Security-Best-Practices: CloudTrail.2 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, OPS-11.02AC, OPS-13.03B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, IAM-08.06B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, CRY-10.01AC, CRY-11.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.04B, PSS-12.02B, PSS-12.03AC •HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 3.7 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5, pt_1, pt_4 •CIS-5.0: 3.5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.4, 10.3.3.6, 10.3.4.5, 3.5.1.5, 8.3.2.9, A1.2.1.11 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 3.5 •ENS-RD2022: op.exp.8.r4.aws.ct.4, op.exp.8.r4.aws.ct.7 •CIS-6.0: 4.5 •AWS-Foundational-Technical-Review: SDAT-002 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN02.AR01 •SecNumCloud-3.2: 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.3 •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DETECT-01 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •CIS-4.0.1: 3.5 •NIS2: 9.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-svc

PASS medium cloudtrail us-east-2 cloudtrail_log_file_validation_enabled CloudTrail trail has log file validation enabled arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Multiregion trail us-east-2 has log file validation enabled.

Without validation, adversaries can alter, forge, or delete audit entries without detection, compromising log integrity and non-repudiation.

This impairs investigations, enables alert evasion, and obscures unauthorized changes across regions or accounts.

Enable log file integrity validation on all trails (LogFileValidationEnabled=true).

Enforce least privilege on the logs bucket, retain and protect digest files (e.g., S3 Object Lock/MFA Delete), and monitor validation results to support defense in depth.

•CISA: your-systems-3 •CIS-7.0: 4.2 •SOC2: cc_7_3, pi_1_3 •CIS-1.4: 3.2 •CIS-1.5: 3.2 •GDPR: article_25, article_32 •AWS-Foundational-Security-Best-Practices: CloudTrail.4 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-13.01AC, OPS-15.02AC, OPS-26.05B, OPS-26.01AS, DEV-08.02B, SIM-01.02AC, SIM-03.07B, COM-04.01AC, PSS-12.03AC •HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_312_b, 164_312_c_1, 164_312_c_2 •CIS-2.0: 3.2 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01, SEC06-BP06 •NIST-CSF-2.0: ds_6, pt_1 •CIS-5.0: 3.2 •NIST-800-171-Revision-2: 3_3_8, 3_13_1 •PCI-4.0: 10.3.2.5, 10.3.3.7, 10.3.4.6, A1.2.1.12 •NIST-800-53-Revision-4: si_7_1, si_7 •NIST-800-53-Revision-5: au_9_a, cm_6_a, cm_9_b, pm_11_b, pm_17_b, sa_1_1, sa_10_1, sc_16_1, si_1_a_2, si_4_d, si_7_1, si_7_3, si_7_7, si_7_a •CIS-3.0: 3.2 •ENS-RD2022: op.exp.8.aws.ct.3 •CIS-6.0: 4.2 •NIST-CSF-1.1: ds_6, ds_7 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN01.AR01, CCC.AuditLog.CN01.AR02 •SecNumCloud-3.2: 10.4, 12.7, 16.6 •PCI-3.2.1: 10.5, 10.5.2, 10.5.5 •ProwlerThreatScore-1.0: 3.1.2 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •FedRamp-Moderate-Revision-4: au-9, si-7-1, si-7 •FedRAMP-Low-Revision-4: ac-2, au-2, au-9 •CIS-4.0.1: 3.2 •NIS2: 3.4.2.d •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla

PASS medium cloudtrail us-east-2 cloudtrail_logs_s3_bucket_access_logging_enabled CloudTrail trail destination S3 bucket has access logging enabled arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Multiregion Trail us-east-2 S3 bucket access logging is enabled for bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Without access logging on the CloudTrail logs bucket, access and changes to log files lack an independent audit trail. Attackers could read, delete, or replace logs without attribution, undermining log confidentiality and integrity, and slowing incident response.

Enable S3 server access logging on the CloudTrail logs bucket and write logs to a separate, tightly controlled bucket. Apply least privilege, enable versioning, and consider Object Lock to deter tampering. Centralize monitoring to support defense-in-depth and rapid investigation.

•CIS-7.0: 4.4 •SOC2: cc_a_1_1 •CIS-1.4: 3.6 •CIS-1.5: 3.6 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: CloudTrail.7 •ISO27001-2013: A.12.4.O •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, IAM-10.01B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, INQ-04.01AC, PSS-04.05B, PSS-12.03AC •CIS-2.0: 3.6 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-CSF-2.0: pt_1 •CIS-5.0: 3.4 •AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM •CIS-3.0: 3.4 •ENS-RD2022: op.exp.8.r1.aws.ct.6, op.exp.8.r4.aws.ct.5 •CIS-6.0: 4.4 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.7 •ProwlerThreatScore-1.0: 3.1.3 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •CIS-4.0.1: 3.4 •NIS2: 3.2.3.c, 11.1.1, 11.2.2.f

PASS critical cloudtrail us-east-2 cloudtrail_logs_s3_bucket_is_not_publicly_accessible CloudTrail trail S3 bucket is not publicly accessible arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 from multiregion trail us-east-2 is not publicly accessible.

Exposed CloudTrail logs erode confidentiality and integrity.

Adversaries can harvest API activity to map accounts, roles, and keys, enabling reconnaissance and evasion. If write is allowed, logs can be poisoned or deleted, thwarting investigations and compromising incident timelines.

Apply least privilege to the log bucket:
- Enable S3 Block Public Access (account and bucket)
- Remove AllUsers/AuthenticatedUsers ACLs; avoid wildcard principals
- Permit only CloudTrail and constrain with aws:SourceArn

Use a dedicated private bucket and monitor for permission changes.

•CIS-1.4: 3.3 •CIS-1.5: 3.3 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: CloudTrail.6 •ISO27001-2013: A.12.4.S, A.12.6.J •KISA-ISMS-P-2023: 2.6.1, 2.10.1 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC •CIS-2.0: 3.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ds_5, pt_1 •ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r4.aws.ct.2, op.exp.8.r4.aws.ct.6 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN04.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 12.7 •ProwlerThreatScore-1.0: 2.2.5 •ISO27001-2022: A.8.1, A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •NIS2: 3.2.3.c

PASS high cloudtrail us-east-1 cloudtrail_multi_region_enabled Region has at least one CloudTrail trail logging arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 is multiregion and it is logging.

Missing coverage in any region creates visibility gaps.

Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity).

Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.

Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 4.1 •SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3 •CIS-1.4: 3.1 •CIS-1.5: 3.1 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: CloudTrail.1 •ISO27001-2013: A.12.4.T •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •CIS-2.0: 3.1 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03 •GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control •CIS-5.0: 3.1 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23 •NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Account-Security-Onboarding: Enable as part of Organization trail •CIS-3.0: 3.1 •ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1 •CIS-6.0: 4.1 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1 •CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 •PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ProwlerThreatScore-1.0: 3.1.1 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 •FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 •CIS-4.0.1: 3.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07

PASS high cloudtrail us-east-2 cloudtrail_multi_region_enabled Region has at least one CloudTrail trail logging arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 is multiregion and it is logging.

Missing coverage in any region creates visibility gaps.

Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity).

Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.

Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 4.1 •SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3 •CIS-1.4: 3.1 •CIS-1.5: 3.1 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: CloudTrail.1 •ISO27001-2013: A.12.4.T •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •CIS-2.0: 3.1 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03 •GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control •CIS-5.0: 3.1 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23 •NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Account-Security-Onboarding: Enable as part of Organization trail •CIS-3.0: 3.1 •ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1 •CIS-6.0: 4.1 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1 •CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 •PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ProwlerThreatScore-1.0: 3.1.1 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 •FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 •CIS-4.0.1: 3.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07

PASS low cloudtrail us-east-1 cloudtrail_multi_region_enabled_logging_management_events CloudTrail trail logs management events for read and write operations arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled.

Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.

Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response.

Enable a multi-region CloudTrail that logs management events for read and write in all regions.

Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4 •AWS-Account-Security-Onboarding: Enable as part of Organization trail •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.2, 12.6 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c

PASS low cloudtrail us-east-2 cloudtrail_multi_region_enabled_logging_management_events CloudTrail trail logs management events for read and write operations arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled.

Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.

Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response.

Enable a multi-region CloudTrail that logs management events for read and write in all regions.

Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4 •AWS-Account-Security-Onboarding: Enable as part of Organization trail •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.2, 12.6 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-01 •NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c

PASS low cloudtrail us-east-2 cloudtrail_s3_dataevents_read_enabled CloudTrail trail records S3 object-level read events for all S3 buckets arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations.

Without object-level read logging, S3 access is opaque. Attackers or insiders can exfiltrate data via GetObject without audit trails, eroding confidentiality and hindering forensics, anomaly detection, and incident response.

Enable CloudTrail data events for S3 objects with ReadOnly (or All) across all current and future buckets. Use a multi-Region trail, centralize logs in an encrypted bucket with lifecycle retention, and integrate monitoring/alerts to support defense in depth and accountable access.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 4.9 •SOC2: cc_2_1, cc_7_2 •CIS-1.4: 3.11 •CIS-1.5: 3.11 •GDPR: article_30 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i •CIS-2.0: 3.11 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail •CIS-5.0: 3.9 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Account-Security-Onboarding: Confirm that logs are present in S3 bucket and SIEM •CIS-3.0: 3.9 •ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4 •CIS-6.0: 4.9 •NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ProwlerThreatScore-1.0: 3.1.6 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 •FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 •CIS-4.0.1: 3.9 •NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla

PASS low cloudtrail us-east-2 cloudtrail_s3_dataevents_write_enabled CloudTrail trail records all S3 object-level API operations for all buckets arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations.

Without object-level write logging, unauthorized or accidental changes and deletions can go unobserved, undermining data integrity and availability. Forensics lose visibility into who modified or removed objects, hindering detection of ransomware, rogue automation, or insider tampering.

Enable CloudTrail S3 data events for object-level write (and optionally read) across all buckets on a multi-Region trail. Apply least privilege to log storage, set lifecycle retention, and integrate alerts. Use advanced selectors to target sensitive buckets/operations for cost control and defense in depth.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 4.8 •SOC2: cc_2_1, cc_7_2, pi_1_2 •CIS-1.4: 3.10 •CIS-1.5: 3.10 •GDPR: article_30 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i •CIS-2.0: 3.10 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail •CIS-5.0: 3.8 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.7, 10.2.1.2.7, 10.2.1.3.7, 10.2.1.4.7, 10.2.1.5.7, 10.2.1.6.7, 10.2.1.7.7, 10.2.1.7, 10.2.2.7, 10.3.1.7, 10.6.3.7, 5.3.4.7, A1.2.1.7 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM •CIS-3.0: 3.8 •ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4 •CIS-6.0: 4.8 •NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5 •CCC-v2025.10: CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.1.5 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 •FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 •CIS-4.0.1: 3.8 •NIS2: 3.2.3.c, 3.2.3.g •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_alarm_state_configured CloudWatch metric alarm has actions configured for the ALARM state arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alert CloudWatch metric alarm scrivas-dev-api-error-alert has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_7, ip_8, dp_4 •PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_alarm_state_configured CloudWatch metric alarm has actions configured for the ALARM state arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alert CloudWatch metric alarm scrivas-stage-error-alert has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_7, ip_8, dp_4 •PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_alarm_state_configured CloudWatch metric alarm has actions configured for the ALARM state arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prod CloudWatch metric alarm scrivas_prod has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_7, ip_8, dp_4 •PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_enabled CloudWatch metric alarm has actions enabled arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alert CloudWatch metric alarm scrivas-dev-api-error-alert has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_8, dp_4 •CCC-v2025.10: CCC.LB.CN06.AR01 •SecNumCloud-3.2: 16.2

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_enabled CloudWatch metric alarm has actions enabled arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alert CloudWatch metric alarm scrivas-stage-error-alert has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_8, dp_4 •CCC-v2025.10: CCC.LB.CN06.AR01 •SecNumCloud-3.2: 16.2

PASS high cloudwatch us-east-2 cloudwatch_alarm_actions_enabled CloudWatch metric alarm has actions enabled arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prod CloudWatch metric alarm scrivas_prod has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_8, dp_4 •CCC-v2025.10: CCC.LB.CN06.AR01 •SecNumCloud-3.2: 16.2

FAIL medium cloudwatch us-east-2 cloudwatch_changes_to_network_acls_alarm_configured CloudWatch log metric filter and alarm exist for Network ACL (NACL) change events arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Absent monitoring of NACL changes reduces detection of policy tampering, risking loss of confidentiality (opened ingress/egress), degraded network integrity (lateral movement, bypassed segmentation), and reduced availability (traffic blackholes or lockouts).

Implement a CloudWatch Logs metric filter and alarm for NACL change events from CloudTrail and route alerts to responders. Enforce least privilege on NACL management, require change control, and use defense in depth with configuration monitoring and flow logs to validate and monitor network posture.

•CIS-7.0: 5.11 •SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 •CIS-1.4: 4.11 •CIS-1.5: 4.11 •MITRE-ATTACK: T1496 •ISO27001-2013: A.12.4.D •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •HIPAA: 164_308_a_6_i •CIS-2.0: 4.11 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ra_5, cm_1, dp_4 •CIS-5.0: 4.11 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 •NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b •CIS-3.0: 4.11 •CIS-6.0: 5.11 •NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 •CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.12 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-2, ca-7, ir-4 •CIS-4.0.1: 4.11 •NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 6.4.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_changes_to_network_gateways_alarm_configured CloudWatch Logs metric filter and alarm exist for changes to network gateways arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without this monitoring, gateway changes can expose private networks to the Internet or break connectivity. Adversaries or mistakes can enable data exfiltration, bypass network inspection, and trigger outages via deletions or detachments, impacting confidentiality and availability.

Send CloudTrail to CloudWatch Logs and create a metric filter for the listed gateway events with an alarm that notifies responders. Enforce least privilege for gateway modifications, require change approvals, and route alerts to monitored channels as part of defense in depth.

•CIS-7.0: 5.12 •SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 •CIS-1.4: 4.12 •CIS-1.5: 4.12 •MITRE-ATTACK: T1496 •ISO27001-2013: A.12.4.C •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B •HIPAA: 164_308_a_6_i •CIS-2.0: 4.12 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ra_5, ae_2, ae_3, cm_1, dp_4 •CIS-5.0: 4.12 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 •NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b •CIS-3.0: 4.12 •CIS-6.0: 5.12 •NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 •CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.13 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ir-4 •CIS-4.0.1: 4.12 •NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_changes_to_network_route_tables_alarm_configured Account monitors VPC route table changes with a CloudWatch Logs metric filter and alarm arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without monitoring of route table changes, unauthorized or accidental edits can redirect traffic, bypass inspection, or blackhole routes, impacting confidentiality (exfiltration), integrity (tampered paths), and availability (outages from misrouted traffic).

Implement a CloudWatch Logs metric filter and alarm on CloudTrail for these route table events and notify responders. Enforce least privilege for route modifications, require change control, and apply defense in depth with VPC Flow Logs and guardrails to prevent and quickly contain unsafe routing changes.

•CIS-7.0: 5.13 •SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 •CIS-1.4: 4.13 •CIS-1.5: 4.13 •MITRE-ATTACK: T1496 •ISO27001-2013: A.12.4.B •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, COS-03.02B, PSS-04.01B •HIPAA: 164_308_a_6_i •CIS-2.0: 4.13 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ae_2, ae_3, cm_1, dp_4 •CIS-5.0: 4.13 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 •NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b •CIS-3.0: 4.13 •CIS-6.0: 5.13 •NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 •CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.14 •FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ir-4 •CIS-4.0.1: 4.13 •NIS2: 2.2.3, 3.2.3.a, 3.2.3.f, 3.2.4, 6.4.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_changes_to_vpcs_alarm_configured AWS account has a CloudWatch Logs metric filter and alarm for VPC changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on VPC changes, unauthorized or accidental edits to routes, peering, or attributes can go unnoticed, exposing private networks and enabling data exfiltration (C), lateral movement and traffic tampering (I), and outages from misrouted or bridged networks (A).

Create a CloudWatch Logs metric filter and alarm on CloudTrail for critical VPC change events, and notify responders. Apply least privilege to network changes, require change approvals, and use defense in depth (segmentation, route controls) to prevent and contain unauthorized modifications.

•CIS-7.0: 5.14 •SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 •CIS-1.4: 4.14 •CIS-1.5: 4.14 •MITRE-ATTACK: T1496 •ISO27001-2013: A.12.4.A •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B •HIPAA: 164_308_a_6_i •CIS-2.0: 4.14 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ra_5, ae_2, cm_1 •CIS-5.0: 4.14 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 •NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b •CIS-3.0: 4.14 •CIS-6.0: 5.14 •NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 •CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.15 •ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ir-4 •CIS-4.0.1: 4.14 •NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium cloudwatch us-east-2 cloudwatch_cross_account_sharing_disabled CloudWatch does not allow cross-account sharing arn:aws:iam:us-east-2:716468089330:role CloudWatch doesn't allow cross-account sharing.

Granting other accounts visibility into observability data reduces confidentiality and enables reconnaissance. Adversaries or over-privileged partners can map architectures, profile workloads, and spot alerting gaps, increasing chances of lateral movement and evasion.

Disable cross-account sharing unless strictly required. If needed, restrict access to specific trusted accounts, scope read-only permissions to only necessary resources, and use a dedicated monitoring account. Apply least privilege and separation of duties, and regularly audit role trust and access patterns.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01 •ENS-RD2022: op.acc.4.aws.iam.1

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* Log Group /aws/guardduty/malware-scan-events does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* Log Group scrivas-gate-prod does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* Log Group scrivas-backend-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* Log Group scrivas-search-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* Log Group scrivas-patient-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* Log Group vpc_logs does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* Log Group scrivas-backend-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* Log Group scrivas-patient-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* Log Group scrivas-gate-stage does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* Log Group scrivas-search-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* Log Group scrivas-gate-dev does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* Log Group scrivas-patient-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* Log Group scrivas-search-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* Log Group ec2-docker-logs does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* Log Group scrivas-backend-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* Log Group /aws/vpc/flow-logs/us-east-2 does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* Log Group aws-cloudtrail-logs-716468089330-e5f9b539 does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* Log Group RDSOSMetrics does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_kms_encryption_enabled CloudWatch log group is encrypted with an AWS KMS key arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* Log Group /aws/eks/scrivas-stage/cluster does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_3, pi_1_4 •MITRE-ATTACK: T1040 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_5 •NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 •PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 •NIST-800-53-Revision-4: au_9, sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1, 12.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: au-9, sc-28 •FedRAMP-Low-Revision-4: au-9 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* No secrets found in /aws/guardduty/malware-scan-events log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* Potential secrets found in log group scrivas-gate-prod in log stream gate-api at 2026-06-10T04:40:33.598-04:00 - Postgres URL with hardcoded password on line 1; at 2026-06-10T04:42:34.736-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* No secrets found in scrivas-backend-prod-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* No secrets found in scrivas-search-prod-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* Potential secrets found in log group scrivas-patient-prod-env in log stream patient-api at 2026-05-21T23:52:27.259-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* No secrets found in vpc_logs log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* No secrets found in scrivas-backend-stage-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* Potential secrets found in log group scrivas-patient-stage-env in log stream patient-api at 2026-04-07T16:47:19.389-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* Potential secrets found in log group scrivas-gate-stage in log stream gate-api at 2026-04-07T13:11:28.464-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* No secrets found in scrivas-search-stage-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* Potential secrets found in log group scrivas-gate-dev in log stream gate-api at 2026-03-17T09:06:17.190-04:00 - Postgres URL with hardcoded password on line 1; at 2026-03-17T09:33:01.067-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* Potential secrets found in log group scrivas-patient-dev-env in log stream patient-api at 2026-03-05T14:20:05.593-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* No secrets found in scrivas-search-dev-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* No secrets found in ec2-docker-logs log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* Potential secrets found in log group scrivas-backend-dev-env in log stream encounter-api at 2026-02-24T08:31:46.315-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* No secrets found in /aws/vpc/flow-logs/us-east-2 log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* No secrets found in aws-cloudtrail-logs-716468089330-e5f9b539 log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* No secrets found in RDSOSMetrics log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS medium cloudwatch us-east-2 cloudwatch_log_group_no_secrets_in_logs CloudWatch log group contains no secrets in its log events arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* No secrets found in /aws/eks/scrivas-stage/cluster log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DATA-05

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* Log Group /aws/guardduty/malware-scan-events is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* Log Group scrivas-gate-prod is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* Log Group scrivas-backend-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* Log Group scrivas-search-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* Log Group scrivas-patient-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* Log Group vpc_logs is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* Log Group scrivas-backend-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* Log Group scrivas-patient-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* Log Group scrivas-gate-stage is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* Log Group scrivas-search-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* Log Group scrivas-gate-dev is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* Log Group scrivas-patient-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* Log Group scrivas-search-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* Log Group ec2-docker-logs is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* Log Group scrivas-backend-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* Log Group /aws/vpc/flow-logs/us-east-2 is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* Log Group aws-cloudtrail-logs-716468089330-e5f9b539 is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* Log Group RDSOSMetrics is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

PASS high cloudwatch us-east-2 cloudwatch_log_group_not_publicly_accessible CloudWatch Log Group is not publicly accessible arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* Log Group /aws/eks/scrivas-stage/cluster is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

•SOC2: pi_1_4 •KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 •NIST-CSF-2.0: ds_5 •CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 •SecNumCloud-3.2: 12.7 •ISO27001-2022: A.8.15, A.8.16 •NIS2: 3.2.3.c

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* Log Group /aws/guardduty/malware-scan-events has less than 365 days retention period (90 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* Log Group scrivas-gate-prod comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* Log Group scrivas-backend-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* Log Group scrivas-search-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* Log Group scrivas-patient-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* Log Group vpc_logs has less than 365 days retention period (30 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* Log Group scrivas-backend-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* Log Group scrivas-patient-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* Log Group scrivas-gate-stage comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* Log Group scrivas-search-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* Log Group scrivas-gate-dev comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* Log Group scrivas-patient-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* Log Group scrivas-search-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* Log Group ec2-docker-logs comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* Log Group scrivas-backend-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* Log Group /aws/vpc/flow-logs/us-east-2 comply with 365 days retention period since it has 365 days.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* Log Group aws-cloudtrail-logs-716468089330-e5f9b539 comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

FAIL medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* Log Group RDSOSMetrics has less than 365 days retention period (30 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

PASS medium cloudwatch us-east-2 cloudwatch_log_group_retention_policy_specific_days_enabled CloudWatch log group has a retention policy of at least the configured minimum days or never expires arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* Log Group /aws/eks/scrivas-stage/cluster comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

•SOC2: cc_7_2, cc_7_3, cc_c_1_2 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B •HIPAA: 164_312_b •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 •PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 •NIST-800-53-Revision-4: au_11, si_12 •NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 •ENS-RD2022: op.exp.8.r3.aws.cw.1 •CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1 •PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c •ProwlerThreatScore-1.0: 3.2.2 •ISO27001-2022: A.8.15, A.8.16 •FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 •FedRAMP-Low-Revision-4: au-11 •NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled CloudWatch Logs metric filter and alarm exist for AWS Config configuration changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on AWS Config changes, actions like StopConfigurationRecorder or DeleteDeliveryChannel can silently suspend recording and delivery.

This degrades the integrity and availability of configuration audit data, enabling undetected changes and delaying incident response.

Create a CloudWatch Logs metric filter and alarm for config.amazonaws.com events (StopConfigurationRecorder, DeleteDeliveryChannel, PutDeliveryChannel, PutConfigurationRecorder). Route CloudTrail to Logs, notify responders, and enforce least privilege and separation of duties on Config changes to prevent abuse.

•CIS-7.0: 5.9 •SOC2: cc_5_2 •CIS-1.4: 4.9 •CIS-1.5: 4.9 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.F •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •CIS-2.0: 4.9 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_7, dp_4 •CIS-5.0: 4.9 •CIS-3.0: 4.9 •CIS-6.0: 5.9 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.10 •ISO27001-2022: A.8.15, A.8.16 •CIS-4.0.1: 4.9 •NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled CloudWatch Logs metric filter and alarm exist for CloudTrail configuration changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Absent this monitoring, logging can be stopped or altered without notice, eroding visibility.

That enables covert activity and data exfiltration without audit evidence, harming confidentiality, the integrity of records, and the availability of reliable logs for detection and forensics.

Implement a metric filter for trail configuration events and a linked alarm that notifies response channels.

Apply least privilege and separation of duties for trail changes, add defense in depth with centralized logging and validation, and regularly test that alerts fire.

•CISA: your-data-2 •CIS-7.0: 5.5 •SOC2: cc_5_2 •CIS-1.4: 4.5 •CIS-1.5: 4.5 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.J •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, SIM-03.07B, COM-04.01AC, PSS-04.01B •CIS-2.0: 4.5 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_3, cm_7, dp_4 •CIS-5.0: 4.5 •AWS-Account-Security-Onboarding: Critical alert on cloudtrail settings changes •CIS-3.0: 4.5 •ENS-RD2022: op.exp.8.aws.ct.2, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3 •CIS-6.0: 5.5 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR01, CCC.Logging.CN07.AR01, CCC.LB.CN04.AR01 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.6 •ISO27001-2022: A.8.15, A.8.16 •CIS-4.0.1: 4.5 •NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.2.4, 3.5.4, 7.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_authentication_failures Account has a CloudWatch Logs metric filter and alarm for AWS Management Console authentication failures arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Absent visibility into failed console logins enables undetected brute-force and credential-stuffing attempts, extending attacker dwell time.

Successful guesses can grant console access, risking data confidentiality, configuration integrity, and availability through destructive changes.

Implement a log metric filter for ConsoleLogin failures and attach a CloudWatch alarm with actionable notifications. Tune thresholds to reduce noise and route alerts to incident response.

Apply least privilege and enforce MFA to limit impact, and correlate alerts with source IP and user context.

•CIS-7.0: 5.6 •SOC2: pi_1_3 •CIS-1.4: 4.6 •CIS-1.5: 4.6 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.I •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, PSS-04.01B •HIPAA: 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii •CIS-2.0: 4.6 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ra_5, ip_7, ip_8, pt_1, ae_2, cm_1, cm_3, cm_7, dp_4 •CIS-5.0: 4.6 •AWS-Account-Security-Onboarding: Alert on rise of ConsoleLoginFailures events •CIS-3.0: 4.6 •ENS-RD2022: op.exp.8.aws.ct.5 •CIS-6.0: 5.6 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.7 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.6 •NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 7.2.b

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_aws_organizations_changes CloudWatch Logs metric filter and alarm exist for AWS Organizations changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on AWS Organizations changes, attackers or misconfigurations can silently alter governance, enabling unauthorized access and policy bypass. They could create/remove accounts, change or detach SCPs, or delete the organization, risking data exposure (C), privilege escalation (I), and service disruption (A).

Send CloudTrail events to CloudWatch Logs, add a metric filter for organizations.amazonaws.com change events, and attach an alarm that notifies responders. Enforce least privilege and separation of duties for org admins, require MFA and approvals, and regularly test alerts to ensure timely detection and response.

•CIS-7.0: 5.15 •SOC2: cc_5_2 •CIS-1.4: 4.15 •CIS-1.5: 4.15 •MITRE-ATTACK: T1496 •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •CIS-2.0: 4.15 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ae_3, cm_7 •CIS-5.0: 4.15 •CIS-3.0: 4.15 •CIS-6.0: 5.15 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.16 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.15 •NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk Account has a CloudWatch log metric filter and alarm for disabling or scheduled deletion of customer-managed KMS keys arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Missing alerts on CMK disablement or scheduled deletion undermines availability and integrity: encrypted data may become undecryptable, backups unusable, and recovery impossible. Attackers or insiders can change key states unnoticed, causing outages and irreversible data loss.

Establish CloudWatch metric filters and alarms for DisableKey and ScheduleKeyDeletion CloudTrail events to enable rapid response.
- Apply least privilege to KMS administration
- Enforce change control and separation of duties
- Use deletion waiting periods and monitor all regions

•CIS-7.0: 5.7 •CIS-1.4: 4.7 •CIS-1.5: 4.7 •MITRE-ATTACK: T1485, T1496 •GDPR: article_25 •ISO27001-2013: A.10.1.C, A.12.4.H •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.02AC, OIS-08.02B, HR-03.02AC, AM-01.01AC, AM-07.02B, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, CRY-05.02B, PSS-04.01B •CIS-2.0: 4.7 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ae_2, cm_7 •CIS-5.0: 4.7 •CIS-3.0: 4.7 •ENS-RD2022: op.exp.10.aws.cmk.4, op.exp.10.aws.cmk.5 •CIS-6.0: 5.7 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.KeyMgmt.CN01.AR01 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.8 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.7 •NIS2: 3.2.3.c, 3.2.3.g, 3.5.4, 7.2.b

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_for_s3_bucket_policy_changes CloudWatch log metric filter and alarm exist for S3 bucket policy changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on S3 policy and ACL changes, unauthorized modifications can go unnoticed, weakening confidentiality and integrity. Misuse could expose buckets publicly, grant write/delete access, or alter replication paths, enabling data exfiltration and destructive actions.

Establish and maintain metric filters and alarms for S3 bucket policy, ACL, CORS, lifecycle, and replication changes. Route alerts to monitored channels and integrate with SIEM. Enforce least privilege, require change reviews, and use defense in depth to prevent and quickly detect unsafe bucket policy changes.

•CIS-7.0: 5.8 •SOC2: cc_5_2 •CIS-1.4: 4.8 •CIS-1.5: 4.8 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.G •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •CIS-2.0: 4.8 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: pt_1, ae_1, ae_2, cm_7 •CIS-5.0: 4.8 •CIS-3.0: 4.8 •CIS-6.0: 5.8 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR02 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.9 •ISO27001-2022: A.8.15, A.8.16 •CIS-4.0.1: 4.8 •NIS2: 2.2.3, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_policy_changes CloudWatch Logs metric filter and alarm exist for IAM policy changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Absent alerting on IAM policy changes, privilege modifications can go unnoticed, enabling privilege escalation, hidden backdoors, or permission revocations. This threatens confidentiality and integrity, and may impact availability if critical access is removed or misconfigured.

Create a metric filter for IAM policy create/update/delete and attach/detach events with an alarm to notify responders.
- Enforce least privilege and separation of duties for policy changes
- Require approvals and central logging across Regions/accounts
- Integrate alerts with incident response

•CIS-7.0: 5.4 •SOC2: cc_5_2, pi_1_3 •CIS-1.4: 4.4 •CIS-1.5: 4.4 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.K •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •CIS-2.0: 4.4 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_3, ae_2, cm_7 •CIS-5.0: 4.4 •CIS-3.0: 4.4 •ENS-RD2022: op.exp.8.aws.ct.5 •CIS-6.0: 5.4 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •PCI-3.2.1: 8.1, 8.1.2 •ProwlerThreatScore-1.0: 3.3.5 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.4 •NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_root_usage Account has a CloudWatch Logs metric filter and alarm for root account usage arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on root activity, full-privilege actions can proceed unnoticed, impacting:
- confidentiality via data access/exfiltration
- integrity via policy/config tampering
- availability via deletions or shutdowns
Delayed detection increases blast radius and persistence.

Enable real-time alerts for root activity using a log metric filter and a high-priority alarm with notifications.

Reduce exposure: enforce least privilege, keep root for break-glass with MFA, disable root access keys, and route alerts into incident response for defense in depth.

•CIS-7.0: 5.3 •SOC2: pi_1_3 •CIS-1.4: 4.3 •CIS-1.5: 4.3 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.L •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01B, IAM-03.03B, IAM-06.04B, IAM-06.05B, PSS-04.01B •HIPAA: 164_308_a_6_i, 164_308_a_6_ii •CIS-2.0: 4.3 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ip_8, ae_2, cm_7, dp_4 •CIS-5.0: 4.3 •AWS-Account-Security-Onboarding: Critical alert on every root user activity •CIS-3.0: 4.3 •ENS-RD2022: op.exp.8.aws.ct.5, op.exp.8.aws.cw.1 •CIS-6.0: 5.3 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01 •SecNumCloud-3.2: 12.9 •PCI-3.2.1: 7.2, 7.2.1 •ProwlerThreatScore-1.0: 3.3.4 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-IAM-04, AISF-DETECT-05 •CIS-4.0.1: 4.3 •NIS2: 2.3.1, 3.2.1, 3.2.2, 3.2.3.c, 3.2.3.e, 3.2.3.g, 3.5.4, 7.2.b, 9.2.c.vii

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_security_group_changes CloudWatch Logs metric filter and alarm exist for security group changes arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on security group changes, unauthorized or mistaken rules can expose services to the Internet, enabling brute force and lateral movement (confidentiality, integrity). Deletions or restrictive edits can break connectivity (availability). Delayed detection increases attacker dwell time and impact.

Establish real-time alerts for security group modifications by sending CloudTrail to CloudWatch, creating metric filters and alarms, and notifying responders.
- Enforce least privilege on SG changes
- Use change management and tagging
- Centralize logs, test alarms, and maintain runbooks
- Layer with NACLs and WAF for defense in depth

•CIS-7.0: 5.10 •SOC2: cc_5_2 •CIS-1.4: 4.10 •CIS-1.5: 4.10 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.E •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B •CIS-2.0: 4.10 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_3, ip_8, ae_1, ae_2, cm_7, dp_4 •CIS-5.0: 4.10 •CIS-3.0: 4.10 •CIS-6.0: 5.10 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.11 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.10 •NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 11.5.2.d •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_sign_in_without_mfa CloudWatch log metric filter and alarm exist for Management Console sign-in without MFA arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on non-MFA console logins, successful use of stolen passwords can go undetected, enabling:
- Unauthorized console access and IAM changes
- Data exfiltration or deletion

Impacts: loss of confidentiality and integrity, and potential availability disruption.

Enforce MFA for all console-capable identities and maintain alerts for ConsoleLogin with MFAUsed != \"Yes\".

Apply least privilege, route alarms to monitored channels, and tune for SSO to reduce noise. Test alarms regularly and review coverage as part of defense in depth.

•CIS-7.0: 5.2 •CIS-1.4: 4.2 •CIS-1.5: 4.2 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.M •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-16.01B, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, IAM-09.02B, IAM-09.01AC, PSS-04.01B, PSS-05.01B, PSS-07.02B •CIS-2.0: 4.2 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •CIS-5.0: 4.2 •ASD-Essential-Eight-Nov 2023: E8-3.1 •CIS-3.0: 4.2 •ENS-RD2022: op.exp.8.aws.ct.5 •CIS-6.0: 5.2 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.3 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.2 •NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 9.2.c.vii, 11.7.2

FAIL medium cloudwatch us-east-2 cloudwatch_log_metric_filter_unauthorized_api_calls CloudWatch Logs metric filter and alarm exist for unauthorized API calls arn:aws:logs:us-east-2:716468089330:log-group No CloudWatch log groups found with metric filters or alarms associated.

Without alerting on unauthorized API calls, permission probing and failed access by compromised identities can go unnoticed. Attackers can enumerate services, pivot, and attempt privilege escalation, threatening data confidentiality and integrity.

Enable real-time alerting by adding a CloudWatch Logs metric filter for unauthorized errors (*UnauthorizedOperation, AccessDenied*) and associating it with an alarm that notifies responders.
- Enforce least privilege to reduce noise
- Integrate with IR tooling for defense in depth

•CIS-7.0: 5.1 •SOC2: pi_1_3 •CIS-1.4: 4.1 •CIS-1.5: 4.1 •MITRE-ATTACK: T1496 •GDPR: article_25 •ISO27001-2013: A.12.4.N •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-06.05B, PSS-04.01B •CIS-2.0: 4.1 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_3, ra_5, ip_7, ip_8, pt_1, ae_1, ae_2, cm_1, cm_3, cm_7, dp_4 •CIS-5.0: 4.1 •CIS-3.0: 4.1 •ENS-RD2022: op.exp.8.aws.ct.5 •CIS-6.0: 5.1 •NIST-CSF-1.1: cm_2, ra_5, sc_4 •CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02 •SecNumCloud-3.2: 12.9 •ProwlerThreatScore-1.0: 3.3.2 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-05 •CIS-4.0.1: 4.1 •NIS2: 3.2.3.c, 3.2.3.g, 3.2.4, 3.4.2.c, 3.5.4

FAIL high config us-east-2 config_delegated_admin_and_org_aggregator_all_regions AWS Config has a delegated administrator and an organization aggregator covering all AWS regions arn:aws:config:us-east-2:716468089330:config-aggregator/unknown AWS Config has no Organization Aggregator configured in any region (no delegated administrator registered for config.amazonaws.com).

Without an org-wide AWS Config aggregator and a delegated administrator, configuration data is fragmented across accounts and regions, compliance reporting is incomplete, and drift detection is delayed. Adversaries or misconfigurations can persist in unmonitored accounts, eroding audit readiness and regulatory posture.

Register a delegated administrator for AWS Config via AWS Organizations and create at least one Configuration Aggregator with an OrganizationAggregationSource that covers all AWS regions. This centralizes configuration data across the organization for unified compliance and audit reporting.

PASS medium config us-east-2 config_recorder_all_regions_enabled AWS Config recorder is enabled and not in failure state or disabled arn:aws:config:us-east-2:716468089330:recorder AWS Config recorder default is enabled.

Gaps in Config recording create blind spots. Changes in unmonitored Regions aren't captured, weakening integrity and auditability. Adversaries can alter resources or stage assets unnoticed, enabling misconfigurations and delaying incident response.

Enable AWS Config in every Region with continuous recording and maintain healthy recorder status.

•CIS-7.0: 4.3 •SOC2: cc_2_1, cc_3_1, cc_3_4, cc_8_1, pi_1_3 •CIS-1.4: 3.5 •CIS-1.5: 3.5 •MITRE-ATTACK: T1190, T1078, T1204, T1098, T1136, T1525, T1562, T1110, T1040, T1119, T1530, T1485, T1486, T1491, T1499, T1496, T1498 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: Config.1 •ISO27001-2013: A.12.4.P •KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OIS-05.01B, PS-02.01B, PS-02.01AS, PS-02.02AS, DEV-08.02B •HIPAA: 164_308_a_1_ii_a •CIS-2.0: 3.5 •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02 •GxP-EU-Annex-11: 10-change-and-configuration-management, 4.5-validation-development-quality, 4.6-validation-quality-performance •NIST-CSF-2.0: rm_1, po_3, po_4, ov_3, pt_1 •CIS-5.0: 3.3 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1 •AWS-Account-Security-Onboarding: Enable continuous recording for most of the resources, Confirm that records are present in central aggregator •CIS-3.0: 3.3 •ENS-RD2022: op.exp.1.aws.cfg.1, op.exp.1.aws.cfg.2, op.exp.3.aws.cfg.1, op.exp.3.r3.aws.cfg.1, op.mon.3.r2.aws.cfg.1, op.mon.3.r6.aws.cfg.1 •CIS-6.0: 4.3 •NIST-CSF-1.1: cm_2, am_1, ra_5, sc_4, ip_12 •CCC-v2025.10: CCC.Core.CN04.AR01 •SecNumCloud-3.2: 8.1, 12.2, 13.1, 14.2, 17.5, 18.3 •PCI-3.2.1: 2.4, 2.4.a, 10.5, 10.5.2, 11.5, 11.5.a, 11.5.b •ProwlerThreatScore-1.0: 3.3.1 •ISO27001-2022: A.5.16, A.5.22 •AWS-AI-Security-Framework-1.0: AISF-GOV-01 •CIS-4.0.1: 3.3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy, ksi-mla-07

PASS medium config us-east-2 config_recorder_using_aws_service_role AWS Config recorder uses the AWSServiceRoleForConfig service-linked role arn:aws:config:us-east-2:716468089330:recorder AWS Config recorder default is using AWSServiceRoleForConfig.

Using a custom or incorrect role can break recording or create blind spots, undermining the integrity and availability of configuration history. Over‑privileged roles weaken least privilege, increasing risk of unauthorized access, stealthy changes, and delayed incident response.

Use the AWS‑managed service‑linked role AWSServiceRoleForConfig for all recorders to enforce least privilege and consistent trust.

Avoid custom roles; restrict who can modify the recorder or role; monitor for drift and ensure recording remains enabled as part of defense in depth.

•KISA-ISMS-P-2023: 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, DEV-08.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2 •NIST-CSF-2.0: rm_1, po_4, ov_3, pt_1 •SecNumCloud-3.2: 13.1 •AWS-AI-Security-Framework-1.0: AISF-GOV-01 •FedRAMP-20x-KSI-Low-25.05C: ksi-piy

FAIL medium drs us-east-1 drs_job_exist Region has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery job arn:aws:drs:us-east-1:716468089330:recovery-job DRS is not enabled for this region.

Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime.

Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery.

•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490 •KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2 •KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2 •NIST-CSF-2.0: be_5, ip_9 •ENS-RD2022: op.cont.3.aws.drs.1

FAIL medium drs us-east-2 drs_job_exist Region has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery job arn:aws:drs:us-east-2:716468089330:recovery-job DRS is not enabled for this region.

Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime.

Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery.

•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490 •KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2 •KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2 •NIST-CSF-2.0: be_5, ip_9 •ENS-RD2022: op.cont.3.aws.drs.1

PASS medium dynamodb us-east-2 dynamodb_table_autoscaling_enabled DynamoDB table uses on-demand capacity or has auto scaling enabled for read and write capacity units arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock •ManagedBy=terraform •Purpose=terraform-backend-lock DynamoDB table terraform-lock automatically scales capacity on demand.

Insufficient capacity scaling causes throttling that degrades availability and increases latency.

Sustained throttling can trigger retry storms, timeouts, and backlogs, risking missed writes or out-of-order processing that impacts data integrity and drives operational costs.

Adopt elastic capacity: prefer on-demand for unpredictable traffic, or use PROVISIONED with auto scaling on both reads and writes.

Define safe utilization targets and bounds, monitor consumption, and plan for bursts to maintain availability and resilience over manual fixed throughput.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: ds_4

FAIL medium dynamodb us-east-2 dynamodb_table_deletion_protection_enabled DynamoDB table has deletion protection enabled arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock •ManagedBy=terraform •Purpose=terraform-backend-lock DynamoDB table terraform-lock does not have deletion protection enabled.

Without deletion protection, tables can be removed by authorized actions or misconfigured automation, causing irrecoverable data loss and service outage. This impacts integrity and availability, and increases the blast radius of compromised credentials or mistaken runbooks.

Enable deletion protection on critical tables.
- Enforce least privilege to restrict who can modify this setting
- Require change control to disable it before planned deletes
- Combine with PITR and backups for defense in depth
- Use automation to make this the default for new tables

•AWS-Foundational-Security-Best-Practices: DynamoDB.6, DynamoDB.7 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: AM-07.02B •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: ds_3, ds_4, pt_5 •SecNumCloud-3.2: 17.4

FAIL medium dynamodb us-east-2 dynamodb_table_protected_by_backup_plan DynamoDB table is protected by a backup plan arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock •ManagedBy=terraform •Purpose=terraform-backend-lock DynamoDB table terraform-lock is not protected by a backup plan.

Without a backup plan, table data lacks governed copies, harming availability and integrity. Accidental deletes, corrupt writes, or malicious actions can become unrecoverable, and RPO/RTO worsen. You also forfeit cross-Region/account copies and immutability features, increasing downtime and data loss.

Place all critical tables under an AWS Backup backup plan following defense in depth and least privilege:
- Use tag-based assignments for coverage at scale
- Define schedules, retention, and cross-Region/account copies
- Enable Vault Lock for immutability
- Regularly test restores and restrict backup deletion

•AWS-Foundational-Security-Best-Practices: DynamoDB.4 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: be_5, ds_4, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.9, 10.3.3.11 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR02 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 4.1.4, 12.1.2.c, 12.2.2.b

PASS medium dynamodb us-east-2 dynamodb_tables_kms_cmk_encryption_enabled DynamoDB table is encrypted at rest with AWS KMS arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock •ManagedBy=terraform •Purpose=terraform-backend-lock DynamoDB table terraform-lock has KMS encryption enabled with key ec1c4624-868a-4759-a6cb-78a0853bd17f.

Relying on the default service-owned key reduces control over confidentiality: no custom key policies, limited auditability, and no independent rotation or disablement. This weakens least-privilege enforcement and incident response, and can impede meeting mandates that require customer-controlled keys.

Encrypt tables with KMS keys in your account-prefer customer-managed keys for sensitive data.

  • Enforce least-privilege key policies and scope grants
  • Enable rotation and monitor key usage
  • Separate duties for key admins vs data users
  • Restrict which principals can use the key for DynamoDB

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •MITRE-ATTACK: T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, IAM-09.03B, IAM-09.02AC, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1 •NIST-800-171-Revision-2: 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.11, 3.5.1.12, 8.3.2.18, 8.3.2.19 •NIST-800-53-Revision-4: sc_13 •NIST-800-53-Revision-5: au_9_3, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.dydb.1 •AWS-Foundational-Technical-Review: SDAT-002 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.5, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05

FAIL medium dynamodb us-east-2 dynamodb_tables_pitr_enabled DynamoDB table has point-in-time recovery (PITR) enabled arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock •ManagedBy=terraform •Purpose=terraform-backend-lock DynamoDB table terraform-lock does not have point-in-time recovery enabled.

Without PITR, unintended or malicious writes/deletes cannot be precisely rolled back, leading to permanent data loss and corrupted state. Failures from buggy deployments, compromised credentials, or faulty batch jobs reduce data integrity and availability, and prolong incident recovery and forensic analysis.

Enable PITR on critical tables and set a recovery window aligned to your RPO (1-35 days). Enforce least privilege on who can modify backup settings. Regularly test restores and monitor backup status. Embed PITR in IaC and change control for consistency, and apply defense in depth with on-demand backups for key milestones.

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: DynamoDB.2 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_13_2 •ASD-Essential-Eight-Nov 2023: E8-8.1, E8-8.2 •PCI-4.0: 10.3.3.10, 10.5.1.6, 3.2.1.5, 3.3.1.1.5, 3.3.1.3.5, 3.3.2.5, 3.3.3.5 •NIST-800-53-Revision-4: cp_9, cp_10, si_12 •NIST-800-53-Revision-5: cp_1_2, cp_2_5, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, sc_5_2, si_13_5 •NIST-CSF-1.1: ip_4, ip_9, rp_1, rp_1 •AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03 •SecNumCloud-3.2: 12.5 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c •FedRamp-Moderate-Revision-4: cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: cp-9, cp-10, sc-5 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna, ksi-rpl

PASS medium ec2 us-east-1 ec2_ami_account_block_public_access AMI block public access is enabled at the account level arn:aws:ec2:us-east-2:716468089330:account AMI Block Public Access is enabled in us-east-1.

Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors.

Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly.

PASS medium ec2 us-east-2 ec2_ami_account_block_public_access AMI block public access is enabled at the account level arn:aws:ec2:us-east-2:716468089330:account AMI Block Public Access is enabled in us-east-2.

Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors.

Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly.

PASS high ec2 us-east-2 ec2_ebs_default_encryption EBS default encryption is enabled arn:aws:ec2:us-east-2:716468089330:volume EBS Default Encryption is activated.

Without encryption by default, data on new EBS volumes and snapshots may be stored in plaintext. A compromised account or mis-shared snapshot can expose disk contents, enabling data exfiltration, offline analysis, and loss of confidentiality.

Enable EBS encryption by default in every region and select a customer-managed KMS key. Apply least privilege to key use, rotate keys, and monitor access. Enforce encrypted volume creation with organizational guardrails and secure templates as defense in depth.

•CISA: your-systems-3, your-data-1 •CIS-7.0: 6.1.1 •MITRE-ATTACK: T1119 •AWS-Foundational-Security-Best-Practices: EC2.7 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 EBS Snapshot vol-07bd5c93cb1ce9a93 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c EBS Snapshot vol-049bd3b9fbf52844c is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 EBS Snapshot vol-00abcebca9a065189 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 EBS Snapshot vol-0fc1a9c187da02554 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a EBS Snapshot vol-0655f47f37fd9283a is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c EBS Snapshot vol-06fd9a9b51f0c386c is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 EBS Snapshot vol-0ca0556d08ef42c06 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b EBS Snapshot vol-03f685457f48aef3b is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

PASS high ec2 us-east-2 ec2_ebs_volume_encryption EBS volume is encrypted arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 EBS Snapshot vol-096ef60e2b2bc8850 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.

Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.

Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_5 •CIS-1.4: 2.2.1 •CIS-1.5: 2.2.1 •MITRE-ATTACK: T1119 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: EC2.3 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •CIS-2.0: 2.2.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-g, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •CIS-5.0: 5.1.1 •NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.20, 8.3.2.34 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 •CIS-3.0: 2.2.1 •ENS-RD2022: mp.si.2.aws.kms.1 •CIS-6.0: 6.1.1 •NIST-CSF-1.1: ds_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ProwlerThreatScore-1.0: 4.2.1 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-28 •CIS-4.0.1: 5.1.1

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 EBS Volume vol-07bd5c93cb1ce9a93 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c EBS Volume vol-049bd3b9fbf52844c is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 EBS Volume vol-00abcebca9a065189 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 EBS Volume vol-0fc1a9c187da02554 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a EBS Volume vol-0655f47f37fd9283a is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c EBS Volume vol-06fd9a9b51f0c386c is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 EBS Volume vol-0ca0556d08ef42c06 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b EBS Volume vol-03f685457f48aef3b is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL medium ec2 us-east-2 ec2_ebs_volume_protected_by_backup_plan EBS volume is protected by a backup plan arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 EBS Volume vol-096ef60e2b2bc8850 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

•AWS-Foundational-Security-Best-Practices: EC2.28 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 3.1, 3.1.c •ISO27001-2022: A.8.14 •NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 Snapshots not found for the EBS volume vol-07bd5c93cb1ce9a93.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c Snapshots not found for the EBS volume vol-049bd3b9fbf52844c.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 Snapshots not found for the EBS volume vol-00abcebca9a065189.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 Snapshots not found for the EBS volume vol-0fc1a9c187da02554.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a Snapshots not found for the EBS volume vol-0655f47f37fd9283a.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c Snapshots not found for the EBS volume vol-06fd9a9b51f0c386c.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 Snapshots not found for the EBS volume vol-0ca0556d08ef42c06.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b Snapshots not found for the EBS volume vol-03f685457f48aef3b.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

FAIL high ec2 us-east-2 ec2_ebs_volume_snapshots_exists EBS volume has at least one snapshot arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 Snapshots not found for the EBS volume vol-096ef60e2b2bc8850.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures

•SOC2: cc_7_5 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •ASD-Essential-Eight-Nov 2023: E8-8.1 •PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 •AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 •SecNumCloud-3.2: 12.5

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-008ec7fbfb6122115 •Name=ML_dev Elastic IP 16.58.108.209 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0f1b179c7dbcd4a49 •Name=Netbird_elasticip Elastic IP 16.59.189.218 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b3287d784d49d661 •Name=Scrivas_stage_env Elastic IP 18.118.91.126 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b8681b277d57fe92 •Name=scrivas-dev-env Elastic IP 3.14.230.56 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-096b94ac565c27327 •Name=Ml_prod_ip Elastic IP 3.147.5.202 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-02269883e142e58a1 •Name=scrivas_prod_env Elastic IP 3.150.90.196 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_elastic_ip_unassigned Elastic IP is associated with an instance or network interface arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0dfd7e61faef43c26 •Name=ML_stage Elastic IP 52.14.227.224 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

•CISA: your-systems-1, your-surroundings-1 •AWS-Foundational-Security-Best-Practices: EC2.12 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_4_1 •NIST-CSF-1.1: ds_3 •FFIEC: d1-g-it-b-1 •PCI-3.2.1: 2.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_account_imdsv2_enabled IMDSv2 is required by default for EC2 instances at the account level arn:aws:ec2:us-east-2:716468089330:account IMDSv2 is not enabled by default for EC2 instances.

Without a default of IMDSv2, new instances may enable IMDSv1, exposing metadata via simple HTTP. SSRF or proxy misconfigs can steal temporary IAM credentials, enabling data exfiltration (confidentiality), unauthorized API changes (integrity), and lateral movement that can disrupt services (availability).

Enforce IMDSv2 at the account level in every Region by setting http_tokens to required. Add guardrails with SCP/IAM conditions. Standardize AMIs and launch templates to require tokens, validate workload compatibility, and apply least privilege to instance roles for defense in depth. For containers, prefer hop limit 2.

•KISA-ISMS-P-2023: 2.6.2, 2.10.2 •C5-2025: OPS-25.01B •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.i

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

FAIL low ec2 us-east-2 ec2_instance_detailed_monitoring_enabled EC2 instance has detailed monitoring enabled arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 •NIS2: 3.2.3.h

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_instance_imdsv2_enabled EC2 instance requires IMDSv2 or has the instance metadata service disabled arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads

•CIS-7.0: 6.7 •SOC2: cc_7_2 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: EC2.8 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •CIS-2.0: 5.6 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.7 •NIST-800-171-Revision-2: 3_12_4 •PCI-4.0: 8.2.8.4 •NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 •CIS-3.0: 5.6 •CIS-6.0: 6.7 •NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 •ProwlerThreatScore-1.0: 4.1.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-3, ca-7 •CIS-4.0.1: 5.7 •NIS2: 6.7.2.i •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b at IP 16.58.108.209 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db is not internet facing with an instance profile.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e at IP 3.14.230.56 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 at IP 52.14.227.224 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb at IP 18.118.91.126 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd at IP 3.150.90.196 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high ec2 us-east-2 ec2_instance_internet_facing_with_instance_profile EC2 instance is not internet-facing with an instance profile attached arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 at IP 3.147.5.202 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •ENS-RD2022: mp.com.4.aws.vpc.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_managed_by_ssm EC2 instance is managed by AWS Systems Manager or not running arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

•CISA: your-systems-1 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.1 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 •ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 •NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 •SecNumCloud-3.2: 8.1, 12.10, 12.12 •RBI-Cyber-Security-Framework: annex_i_1_1 •FFIEC: d1-g-it-b-1, d3-pc-im-b-5 •ISO27001-2022: A.5.26 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-8, sa-3 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b is not older than 180 days (100 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db is not older than 180 days (159 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e is not older than 180 days (154 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 is not older than 180 days (97 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb is not older than 180 days (145 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd is not older than 180 days (91 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_older_than_specific_days EC2 instance is not older than the configured maximum age or is not running arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 is not older than 180 days (91 days).

Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability

Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius

Adjust max_ec2_instance_age_in_days to match policy.

•CISA: your-systems-1 •AWS-Foundational-Security-Best-Practices: EC2.4 •KISA-ISMS-P-2023: 2.9.2 •HIPAA: 164_308_a_1_ii_b •KISA-ISMS-P-2023-korean: 2.9.2 •GxP-21-CFR-Part-11: 11.10-a •NIST-800-171-Revision-2: 3_4_1, 3_4_2 •ASD-Essential-Eight-Nov 2023: E8-2.8 •NIST-800-53-Revision-4: cm_2 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 •NIST-CSF-1.1: ds_7, ip_1 •FFIEC: d1-g-it-b-1 •ISO27001-2022: A.8.10 •FedRamp-Moderate-Revision-4: cm-2 •FedRAMP-Low-Revision-4: cm-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_paravirtual_type EC2 instance virtualization type is HVM arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

•AWS-Foundational-Security-Best-Practices: EC2.24 •KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cassandra_exposed_to_internet EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.

Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_cifs_exposed_to_internet EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.

Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

•CIS-7.0: 6.1.2 •SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •CIS-5.0: 5.1.2 •CIS-6.0: 6.1.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.1.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_elasticsearch_kibana_exposed_to_internet EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation

Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ftp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).

Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kafka_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_kerberos_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services

Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ldap_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration

Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth

If external access is required, place a proxy and enforce rate limits.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_memcached_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior

Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mongodb_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_mysql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_oracle_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_postgresql_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_rdp_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_redis_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.

Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_sqlserver_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_ssh_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •CCC-v2025.10: CCC.Core.CN01.AR02 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev Instance i-095bd68aff22b103b does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas Instance i-02754e7ae419cd5db does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env Instance i-010066e6c9027aa6e does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage Instance i-046e7fc4677eaa796 does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env Instance i-067bdb5e3e09fa4bb does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env Instance i-073154fb4fa773bbd does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_instance_port_telnet_exposed_to_internet EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod Instance i-0055a6b877ba156e7 does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.

Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_3 •ProwlerThreatScore-1.0: 2.1.6 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •NIS2: 6.7.2.g

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

FAIL medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db not associated with an Instance Profile Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

PASS medium ec2 us-east-2 ec2_instance_profile_attached EC2 instance is associated with an IAM instance profile role arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

•CIS-7.0: 2.16 •CIS-1.4: 1.18 •CIS-1.5: 1.18 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC •CIS-2.0: 1.18 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 •CIS-5.0: 1.17 •NIST-800-171-Revision-2: 3_1_1, 3_1_2 •PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 •NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a •CIS-3.0: 1.18 •CIS-6.0: 2.17 •FFIEC: d3-pc-am-b-1 •ProwlerThreatScore-1.0: 1.2.4 •ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 1.18 •NIS2: 11.1.1, 11.2.2.d

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b has a Public IP: 16.58.108.209 (ec2-16-58-108-209.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db has a Public IP: 16.59.189.218 (ec2-16-59-189-218.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e has a Public IP: 3.14.230.56 (ec2-3-14-230-56.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 has a Public IP: 52.14.227.224 (ec2-52-14-227-224.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb has a Public IP: 18.118.91.126 (ec2-18-118-91-126.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd has a Public IP: 3.150.90.196 (ec2-3-150-90-196.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

FAIL medium ec2 us-east-2 ec2_instance_public_ip EC2 instance does not have a public IP address arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 has a Public IP: 3.147.5.202 (ec2-3-147-5-202.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_6 •MITRE-ATTACK: T1190 •AWS-Foundational-Security-Best-Practices: EC2.9 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ac_3, ac_5, ip_8 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev No secrets found in EC2 instance i-095bd68aff22b103b since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas No secrets found in EC2 instance i-02754e7ae419cd5db since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env No secrets found in EC2 instance i-010066e6c9027aa6e since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage No secrets found in EC2 instance i-046e7fc4677eaa796 since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env No secrets found in EC2 instance i-067bdb5e3e09fa4bb since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env No secrets found in EC2 instance i-073154fb4fa773bbd since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS high ec2 us-east-2 ec2_instance_secrets_user_data EC2 instance user data contains no secrets arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod No secrets found in EC2 instance i-0055a6b877ba156e7 since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

•MITRE-ATTACK: T1552 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 •NIST-CSF-2.0: ds_5 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-DATA-05 •NIS2: 3.5.3.a

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_stopped_older_than_specific_days EC2 instance has not been stopped longer than the configured maximum days arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts

Adjust max_ec2_instance_stopped_days to match policy.

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b uses only one ENI: ( Interfaces: ['eni-0eb7c8be6cbdcdb2e'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db uses only one ENI: ( Interfaces: ['eni-0c6930a5310520d0f'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e uses only one ENI: ( Interfaces: ['eni-0ce22bed73e11293b'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 uses only one ENI: ( Interfaces: ['eni-0e6a8f502a37c7496'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb uses only one ENI: ( Interfaces: ['eni-0f39fad20067101e6'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd uses only one ENI: ( Interfaces: ['eni-047c4fd5cc9b17732'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_instance_uses_single_eni EC2 instance has no more than one Elastic Network Interface (ENI) attached arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 uses only one ENI: ( Interfaces: ['eni-0f8af55ce6e60d737'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.

If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions

Embed defense in depth and zero trust.

•AWS-Foundational-Security-Best-Practices: EC2.17 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 Instance i-095bd68aff22b103b is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 Instance i-02754e7ae419cd5db is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 Instance i-010066e6c9027aa6e is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 Instance i-046e7fc4677eaa796 is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 Instance i-067bdb5e3e09fa4bb is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 Instance i-073154fb4fa773bbd is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

PASS medium ec2 us-east-2 ec2_instance_with_outdated_ami EC2 instance uses a non-deprecated Amazon AMI arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 Instance i-0055a6b877ba156e7 is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

•ASD-Essential-Eight-Nov 2023: E8-2.8

FAIL high ec2 us-east-2 ec2_networkacl_allow_ingress_any_port Network ACL does not allow ingress from 0.0.0.0/0 to any port arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 Network ACL acl-0434045af7cd4bbc7 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

•CISA: your-data-2 •CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.1 •CIS-6.0: 6.2 •NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 •CCC-v2025.10: CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_networkacl_allow_ingress_any_port Network ACL does not allow ingress from 0.0.0.0/0 to any port arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 Network ACL acl-0cabb33741ea2f4f8 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

•CISA: your-data-2 •CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.1 •CIS-6.0: 6.2 •NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 •CCC-v2025.10: CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_networkacl_allow_ingress_any_port Network ACL does not allow ingress from 0.0.0.0/0 to any port arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 Network ACL acl-0e58a8e59c5863345 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

•CISA: your-data-2 •CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.1 •CIS-6.0: 6.2 •NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 •CCC-v2025.10: CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_22 Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 Network ACL acl-0434045af7cd4bbc7 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.

Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN

Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 •CIS-5.0: 5.2 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_22 Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 Network ACL acl-0cabb33741ea2f4f8 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.

Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN

Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 •CIS-5.0: 5.2 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_22 Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 Network ACL acl-0e58a8e59c5863345 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.

Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN

Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 •CIS-5.0: 5.2 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_3389 Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 Network ACL acl-0434045af7cd4bbc7 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.

  • Restrict RDP to specific admin IP ranges
  • Prefer bastion hosts or Session Manager over direct RDP
  • Use private subnets and layer controls for defense in depth

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_3389 Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 Network ACL acl-0cabb33741ea2f4f8 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.

  • Restrict RDP to specific admin IP ranges
  • Prefer bastion hosts or Session Manager over direct RDP
  • Use private subnets and layer controls for defense in depth

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

FAIL medium ec2 us-east-2 ec2_networkacl_allow_ingress_tcp_port_3389 Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 Network ACL acl-0e58a8e59c5863345 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.

  • Restrict RDP to specific admin IP ranges
  • Prefer bastion hosts or Session Manager over direct RDP
  • Use private subnets and layer controls for defense in depth

•CIS-7.0: 6.2 •SOC2: cc_6_6 •CIS-1.4: 5.1 •CIS-1.5: 5.1 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.21 •KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.1 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •CIS-5.0: 5.2 •PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 •CIS-3.0: 5.1 •CIS-6.0: 6.2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 •ProwlerThreatScore-1.0: 2.1.3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.2 •NIS2: 6.7.2.g

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS critical ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_all_ports Security group does not have all ports open to the Internet arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •ENS-RD2022: mp.com.1.aws.sg.2 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 •SecNumCloud-3.2: 13.2 •PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 •ProwlerThreatScore-1.0: 2.1.4 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to the Internet.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

FAIL high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 •SecNumCloud-3.2: 9.6, 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRAMP-20x-KSI-Low-25.05C: ksi-cna

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

FAIL medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has a port open to a specific public IP address in ingress rule.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS medium ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip Security group does not have any port open to a specific public IP address arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.19 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •C5-2025: OIS-05.03B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 •NIST-CSF-2.0: ac_5 •SecNumCloud-3.2: 13.2 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth

•CISA: your-systems-3, your-data-2 •CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6, cc_7_2 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.13 •ISO27001-2013: A.12.6.C, A.13.1.C •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •HIPAA: 164_308_a_1_ii_b, 164_312_e_1 •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3 •CIS-5.0: 5.3, 5.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 •PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 •NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 •CCC-v2025.10: CCC.Core.CN01.AR02 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 •FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 Security group does not allow ingress from the Internet to TCP port 3389 (RDP) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.

Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.

Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

•CIS-7.0: 6.3, 6.4 •SOC2: cc_6_6 •CIS-1.4: 5.2 •CIS-1.5: 5.2, 5.3 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •AWS-Foundational-Security-Best-Practices: EC2.14 •ISO27001-2013: A.12.6.B, A.13.1.B •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •CIS-2.0: 5.2, 5.3 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_3, ac_5 •CIS-5.0: 5.3, 5.4 •CIS-3.0: 5.2, 5.3 •CIS-6.0: 6.3, 6.4 •AWS-Foundational-Technical-Review: NETSEC-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 •SecNumCloud-3.2: 13.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.4, 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •CIS-4.0.1: 5.3, 5.4

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)

Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west)

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps

Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.

Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener

This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.

Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 Security group does not allow ingress from the Internet to TCP port 23 (Telnet) arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement

This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

•SOC2: cc_6_6 •MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •C5-2025: PI-01.01AC •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •CCC-v2025.10: CCC.Core.CN01.AR03 •ProwlerThreatScore-1.0: 2.1.7 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS high ec2 us-east-2 ec2_securitygroup_allow_wide_open_public_ipv4 Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse

Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •AWS-Foundational-Technical-Review: NETSEC-001 •SecNumCloud-3.2: 12.14 •ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791 Security group default (sg-093604be72efb9791) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 Security group ec2-rds-2 (sg-0d87b03d9b2789750) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853 Security group default (sg-0dbf3eea7e40c7853) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 Security group rds-ec2-3 (sg-058c35683b5b40123) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7 Security group default (sg-0438e6794e0d9c0d7) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 Security group rds-ec2-1 (sg-0084c72426d93c9c6) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f Security group ec2-rds-1 (sg-0f29b9425a85de27f) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 Security group rds-ec2-2 (sg-09fbc74b0b61042d9) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b Security group ec2-rds-3 (sg-06728bf2249b5938b) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) was created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) was created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_from_launch_wizard Security group not created using the EC2 Launch Wizard arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •ENS-RD2022: mp.com.1.aws.sg.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 Security group ec2-rds-2 (sg-0d87b03d9b2789750) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 Security group rds-ec2-3 (sg-058c35683b5b40123) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 Security group rds-ec2-1 (sg-0084c72426d93c9c6) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f Security group ec2-rds-1 (sg-0f29b9425a85de27f) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 Security group rds-ec2-2 (sg-09fbc74b0b61042d9) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b Security group ec2-rds-3 (sg-06728bf2249b5938b) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS low ec2 us-east-2 ec2_securitygroup_not_used Non-default EC2 security group is in use arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

•AWS-Foundational-Security-Best-Practices: EC2.22 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •NIST-CSF-2.0: ac_5, ip_1 •ENS-RD2022: mp.com.1.aws.sg.3 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791 Security group default (sg-093604be72efb9791) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 •Name=Ml_prod_sg Security group ml_prod_sg (sg-0256d81b7afd54cf9) has 3 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 Security group ec2-rds-2 (sg-0d87b03d9b2789750) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853 Security group default (sg-0dbf3eea7e40c7853) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 Security group rds-ec2-3 (sg-058c35683b5b40123) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 •Name=Scrivas_Ml_dev Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has 3 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7 Security group default (sg-0438e6794e0d9c0d7) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 •GuardDutyManaged=true Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 Security group rds-ec2-1 (sg-0084c72426d93c9c6) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f Security group ec2-rds-1 (sg-0f29b9425a85de27f) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 •Name=scrivas_prod Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 Security group rds-ec2-2 (sg-09fbc74b0b61042d9) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b Security group ec2-rds-3 (sg-06728bf2249b5938b) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 •Name=sg-netbird Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has 4 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 •Name=scrivas-dev-env Security group launch-wizard-1 (sg-0621cd7244c8006b3) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ec2 us-east-2 ec2_securitygroup_with_many_ingress_egress_rules Security group has 50 or fewer inbound rules and 50 or fewer outbound rules arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 Security group scrivas_stage_env (sg-0823502d51c886ab1) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 •AWS-Foundational-Technical-Review: NETSEC-001 •ISO27001-2022: A.8.20, A.8.21, A.8.22

PASS medium ecr us-east-2 ecr_registry_scan_images_on_push_enabled ECR registry has image scanning on push enabled for all repositories arn:aws:ecr:us-east-2:716468089330:registry/716468089330 ECR registry 716468089330 has ENHANCED scan with scan on push enabled.

Absent or filtered scan on push lets vulnerable images be pushed and deployed without timely detection, enabling exploitation of known CVEs (RCE, privilege escalation), supply chain compromise, and lateral movement - threatening workload integrity and data confidentiality.

Enable registry-wide scan on push and ensure rules apply to all repositories (no filters). Prefer enhanced scanning for broader coverage, and pair with continuous scans when available. Integrate findings into CI/CD gates and alerts to enforce defense in depth and block promotion of risky images.

•KISA-ISMS-P-2023: 2.10.2, 2.11.2 •C5-2025: PSS-11.01B, PSS-11.01AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.2 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •CCC-v2025.10: CCC.CntrReg.CN01.AR01 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS low ecr us-east-2 ecr_repositories_lifecycle_policy_enabled ECR repository has a lifecycle policy configured arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice Repository scrivas/patientsummaryservice has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

•AWS-Foundational-Security-Best-Practices: ECR.3 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: OPS-26.04B, OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 •NIS2: 12.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS low ecr us-east-2 ecr_repositories_lifecycle_policy_enabled ECR repository has a lifecycle policy configured arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser Repository scrivas/patientdocumentparser has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

•AWS-Foundational-Security-Best-Practices: ECR.3 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: OPS-26.04B, OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 •NIS2: 12.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS low ecr us-east-2 ecr_repositories_lifecycle_policy_enabled ECR repository has a lifecycle policy configured arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber Repository scrivas/sonioxtranscriber has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

•AWS-Foundational-Security-Best-Practices: ECR.3 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: OPS-26.04B, OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 •NIS2: 12.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS low ecr us-east-2 ecr_repositories_lifecycle_policy_enabled ECR repository has a lifecycle policy configured arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions Repository scrivas/saisuggestions has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

•AWS-Foundational-Security-Best-Practices: ECR.3 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: OPS-26.04B, OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 •NIS2: 12.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS low ecr us-east-2 ecr_repositories_lifecycle_policy_enabled ECR repository has a lifecycle policy configured arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor Repository scrivas/postprocessor has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

•AWS-Foundational-Security-Best-Practices: ECR.3 •KISA-ISMS-P-2023: 2.9.2 •C5-2025: OPS-26.04B, OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 •NIS2: 12.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS critical ecr us-east-2 ecr_repositories_not_publicly_accessible ECR repository is not publicly accessible arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice Repository scrivas/patientsummaryservice is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.

Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing

•KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1 •ProwlerThreatScore-1.0: 2.3.7 •ISO27001-2022: A.8.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS critical ecr us-east-2 ecr_repositories_not_publicly_accessible ECR repository is not publicly accessible arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser Repository scrivas/patientdocumentparser is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.

Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing

•KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1 •ProwlerThreatScore-1.0: 2.3.7 •ISO27001-2022: A.8.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS critical ecr us-east-2 ecr_repositories_not_publicly_accessible ECR repository is not publicly accessible arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber Repository scrivas/sonioxtranscriber is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.

Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing

•KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1 •ProwlerThreatScore-1.0: 2.3.7 •ISO27001-2022: A.8.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS critical ecr us-east-2 ecr_repositories_not_publicly_accessible ECR repository is not publicly accessible arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions Repository scrivas/saisuggestions is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.

Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing

•KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1 •ProwlerThreatScore-1.0: 2.3.7 •ISO27001-2022: A.8.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS critical ecr us-east-2 ecr_repositories_not_publicly_accessible ECR repository is not publicly accessible arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor Repository scrivas/postprocessor is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.

Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing

•KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1 •ProwlerThreatScore-1.0: 2.3.7 •ISO27001-2022: A.8.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

FAIL medium ecr us-east-2 ecr_repositories_scan_images_on_push_enabled [DEPRECATED] ECR repository has image scanning on push enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice ECR repository scrivas/patientsummaryservice has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

•AWS-Foundational-Security-Best-Practices: ECR.1 •C5-2025: PSS-11.01B, PSS-11.01AC •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 •PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •SecNumCloud-3.2: 12.11, 14.6

FAIL medium ecr us-east-2 ecr_repositories_scan_images_on_push_enabled [DEPRECATED] ECR repository has image scanning on push enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser ECR repository scrivas/patientdocumentparser has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

•AWS-Foundational-Security-Best-Practices: ECR.1 •C5-2025: PSS-11.01B, PSS-11.01AC •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 •PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •SecNumCloud-3.2: 12.11, 14.6

FAIL medium ecr us-east-2 ecr_repositories_scan_images_on_push_enabled [DEPRECATED] ECR repository has image scanning on push enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber ECR repository scrivas/sonioxtranscriber has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

•AWS-Foundational-Security-Best-Practices: ECR.1 •C5-2025: PSS-11.01B, PSS-11.01AC •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 •PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •SecNumCloud-3.2: 12.11, 14.6

FAIL medium ecr us-east-2 ecr_repositories_scan_images_on_push_enabled [DEPRECATED] ECR repository has image scanning on push enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions ECR repository scrivas/saisuggestions has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

•AWS-Foundational-Security-Best-Practices: ECR.1 •C5-2025: PSS-11.01B, PSS-11.01AC •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 •PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •SecNumCloud-3.2: 12.11, 14.6

FAIL medium ecr us-east-2 ecr_repositories_scan_images_on_push_enabled [DEPRECATED] ECR repository has image scanning on push enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor ECR repository scrivas/postprocessor has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

•AWS-Foundational-Security-Best-Practices: ECR.1 •C5-2025: PSS-11.01B, PSS-11.01AC •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 •PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •SecNumCloud-3.2: 12.11, 14.6

FAIL medium ecr us-east-2 ecr_repositories_tag_immutability ECR repository has image tag immutability enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice Repository scrivas/patientsummaryservice does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

•AWS-Foundational-Security-Best-Practices: ECR.2 •C5-2025: AM-09.01B, OPS-26.03B •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

FAIL medium ecr us-east-2 ecr_repositories_tag_immutability ECR repository has image tag immutability enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser Repository scrivas/patientdocumentparser does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

•AWS-Foundational-Security-Best-Practices: ECR.2 •C5-2025: AM-09.01B, OPS-26.03B •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

FAIL medium ecr us-east-2 ecr_repositories_tag_immutability ECR repository has image tag immutability enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber Repository scrivas/sonioxtranscriber does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

•AWS-Foundational-Security-Best-Practices: ECR.2 •C5-2025: AM-09.01B, OPS-26.03B •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

FAIL medium ecr us-east-2 ecr_repositories_tag_immutability ECR repository has image tag immutability enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions Repository scrivas/saisuggestions does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

•AWS-Foundational-Security-Best-Practices: ECR.2 •C5-2025: AM-09.01B, OPS-26.03B •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

FAIL medium ecr us-east-2 ecr_repositories_tag_immutability ECR repository has image tag immutability enabled arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor Repository scrivas/postprocessor does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

•AWS-Foundational-Security-Best-Practices: ECR.2 •C5-2025: AM-09.01B, OPS-26.03B •FedRAMP-20x-KSI-Low-25.05C: ksi-tpr

PASS high emr us-east-1 emr_cluster_account_public_block_enabled EMR account has Block Public Access enabled arn:aws:elasticmapreduce:us-east-1:716468089330:cluster EMR Account has Block Public Access enabled.

Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.

Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption.

Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.

Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth.

•AWS-Foundational-Security-Best-Practices: EMR.2 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8 •ProwlerThreatScore-1.0: 2.3.11 •ISO27001-2022: A.8.1

PASS high emr us-east-2 emr_cluster_account_public_block_enabled EMR account has Block Public Access enabled arn:aws:elasticmapreduce:us-east-2:716468089330:cluster EMR Account has Block Public Access enabled.

Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.

Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption.

Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.

Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth.

•AWS-Foundational-Security-Best-Practices: EMR.2 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8 •ProwlerThreatScore-1.0: 2.3.11 •ISO27001-2022: A.8.1

PASS high eventbridge us-east-1 eventbridge_bus_cross_account_access AWS EventBridge event bus does not allow cross-account access arn:aws:events:us-east-1:716468089330:event-bus/default EventBridge event bus default does not allow cross-account access.

Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods.

Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.

Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_5, ac_4, dp_4 •CCC-v2025.10: CCC.Core.CN05.AR03

PASS high eventbridge us-east-2 eventbridge_bus_cross_account_access AWS EventBridge event bus does not allow cross-account access arn:aws:events:us-east-2:716468089330:event-bus/default EventBridge event bus default does not allow cross-account access.

Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods.

Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.

Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_5, ac_4, dp_4 •CCC-v2025.10: CCC.Core.CN05.AR03

PASS high eventbridge us-east-1 eventbridge_bus_exposed AWS EventBridge event bus policy does not allow public access arn:aws:events:us-east-1:716468089330:event-bus/default EventBridge event bus default is not exposed to everyone.

Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events.

Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: "*".

Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity.

•CIS-7.0: 2.21 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_5, ac_4, dp_4 •ProwlerThreatScore-1.0: 2.3.13

PASS high eventbridge us-east-2 eventbridge_bus_exposed AWS EventBridge event bus policy does not allow public access arn:aws:events:us-east-2:716468089330:event-bus/default EventBridge event bus default is not exposed to everyone.

Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events.

Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: "*".

Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity.

•CIS-7.0: 2.21 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_5, ac_4, dp_4 •ProwlerThreatScore-1.0: 2.3.13

FAIL medium guardduty us-east-1 guardduty_centrally_managed GuardDuty detector is managed by an administrator account or is the administrator with member accounts arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c is not centrally managed.

Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability.

Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization •ENS-RD2022: op.mon.1.aws.gd.3 •ISO27001-2022: A.5.25, A.5.28, A.5.29 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

FAIL medium guardduty us-east-2 guardduty_centrally_managed GuardDuty detector is managed by an administrator account or is the administrator with member accounts arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc is not centrally managed.

Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability.

Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization •ENS-RD2022: op.mon.1.aws.gd.3 •ISO27001-2022: A.5.25, A.5.28, A.5.29 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

FAIL high guardduty us-east-1 guardduty_delegated_admin_enabled_all_regions GuardDuty has delegated admin configured and is enabled in all regions with organization auto-enable arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty in region us-east-1 has issues: no delegated administrator configured.

Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration.

Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization.

•AWS-AI-Security-Framework-1.0: AISF-DETECT-02

FAIL high guardduty us-east-2 guardduty_delegated_admin_enabled_all_regions GuardDuty has delegated admin configured and is enabled in all regions with organization auto-enable arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty in region us-east-2 has issues: no delegated administrator configured.

Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration.

Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization.

•AWS-AI-Security-Framework-1.0: AISF-DETECT-02

PASS high guardduty us-east-1 guardduty_ec2_malware_protection_enabled GuardDuty detector has Malware Protection for EC2 enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Malware Protection for EC2 enabled.

Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
- Confidentiality loss via data exfiltration/credential theft
- Integrity compromise through tampering and backdoors
- Availability impact from ransomware/cryptominers

Persistence increases lateral movement across the environment.

Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9 •C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9 •NIST-CSF-2.0: ip_7, cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_ec2_malware_protection_enabled GuardDuty detector has Malware Protection for EC2 enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Malware Protection for EC2 enabled.

Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
- Confidentiality loss via data exfiltration/credential theft
- Integrity compromise through tampering and backdoors
- Availability impact from ransomware/cryptominers

Persistence increases lateral movement across the environment.

Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9 •C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9 •NIST-CSF-2.0: ip_7, cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-1 guardduty_eks_audit_log_enabled GuardDuty detector has EKS Audit Log Monitoring enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Audit Log Monitoring enabled.

Without it, Kubernetes API abuse may go undetected, impacting CIA:
- Secret access and data exfiltration
- RBAC changes enabling privilege escalation
- Rogue deployments for persistence/cryptomining

Attackers can laterally move to AWS using harvested credentials.

Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
- Route findings to alerting/IR workflows
- Enforce least privilege on access to findings and configs
- Combine with defense-in-depth: hardened RBAC and runtime monitoring

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •SecNumCloud-3.2: 12.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •NIS2: 3.2.3.c •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_eks_audit_log_enabled GuardDuty detector has EKS Audit Log Monitoring enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Audit Log Monitoring enabled.

Without it, Kubernetes API abuse may go undetected, impacting CIA:
- Secret access and data exfiltration
- RBAC changes enabling privilege escalation
- Rogue deployments for persistence/cryptomining

Attackers can laterally move to AWS using harvested credentials.

Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
- Route findings to alerting/IR workflows
- Enforce least privilege on access to findings and configs
- Combine with defense-in-depth: hardened RBAC and runtime monitoring

•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 •SecNumCloud-3.2: 12.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •NIS2: 3.2.3.c •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS medium guardduty us-east-1 guardduty_eks_runtime_monitoring_enabled GuardDuty detector has EKS Runtime Monitoring enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Runtime Monitoring enabled.

Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability).

  • Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
  • Enforce least privilege for agents and segment cluster access
  • Integrate findings with response workflows and periodically verify runtime coverage

•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_7, cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •NIS2: 3.2.3.h •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS medium guardduty us-east-2 guardduty_eks_runtime_monitoring_enabled GuardDuty detector has EKS Runtime Monitoring enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Runtime Monitoring enabled.

Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability).

  • Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
  • Enforce least privilege for agents and segment cluster access
  • Integrate findings with response workflows and periodically verify runtime coverage

•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: ip_7, cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •NIS2: 3.2.3.h •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-1 guardduty_is_enabled GuardDuty detector is enabled and not suspended arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c enabled.

Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions.

Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth.

•CISA: your-systems-3, your-crisis-response-2 •SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 •MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046 •AWS-Foundational-Security-Best-Practices: GuardDuty.1 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC •HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04 •NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7 •PCI-4.0: 11.5.1.1.2, 11.5.1.2 •NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4 •NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b •AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection •ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1 •AWS-Foundational-Technical-Review: IAM-002 •NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5 •CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01 •SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2 •FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 •PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c •ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_is_enabled GuardDuty detector is enabled and not suspended arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc enabled.

Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions.

Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth.

•CISA: your-systems-3, your-crisis-response-2 •SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 •MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046 •AWS-Foundational-Security-Best-Practices: GuardDuty.1 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC •HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04 •NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7 •PCI-4.0: 11.5.1.1.2, 11.5.1.2 •NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4 •NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b •AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection •ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1 •AWS-Foundational-Technical-Review: IAM-002 •NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5 •CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01 •SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2 •FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 •PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c •ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-1 guardduty_lambda_protection_enabled GuardDuty detector has Lambda Protection enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Lambda Protection enabled.

Without Lambda Protection, Lambda network traffic is uninspected, enabling:
- C2 callbacks and data exfiltration (confidentiality)
- Malicious code altering data or configs (integrity)
- Lateral movement or abuse causing disruption (availability)

Enable Lambda Protection on all detectors in every active Region and account.

Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_lambda_protection_enabled GuardDuty detector has Lambda Protection enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Lambda Protection enabled.

Without Lambda Protection, Lambda network traffic is uninspected, enabling:
- C2 callbacks and data exfiltration (confidentiality)
- Malicious code altering data or configs (integrity)
- Lateral movement or abuse causing disruption (availability)

Enable Lambda Protection on all detectors in every active Region and account.

Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-1 guardduty_no_high_severity_findings GuardDuty detector has no high severity findings arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c does not have high severity findings.

Unresolved High findings often signal active compromise, enabling:
- Data exfiltration and unauthorized access (confidentiality)
- Privilege escalation and tampering (integrity)
- Disruption via malware/crypto-mining (availability)

Attackers can pivot laterally and persist if not contained.

Treat High findings as incidents.

  • Prioritize triage and containment; isolate affected resources, rotate secrets
  • Automate alerting and response with playbooks; integrate into IR
  • Enforce least privilege, network segmentation, and hardened baselines
  • Continuously tune detections and remove unused access to prevent recurrence

•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4 •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B •HIPAA: 164_308_a_6_ii •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_2 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3 •NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4 •NIST-800-53-Revision-5: ir_4_a •AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection •ENS-RD2022: op.exp.7.aws.gd.1 •AWS-Foundational-Technical-Review: IAM-002, SECOPS-001 •NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3 •CCC-v2025.10: CCC.Core.CN07.AR01 •SecNumCloud-3.2: 12.4, 16.3 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d3-dc-an-b-1, d5-er-es-b-4 •ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c •FedRAMP-Low-Revision-4: ir-4 •NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr

FAIL high guardduty us-east-2 guardduty_no_high_severity_findings GuardDuty detector has no high severity findings arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has 1 high severity findings.

Unresolved High findings often signal active compromise, enabling:
- Data exfiltration and unauthorized access (confidentiality)
- Privilege escalation and tampering (integrity)
- Disruption via malware/crypto-mining (availability)

Attackers can pivot laterally and persist if not contained.

Treat High findings as incidents.

  • Prioritize triage and containment; isolate affected resources, rotate secrets
  • Automate alerting and response with playbooks; integrate into IR
  • Enforce least privilege, network segmentation, and hardened baselines
  • Continuously tune detections and remove unused access to prevent recurrence

•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4 •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B •HIPAA: 164_308_a_6_ii •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •NIST-CSF-2.0: ov_2 •NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3 •NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4 •NIST-800-53-Revision-5: ir_4_a •AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection •ENS-RD2022: op.exp.7.aws.gd.1 •AWS-Foundational-Technical-Review: IAM-002, SECOPS-001 •NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3 •CCC-v2025.10: CCC.Core.CN07.AR01 •SecNumCloud-3.2: 12.4, 16.3 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d3-dc-an-b-1, d5-er-es-b-4 •ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c •FedRAMP-Low-Revision-4: ir-4 •NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr

PASS high guardduty us-east-1 guardduty_rds_protection_enabled GuardDuty detector has RDS Protection enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector has RDS Protection enabled.

Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability.

Enable GuardDuty RDS Protection across all accounts and Regions.
- Enforce least privilege for DB users and rotate credentials
- Restrict network exposure to databases
- Integrate findings with alerting and incident response for rapid containment

•AWS-Foundational-Security-Best-Practices: GuardDuty.9 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_rds_protection_enabled GuardDuty detector has RDS Protection enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector has RDS Protection enabled.

Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability.

Enable GuardDuty RDS Protection across all accounts and Regions.
- Enforce least privilege for DB users and rotate credentials
- Restrict network exposure to databases
- Integrate findings with alerting and incident response for rapid containment

•AWS-Foundational-Security-Best-Practices: GuardDuty.9 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-1 guardduty_s3_protection_enabled GuardDuty detector has S3 Protection enabled arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c GuardDuty detector has S3 Protection enabled.

Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
- Exfiltration via mass reads/copies
- Destructive deletes
- Policy/ACL tampering

Undetected actions degrade data confidentiality, integrity, and availability.

Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering.

•AWS-Foundational-Security-Best-Practices: GuardDuty.10 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high guardduty us-east-2 guardduty_s3_protection_enabled GuardDuty detector has S3 Protection enabled arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc GuardDuty detector has S3 Protection enabled.

Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
- Exfiltration via mass reads/copies
- Destructive deletes
- Policy/ACL tampering

Undetected actions degrade data confidentiality, integrity, and availability.

Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering.

•AWS-Foundational-Security-Best-Practices: GuardDuty.10 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: OPS-23.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: cm_7 •SecNumCloud-3.2: 12.4 •AWS-AI-Security-Framework-1.0: AISF-DETECT-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/Admin Group Admin provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/devops Group devops provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/ecr-push-group Group ecr-push-group provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/otherpermission Group otherpermission provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/secertmanageraccess Group secertmanageraccess provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_administrator_access_with_mfa IAM group members granted AdministratorAccess have MFA enabled arn:aws:iam::716468089330:group/storage-access Group storage-access provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access

•MITRE-ATTACK: T1078, T1098, T1550 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •NIST-CSF-2.0: rr_1, ac_4, ip_1 •ASD-Essential-Eight-Nov 2023: E8-3.1 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_avoid_root_usage AWS account root user has not been used in the last day arn:aws:iam::716468089330:root Root user in the account wasn't accessed in the last 1 days.

Recent root usage expands blast radius:
- Data exfiltration (confidentiality)
- Policy/key tampering (integrity)
- Resource deletion and billing changes (availability)
Routine use reduces anomaly visibility and eases account takeover impact.

Minimize root usage by applying least privilege with admin roles or federated SSO and temporary credentials.
- Enforce MFA on root
- Avoid or remove root access keys
- Require multi-person approval
- Monitor and alert on any root sign-in
- Use org guardrails for defense in depth

•CIS-7.0: 2.7 •CIS-1.4: 1.7 •CIS-1.5: 1.7 •MITRE-ATTACK: T1078, T1098 •ISO27001-2013: A.9.2.H, A.9.4.H •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.10.2 •C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-06.04B •CIS-2.0: 1.7 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.6 •AWS-Account-Security-Onboarding: Block root user •CIS-3.0: 1.7 •ENS-RD2022: op.acc.2.aws.iam.4, op.acc.4.aws.iam.7 •CIS-6.0: 2.6 •CCC-v2025.10: CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.6 •ProwlerThreatScore-1.0: 1.2.5 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-04 •CIS-4.0.1: 1.7 •NIS2: 6.7.2.e, 11.3.2.b, 11.3.2.c, 11.4.2.a

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSOrganizationsServiceTrustPolicy AWS policy AWSOrganizationsServiceTrustPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy AWS policy CloudWatchAgentServerPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AWSServiceCatalogAdminFullAccess AWS policy AWSServiceCatalogAdminFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/CloudwatchApplicationInsightsServiceLinkedRolePolicy AWS policy CloudwatchApplicationInsightsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore AWS policy AmazonSSMManagedInstanceCore is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AutoScalingServiceRolePolicy AWS policy AutoScalingServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonRDSServiceRolePolicy AWS policy AmazonRDSServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSElasticLoadBalancingServiceRolePolicy AWS policy AWSElasticLoadBalancingServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyServiceRolePolicy AWS policy AmazonGuardDutyServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/CloudWatchReadOnlyAccess AWS policy CloudWatchReadOnlyAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSTrustedAdvisorServiceRolePolicy AWS policy AWSTrustedAdvisorServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSEC2SpotServiceRolePolicy AWS policy AWSEC2SpotServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubServiceRolePolicy AWS policy AWSSecurityHubServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AdministratorAccess AWS policy AdministratorAccess is attached and allows '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSSupportServiceRolePolicy AWS policy AWSSupportServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/CloudWatchLogsFullAccess AWS policy CloudWatchLogsFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/SecretsManagerReadWrite AWS policy SecretsManagerReadWrite is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/service-role/AmazonRDSEnhancedMonitoringRole AWS policy AmazonRDSEnhancedMonitoringRole is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSClusterPolicy AWS policy AmazonEKSClusterPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonMacieServiceRolePolicy AWS policy AmazonMacieServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSConfigServiceRolePolicy AWS policy AWSConfigServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy AWS policy AmazonEKS_CNI_Policy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly AWS policy AmazonEC2ContainerRegistryReadOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/SecurityAudit AWS policy SecurityAudit is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/IAMUserChangePassword AWS policy IAMUserChangePassword is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/CloudTrailServiceRolePolicy AWS policy CloudTrailServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy AWS policy AmazonEKSWorkerNodePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonS3FullAccess AWS policy AmazonS3FullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk AWS policy AdministratorAccess-AWSElasticBeanstalk is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonEKSServiceRolePolicy AWS policy AmazonEKSServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSWorkerNodeMinimalPolicy AWS policy AmazonEKSWorkerNodeMinimalPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/ServiceQuotasServiceRolePolicy AWS policy ServiceQuotasServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyMalwareProtectionServiceRolePolicy AWS policy AmazonGuardDutyMalwareProtectionServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSGlobalAcceleratorSLRPolicy AWS policy AWSGlobalAcceleratorSLRPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSDashboardConsoleReadOnly AWS policy AmazonEKSDashboardConsoleReadOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonDevOpsGuruFullAccess AWS policy AmazonDevOpsGuruFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryPullOnly AWS policy AmazonEC2ContainerRegistryPullOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonSSMManagedEC2InstanceDefaultPolicy AWS policy AmazonSSMManagedEC2InstanceDefaultPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSNetworkingPolicy AWS policy AmazonEKSNetworkingPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSComputePolicy AWS policy AmazonEKSComputePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AWSQuickSetupDevOpsGuruPermissionsBoundary AWS policy AWSQuickSetupDevOpsGuruPermissionsBoundary is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSResourceExplorerServiceRolePolicy AWS policy AWSResourceExplorerServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSServiceRoleForAmazonEKSNodegroup AWS policy AWSServiceRoleForAmazonEKSNodegroup is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSBlockStoragePolicy AWS policy AmazonEKSBlockStoragePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonDevOpsGuruOrganizationsAccess AWS policy AmazonDevOpsGuruOrganizationsAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonInspector2ServiceRolePolicy AWS policy AmazonInspector2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSLoadBalancingPolicy AWS policy AmazonEKSLoadBalancingPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonEKSVPCResourceController AWS policy AmazonEKSVPCResourceController is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AmazonInspector2AgentlessServiceRolePolicy AWS policy AmazonInspector2AgentlessServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSUserNotificationsServiceLinkedRolePolicy AWS policy AWSUserNotificationsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AdministratorAccess-Amplify AWS policy AdministratorAccess-Amplify is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubV2ServiceRolePolicy AWS policy AWSSecurityHubV2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/service-role/AmazonEBSCSIDriverPolicy AWS policy AmazonEBSCSIDriverPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonDevOpsGuruReadOnlyAccess AWS policy AmazonDevOpsGuruReadOnlyAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/AmazonDevOpsGuruConsoleFullAccess AWS policy AmazonDevOpsGuruConsoleFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_aws_attached_policy_no_administrative_privileges Attached AWS-managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::aws:policy/aws-service-role/AccessAnalyzerServiceRolePolicy AWS policy AccessAnalyzerServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL low iam us-east-2 iam_check_saml_providers_sts IAM SAML provider exists in the account arn:aws:iam::716468089330:root No SAML Providers found.

Without SAML federation, users rely on long-lived IAM keys. Compromised keys enable persistent API access, causing data exfiltration (C), unauthorized resource or policy changes (I), and difficult revocation. Lack of IdP controls (e.g., MFA, session limits) weakens accountability and access governance.

Adopt SAML federation to issue short-lived STS credentials. Map users to roles with least privilege, enforce MFA at the IdP, and set conservative session durations. Retire IAM user access keys for interactive use and monitor role sessions as defense in depth. If federation isn't possible, tightly scope, rotate, and audit keys.

•CIS-7.0: 2.19 •CIS-1.4: 1.21 •CIS-1.5: 1.21 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •CIS-2.0: 1.21 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.20 •CIS-3.0: 1.21 •ENS-RD2022: op.acc.1.aws.iam.2 •CIS-6.0: 2.20 •CCC-v2025.10: CCC.Core.CN05.AR06, CCC.IAM.CN09.AR01 •ProwlerThreatScore-1.0: 1.2.7 •CIS-4.0.1: 1.21

PASS high iam us-east-2 iam_customer_attached_policy_no_administrative_privileges Attached IAM customer-managed policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_customer_attached_policy_no_administrative_privileges Attached IAM customer-managed policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_customer_attached_policy_no_administrative_privileges Attached IAM customer-managed policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom policy VPCFlowLogs-CloudWatch-Policy-1781174377138 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_customer_attached_policy_no_administrative_privileges Attached IAM customer-managed policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom policy scrivas-s3-storage-policy is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_customer_attached_policy_no_administrative_privileges Attached IAM customer-managed policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom policy gitlab-ci-ecr-push is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.14 •SOC2: cc_1_3, cc_6_3 •CIS-1.4: 1.16 •CIS-1.5: 1.16 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •CIS-2.0: 1.16 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 •CIS-5.0: 1.15 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •CIS-3.0: 1.16 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.15 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.3.1 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_customer_unattached_policy_no_administrative_privileges Unattached customer managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/sai Custom policy sai is unattached and does not allow '*:*' administrative privileges.

An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement.

Remove or redesign these policies to enforce least privilege:
- Avoid * in actions/resources; scope precisely and use conditions
- Apply permissions boundaries and SCPs as guardrails
- Require peer review and policy validation before attachment
- Use analysis tools to refine permissions and delete unused policies

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: po_1, ac_4, ac_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •ISO27001-2022: A.8.2

PASS medium iam us-east-2 iam_customer_unattached_policy_no_administrative_privileges Unattached customer managed IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:policy/EnforceMFAdilbag Custom policy EnforceMFAdilbag is unattached and does not allow '*:*' administrative privileges.

An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement.

Remove or redesign these policies to enforce least privilege:
- Avoid * in actions/resources; scope precisely and use conditions
- Apply permissions boundaries and SCPs as guardrails
- Require peer review and policy validation before attachment
- Use analysis tools to refine permissions and delete unused policies

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 •NIST-CSF-2.0: po_1, ac_4, ac_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 •ISO27001-2022: A.8.2

FAIL high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/Admin IAM Group Admin has AdministratorAccess policy attached.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/devops IAM Group devops does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/ecr-push-group IAM Group ecr-push-group does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/otherpermission IAM Group otherpermission does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/secertmanageraccess IAM Group secertmanageraccess does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_group_administrator_access_policy IAM group does not have AdministratorAccess policy attached arn:aws:iam::716468089330:group/storage-access IAM Group storage-access does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:group/Admin Inline policy sai-admin attached to group Admin does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:group/devops Inline policy kms attached to group devops does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:group/devops Inline policy sai-devops attached to group devops does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:group/otherpermission Inline policy custommfa attached to group otherpermission does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:group/otherpermission Inline policy loggingaccess attached to group otherpermission does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:role/FlowLogsToCloudWatch Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS high iam us-east-2 iam_inline_policy_allows_privilege_escalation IAM inline policy does not allow privilege escalation arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins

•SOC2: cc_3_3 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: SP-01.04B, AM-09.04AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •ProwlerThreatScore-1.0: 1.3.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:group/Admin Inline policy sai-admin attached to group Admin does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:group/devops Inline policy kms attached to group devops does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:group/devops Inline policy sai-devops attached to group devops does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:group/otherpermission Inline policy custommfa attached to group otherpermission does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:group/otherpermission Inline policy loggingaccess attached to group otherpermission does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:role/FlowLogsToCloudWatch Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_inline_policy_no_administrative_privileges Inline IAM policy does not allow '*:*' administrative privileges arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

•CISA: your-systems-3, your-surroundings-3 •SOC2: cc_1_3, cc_6_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.1 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: rr_1, rr_2, po_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 •ASD-Essential-Eight-Nov 2023: E8-4.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 •ISO27001-2022: A.5.18, A.8.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:group/Admin Inline policy sai-admin attached to group Admin does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:group/devops Inline policy kms attached to group devops does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:group/devops Inline policy sai-devops attached to group devops does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:group/otherpermission Inline policy custommfa attached to group otherpermission does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:group/otherpermission Inline policy loggingaccess attached to group otherpermission does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:role/FlowLogsToCloudWatch Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS high iam us-east-2 iam_inline_policy_no_full_access_to_cloudtrail Inline IAM policy does not allow 'cloudtrail:*' privileges arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: po_1, ac_7 •ASD-Essential-Eight-Nov 2023: E8-4.4 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:group/Admin Inline policy sai-admin attached to group Admin does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:group/devops Inline policy kms attached to group devops does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:group/devops Inline policy sai-devops attached to group devops does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:group/otherpermission Inline policy custommfa attached to group otherpermission does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:group/otherpermission Inline policy loggingaccess attached to group otherpermission does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:role/FlowLogsToCloudWatch Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_full_access_to_kms Inline IAM policy does not allow kms:* privileges arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.

Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:group/Admin Inline policy sai-admin attached to group Admin does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:group/devops Inline policy kms attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:group/devops Inline policy sai-devops attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:group/otherpermission Inline policy custommfa attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:group/otherpermission Inline policy loggingaccess attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:role/FlowLogsToCloudWatch Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_inline_policy_no_wildcard_marketplace_subscribe Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_no_custom_policy_permissive_role_assumption Custom IAM policy does not allow STS role assumption on wildcard resources arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties

•CISA: your-systems-3, your-surroundings-3 •MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_no_custom_policy_permissive_role_assumption Custom IAM policy does not allow STS role assumption on wildcard resources arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties

•CISA: your-systems-3, your-surroundings-3 •MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_no_custom_policy_permissive_role_assumption Custom IAM policy does not allow STS role assumption on wildcard resources arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties

•CISA: your-systems-3, your-surroundings-3 •MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_no_custom_policy_permissive_role_assumption Custom IAM policy does not allow STS role assumption on wildcard resources arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom Policy scrivas-s3-storage-policy does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties

•CISA: your-systems-3, your-surroundings-3 •MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_no_custom_policy_permissive_role_assumption Custom IAM policy does not allow STS role assumption on wildcard resources arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom Policy gitlab-ci-ecr-push does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties

•CISA: your-systems-3, your-surroundings-3 •MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_no_root_access_key Root account has no active access keys arn:aws:iam::716468089330:root Root account does not have access keys.

Root access keys provide unrestricted API access. If exposed or misused, attackers can:
- Turn off logging and alter policies (integrity)
- Read or export data (confidentiality)
- Delete resources and lock out admins (availability)
Long-lived keys can persist and may bypass console-only MFA.

Delete and prohibit root access keys. Use IAM roles and temporary credentials with least privilege for all automation. Enable MFA on root, limit root to break-glass use, and continuously monitor for any new root keys. Where applicable, apply organization-wide controls to enforce this.

•CISA: your-systems-3, your-surroundings-3 •CIS-7.0: 2.4 •CIS-1.4: 1.4 •CIS-1.5: 1.4 •MITRE-ATTACK: T1078, T1550 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.4 •ISO27001-2013: A.9.2.N, A.9.4.N •KISA-ISMS-P-2023: 2.5.5, 2.7.2, 2.10.2 •C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_312_a_2_i •CIS-2.0: 1.4 •KISA-ISMS-P-2023-korean: 2.5.5, 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.3 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6 •PCI-4.0: 7.2.1.17, 7.2.2.17, 7.2.3.8, 8.2.1.4, 8.2.2.6, 8.2.4.4, 8.2.5.4, 8.3.11.4 •NIST-800-53-Revision-4: ac_2, ac_3, ac_6_10, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_2, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2, ia_4_b, ia_4_4, ia_4_8, ia_5_8, mp_2, sc_23_3, sc_25 •AWS-Account-Security-Onboarding: Block root user •CIS-3.0: 1.4 •ENS-RD2022: op.acc.4.aws.iam.7 •CIS-6.0: 2.3 •AWS-Foundational-Technical-Review: ARC-004 •NIST-CSF-1.1: ac_1, ac_4, pt_3 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.Core.CN05.AR06, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.6 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-am-b-3, d3-pc-am-b-8 •ProwlerThreatScore-1.0: 1.1.13 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-04 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, ia-2 •FedRAMP-Low-Revision-4: ac-2, ac-3, ia-2 •CIS-4.0.1: 1.4 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_password_policy_expires_passwords_within_90_days_or_less IAM account password policy enforces password expiration within 90 days or less arn:aws:iam:us-east-2:716468089330:password-policy Password expiration is not set.

Without rotation, stale passwords persist, enabling credential stuffing, brute force, and password reuse attacks. A compromised IAM user can retain console access, enabling data exfiltration, privilege escalation, and loss of confidentiality and integrity.

Enforce password rotation at <= 90 days and prevent reuse. Pair with MFA, strong length/complexity, and prefer federation/SSO to reduce static passwords. Apply least privilege, monitor sign-ins, and remove inactive console passwords to limit exposure.

•MITRE-ATTACK: T1078, T1110 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.A, A.9.3.A, A.9.4.A •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-03.02B, IAM-08.03B, IAM-08.05B, PSS-07.01B •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 •NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 8.3.6.1, 8.6.3.2 •ENS-RD2022: op.acc.6.aws.iam.3 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5 •ProwlerThreatScore-1.0: 1.1.12 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •NIS2: 1.1.1.d, 1.1.2, 9.2.c.v, 11.6.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL low iam us-east-2 iam_password_policy_lowercase IAM password policy requires at least one lowercase letter arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy does not require at least one lowercase letter.

Without a lowercase requirement, passwords have reduced entropy, making brute force and password spraying more effective. Compromised IAM users can enable unauthorized access and changes, risking confidentiality, integrity, and availability of AWS resources.

Adopt a strong password policy that:
- Enables Require at least one lowercase letter plus uppercase, number, and symbol
- Sets sufficient length and blocks reuse
- Requires MFA for all users
- Applies least privilege to limit blast radius

•CISA: your-systems-3, your-surroundings-4 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.F, A.9.3.F, A.9.4.F •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-08.03B, PSS-07.01B •HIPAA: 164_308_a_5_ii_d •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-800-171-Revision-2: 3_5_7 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 •ProwlerThreatScore-1.0: 1.1.8 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •NIS2: 9.2.c.v, 11.6.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_password_policy_minimum_length_14 IAM password policy requires passwords to be at least 14 characters long arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy does not require minimum length of 14 characters.

Low minimum length reduces entropy, easing brute force and credential stuffing. Compromised IAM users enable console access, unauthorized changes, and lateral movement, leading to data exposure (confidentiality) and tampering (integrity).

Set the minimum password length to >= 14 (prefer 16+).
- Require mixed character types and prevent reuse
- Enforce MFA for all console users
- Prefer SSO over local IAM users
- Apply least privilege and monitor authentication events

•CISA: your-systems-3, your-surroundings-4 •CIS-7.0: 2.8 •CIS-1.4: 1.8 •CIS-1.5: 1.8 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.C, A.9.3.C, A.9.4.C •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-08.03B, PSS-07.01B •HIPAA: 164_308_a_5_ii_d •CIS-2.0: 1.8 •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.7 •NIST-800-171-Revision-2: 3_5_7 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_d_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, cm_12_b, ia_4_d, ia_5, ia_5_b, ia_5_c, ia_5_d, ia_5_f, ia_5_h, ia_5_1_f, ia_5_1_g, ia_5_1_h, ia_5_1_h, ia_5_18_a, ia_5_18_b, ia_8_2_b, ma_4_c, sc_23_3 •CIS-3.0: 1.8 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •CIS-6.0: 2.7 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5, 10.3 •FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 •ProwlerThreatScore-1.0: 1.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-5-c, ia-2, ia-5-1-a-d-e, ia-5-4 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.8 •NIS2: 9.2.c.v •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_password_policy_number IAM password policy requires at least one number arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy does not require at least one number.

Passwords without numbers have lower entropy, making brute-force and credential-stuffing more effective. A compromised IAM user can gain console access, enabling data exposure (confidentiality), configuration changes (integrity), and resource abuse or deletion (availability).

Enforce the password policy option to require at least one number. Combine with strong length, mixed case, and symbols, and prevent reuse. Enable MFA for all users and prefer federated access to limit static credentials, supporting defense in depth against guessing attacks.

•CISA: your-systems-3, your-surroundings-4 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.D, A.9.3.D, A.9.4.D •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B •HIPAA: 164_308_a_5_ii_d •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-800-171-Revision-2: 3_5_7 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5, 10.3 •FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 •ProwlerThreatScore-1.0: 1.1.6 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •NIS2: 9.2.c.v •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_password_policy_reuse_24 IAM password policy prevents reuse of the last 24 passwords arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy reuse prevention is less than 24 or not set.

If fewer than 24 passwords are remembered, users can cycle back to recent secrets, undermining rotation. Attackers with previously exposed passwords can regain console access after a change, reducing confidentiality and integrity and increasing success of credential-stuffing with known credentials.

Set the password policy to remember 24 previous passwords to block reuse. Combine with MFA, strong length and complexity, and avoid rotation practices that encourage predictable patterns. Apply least privilege and monitor authentication events as part of defense in depth.

•CIS-7.0: 2.9 •CIS-1.4: 1.9 •CIS-1.5: 1.9 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.B, A.9.3.B, A.9.4.B •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-01.03B, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-08.03B, IAM-08.05B, IAM-08.07B, PSS-07.01B •HIPAA: 164_308_a_4_ii_c, 164_308_a_5_ii_d, 164_312_d •CIS-2.0: 1.9 •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.8 •NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2, ia_2, ia_5_1, ia_5_4 •CIS-3.0: 1.9 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •CIS-6.0: 2.8 •AWS-Foundational-Technical-Review: IAM-003 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5 •RBI-Cyber-Security-Framework: annex_i_7_2 •PCI-3.2.1: 8.1, 8.1.4, 8.2, 8.2.3, 8.2.3.a, 8.2.3.b, 8.2.4, 8.2.4.a, 8.2.4.b, 8.2.5, 8.2.5.a, 8.2.5.b •ProwlerThreatScore-1.0: 1.1.5 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •CIS-4.0.1: 1.9 •NIS2: 9.2.c.v •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_password_policy_symbol IAM password policy requires at least one symbol arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy does not require at least one symbol.

Missing a symbol requirement lowers password entropy, increasing success of brute force and credential stuffing against console logins. A compromised IAM user can gain unauthorized access and modify resources, threatening confidentiality and integrity across the account.

Enforce the Require at least one non-alphanumeric character rule in the IAM password policy, alongside strong minimum length, mixed character sets, and password reuse prevention. Apply MFA for all human users and uphold least privilege to limit impact. Consider periodic rotation based on risk.

•CISA: your-systems-3, your-surroundings-4 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.E, A.9.3.E, A.9.4.E •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-08.03B, PSS-07.01B •HIPAA: 164_308_a_5_ii_d •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-800-171-Revision-2: 3_5_7 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5, 10.3 •FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 •ProwlerThreatScore-1.0: 1.1.7 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •NIS2: 9.2.c.v •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_password_policy_uppercase IAM password policy requires at least one uppercase letter arn:aws:iam:us-east-2:716468089330:password-policy IAM password policy does not require at least one uppercase letter.

Without an uppercase requirement, passwords have lower entropy, enabling brute force, credential stuffing, and offline cracking. Compromised IAM users can access the console, threatening confidentiality (data exposure), integrity (unauthorized changes), and availability (resource deletion).

Enable the uppercase rule within a strong password policy that also requires length, lowercase, numbers, and symbols. Pair with MFA and least privilege to reduce blast radius. Regularly review policy effectiveness and prefer federated SSO to minimize long-lived IAM passwords.

•CISA: your-systems-3, your-surroundings-4 •MITRE-ATTACK: T1078, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 •ISO27001-2013: A.9.2.G, A.9.3.G, A.9.4.G •KISA-ISMS-P-2023: 2.5.4, 2.10.2 •C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B •HIPAA: 164_308_a_5_ii_d •KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-800-171-Revision-2: 3_5_7 •ENS-RD2022: op.acc.6.r1.aws.iam.1 •AWS-Foundational-Technical-Review: IAM-003 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 •ProwlerThreatScore-1.0: 1.1.9 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-06 •NIS2: 9.2.c.v •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_policy_allows_privilege_escalation Customer managed IAM policy does not allow actions that can lead to privilege escalation arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom Policy arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 11.2.2.a

PASS high iam us-east-2 iam_policy_allows_privilege_escalation Customer managed IAM policy does not allow actions that can lead to privilege escalation arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom Policy arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 11.2.2.a

PASS high iam us-east-2 iam_policy_allows_privilege_escalation Customer managed IAM policy does not allow actions that can lead to privilege escalation arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom Policy arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 11.2.2.a

PASS high iam us-east-2 iam_policy_allows_privilege_escalation Customer managed IAM policy does not allow actions that can lead to privilege escalation arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom Policy arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 11.2.2.a

PASS high iam us-east-2 iam_policy_allows_privilege_escalation Customer managed IAM policy does not allow actions that can lead to privilege escalation arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom Policy arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-06.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 11.2.2.a

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/aksinya User aksinya has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/Azamat User Azamat has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/Dilbag User Dilbag has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/Vasilii User Vasilii has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_policy_attached_only_to_group_or_roles IAM user has no inline or attached policies arn:aws:iam::716468089330:user/Yegor User Yegor has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

•CIS-7.0: 2.13 •SOC2: cc_1_3 •CIS-1.4: 1.15 •CIS-1.5: 1.15 •ISO27001-2013: A.9.2.I, A.9.4.I •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC •CIS-2.0: 1.15 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 •CIS-5.0: 1.14 •NIST-800-171-Revision-2: 3_4_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.15 •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •CIS-6.0: 2.14 •AWS-Foundational-Technical-Review: IAM-006, IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.1 •RBI-Cyber-Security-Framework: annex_i_7_1 •FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 •ProwlerThreatScore-1.0: 1.2.1, 1.2.2 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.15 •NIS2: 1.2.1, 2.1.2.f, 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_policy_cloudshell_admin_not_attached No IAM users, groups, or roles have the AWSCloudShellFullAccess policy attached arn:aws:iam::aws:policy/AWSCloudShellFullAccess AWS CloudShellFullAccess policy is not attached to any IAM entity.

Granting cloudshell:* enables an interactive shell with Internet egress and file upload/download, degrading confidentiality and integrity.

Compromised principals can exfiltrate data, stage tooling with sudo, persist artifacts in CloudShell, and operate from AWS IP space to bypass endpoint controls.

Detach AWSCloudShellFullAccess from identities.

Apply least privilege: permit CloudShell only when necessary via narrowly scoped permissions, restricted roles, short-lived sessions, and approvals. Prefer controlled alternatives (local CLI, bastion, or Session Manager). Enforce separation of duties and monitor usage.

•CIS-7.0: 2.20 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-02.01B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B •CIS-2.0: 1.22 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •CIS-5.0: 1.21 •PCI-4.0: 7.2.1.14, 7.2.1.15, 7.2.1.16, 7.2.2.14, 7.2.2.15, 7.2.2.16, 7.2.3.7, 7.2.5.10, 7.2.5.11, 7.2.5.12, 7.3.1.10, 7.3.1.11, 7.3.1.12, 7.3.2.10, 7.3.2.11, 7.3.2.12, 7.3.3.10, 7.3.3.11, 7.3.3.12, 8.2.7.10, 8.2.7.11, 8.2.7.12, 8.2.8.12, 8.2.8.13, 8.2.8.14, 8.3.4.10, 8.3.4.11, 8.3.4.12 •CIS-6.0: 2.21 •ProwlerThreatScore-1.0: 1.3.2 •CIS-4.0.1: 1.22 •NIS2: 1.2.1

PASS medium iam us-east-2 iam_policy_no_full_access_to_cloudtrail Customer managed IAM policy does not allow cloudtrail:* privileges arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.

This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.

Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

•SOC2: cc_3_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_cloudtrail Customer managed IAM policy does not allow cloudtrail:* privileges arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.

This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.

Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

•SOC2: cc_3_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_cloudtrail Customer managed IAM policy does not allow cloudtrail:* privileges arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.

This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.

Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

•SOC2: cc_3_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_cloudtrail Customer managed IAM policy does not allow cloudtrail:* privileges arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom Policy scrivas-s3-storage-policy does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.

This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.

Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

•SOC2: cc_3_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_cloudtrail Customer managed IAM policy does not allow cloudtrail:* privileges arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom Policy gitlab-ci-ecr-push does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.

This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.

Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

•SOC2: cc_3_3 •MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: IAM-10.01B, SIM-03.07B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •ENS-RD2022: op.exp.8.r4.aws.ct.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_kms Custom IAM policy does not allow 'kms:*' privileges arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 •ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_kms Custom IAM policy does not allow 'kms:*' privileges arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 •ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_kms Custom IAM policy does not allow 'kms:*' privileges arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 •ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_kms Custom IAM policy does not allow 'kms:*' privileges arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom Policy scrivas-s3-storage-policy does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 •ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_full_access_to_kms Custom IAM policy does not allow 'kms:*' privileges arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom Policy gitlab-ci-ecr-push does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity

•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.4 •PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 •ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 •NIS2: 11.2.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_wildcard_marketplace_subscribe Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_wildcard_marketplace_subscribe Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_wildcard_marketplace_subscribe Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_wildcard_marketplace_subscribe Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy Custom Policy scrivas-s3-storage-policy does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_policy_no_wildcard_marketplace_subscribe Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push Custom Policy gitlab-ci-ecr-push does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

•CISA: your-surroundings-3 •SOC2: cc_6_3 •KISA-ISMS-P-2023: 2.5.5 •C5-2025: IAM-01.01B, IAM-01.04B •HIPAA: 164_308_a_4_ii_b •KISA-ISMS-P-2023-korean: 2.5.5 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 •NIST-CSF-2.0: ac_4 •NIST-800-171-Revision-2: 3_1_5 •NIST-800-53-Revision-4: ac_6 •NIST-800-53-Revision-5: ac_6 •NIST-CSF-1.1: ac_4 •FFIEC: d3-pc-am-b-1 •ISO27001-2022: A.5.18, A.8.2 •FedRamp-Moderate-Revision-4: ac-6 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_role_access_not_stale_to_bedrock Regular Bedrock access ensures IAM roles retain only actively used permissions arn:aws:iam::716468089330:role/aws-service-role/config.amazonaws.com/AWSServiceRoleForConfig IAM Role AWSServiceRoleForConfig accessed Bedrock 0 days ago (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_role_access_not_stale_to_bedrock Regular Bedrock access ensures IAM roles retain only actively used permissions arn:aws:iam::716468089330:role/aws-service-role/resource-explorer-2.amazonaws.com/AWSServiceRoleForResourceExplorer IAM Role AWSServiceRoleForResourceExplorer accessed Bedrock 1 days ago (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_role_access_not_stale_to_bedrock Regular Bedrock access ensures IAM roles retain only actively used permissions arn:aws:iam::716468089330:role/aws-service-role/support.amazonaws.com/AWSServiceRoleForSupport IAM Role AWSServiceRoleForSupport has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_role_access_not_stale_to_bedrock Regular Bedrock access ensures IAM roles retain only actively used permissions arn:aws:iam::716468089330:role/IntruderReadOnlyRole IAM Role IntruderReadOnlyRole has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_role_access_not_stale_to_bedrock Regular Bedrock access ensures IAM roles retain only actively used permissions arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 IAM Role SecureframeRole-f983f1e89008 has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS high iam us-east-2 iam_role_administratoraccess_policy IAM role does not have AdministratorAccess policy attached arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole IAM Role AmazonEKS_EBS_CSI_DriverRole does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.

Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 1.2.1, 11.3.1

PASS high iam us-east-2 iam_role_administratoraccess_policy IAM role does not have AdministratorAccess policy attached arn:aws:iam::716468089330:role/IntruderReadOnlyRole IAM Role IntruderReadOnlyRole does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.

Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 1.2.1, 11.3.1

PASS high iam us-east-2 iam_role_administratoraccess_policy IAM role does not have AdministratorAccess policy attached arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 IAM Role SecureframeRole-f983f1e89008 does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.

Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02 •NIS2: 1.2.1, 11.3.1

PASS high iam us-east-2 iam_role_cross_account_readonlyaccess_policy IAM role does not grant ReadOnlyAccess to external AWS accounts arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole IAM Role AmazonEKS_EBS_CSI_DriverRole does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_2, am_6, ac_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05

PASS high iam us-east-2 iam_role_cross_account_readonlyaccess_policy IAM role does not grant ReadOnlyAccess to external AWS accounts arn:aws:iam::716468089330:role/IntruderReadOnlyRole IAM Role IntruderReadOnlyRole does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_2, am_6, ac_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05

PASS high iam us-east-2 iam_role_cross_account_readonlyaccess_policy IAM role does not grant ReadOnlyAccess to external AWS accounts arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 IAM Role SecureframeRole-f983f1e89008 does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_2, am_6, ac_6 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05

PASS high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/AmazonEKSAutoClusterRole IAM Service Role AmazonEKSAutoClusterRole prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/AmazonEKSAutoNodeRole IAM Service Role AmazonEKSAutoNodeRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonEBSCSIDriverRole IAM Service Role AmazonEKSPodIdentityAmazonEBSCSIDriverRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonVPCCNIRole IAM Service Role AmazonEKSPodIdentityAmazonVPCCNIRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/applications-eks-node-group-20251007184911320300000008 •Environment=scrivas-staging •Architecture=x64 •ManagedBy=terraform •Repository=devops-terraform •Service=applications •Purpose=workloads IAM Service Role applications-eks-node-group-20251007184911320300000008 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/service-role/AWSSystemsManagerDefaultEC2InstanceManagementRole IAM Service Role AWSSystemsManagerDefaultEC2InstanceManagementRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

PASS high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/service-role/CloudTrailRoleForCloudWatchLogs_MainTrail IAM Service Role CloudTrailRoleForCloudWatchLogs_MainTrail prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role IAM Service Role EC2-CloudWatchAgent-Role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/EC2-SSM-Access IAM Service Role EC2-SSM-Access does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/EC2SSMRole •scrivas= IAM Service Role EC2SSMRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/FlowLogsToCloudWatch IAM Service Role FlowLogsToCloudWatch does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/gpu-eks-node-group-20251007184911320100000007 •Architecture=x64 •Service=gpu •Environment=scrivas-staging •ManagedBy=terraform •Repository=devops-terraform •Purpose=ml-workloads IAM Service Role gpu-eks-node-group-20251007184911320100000007 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/infrastructure-eks-node-group-20251007184911319500000006 •Environment=scrivas-staging •Service=infrastructure •ManagedBy=terraform •Repository=devops-terraform •Architecture=x64 •Purpose=infrastructure IAM Service Role infrastructure-eks-node-group-20251007184911319500000006 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/rds-monitoring-role IAM Service Role rds-monitoring-role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

PASS high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 IAM Service Role scrivas-staging-cluster-20251007184855668200000001 prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/vpc-flow-logs-role IAM Service Role vpc-flow-logs-role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

PASS high iam us-east-2 iam_role_cross_service_confused_deputy_prevention IAM service role prevents cross-service confused deputy attack arn:aws:iam::716468089330:role/service-role/VPCFlowLogs-Cloudwatch-1781174191538 IAM Service Role VPCFlowLogs-Cloudwatch-1781174191538 prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

•MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 •ASD-Essential-Eight-Nov 2023: E8-4.4 •AWS-Account-Security-Onboarding: Predefine IAM Roles •ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 •AWS-Foundational-Technical-Review: IAM-0012 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •NIS2: 3.1.2.c, 6.8.2.a

FAIL high iam us-east-2 iam_root_credentials_management_enabled AWS Organization has centralized root credentials management enabled arn:aws:iam::716468089330:root Root credentials management is not enabled.

Without central control, member accounts can retain or recover long-term root credentials, weakening confidentiality and integrity.

Threats include:
- Account takeover via root email recovery
- Persistent access through root keys
- Unfixable lockouts from misconfigured policies
- Bypass of separation of duties

Enable centralized root access with root credentials management and assign a delegated administrator.

Apply least privilege and separation of duties by deleting long-term root credentials in members, limiting privileged tasks to short-lived sessions, enforcing MFA, and auditing root-related activity for defense in depth.

•CIS-7.0: 2.1.1 •C5-2025: IAM-03.01B, IAM-08.02B •NIST-CSF-2.0: rr_1, rr_2, po_4, ac_1 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN05.AR06 •AWS-AI-Security-Framework-1.0: AISF-IAM-04

FAIL critical iam us-east-2 iam_root_hardware_mfa_enabled Root account has a hardware MFA device enabled arn:aws:iam::716468089330:mfa Root account has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA on the root user:
- No MFA: stolen password/keys enable full account takeover.
- Virtual MFA: device compromise or backup restoration weakens second-factor assurance.
An attacker could delete resources, change policies, and disable logging, harming confidentiality, integrity, and availability.

Require a hardware MFA token for the root user and remove any virtual MFA. Apply least privilege: avoid using root, disable access keys, and eliminate long-term credentials. In organizations, centralize root management. Keep a controlled break-glass process with strict recovery checks and continuous monitoring.

•CISA: your-systems-3, your-surroundings-2 •CIS-7.0: 2.6 •CIS-1.4: 1.6 •CIS-1.5: 1.6 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.6 •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_d •CIS-2.0: 1.6 •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 •CIS-5.0: 1.5 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •PCI-4.0: 8.4.1.3, 8.4.2.3, 8.4.3.3 •NIST-800-53-Revision-4: ia_2_1, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •AWS-Account-Security-Onboarding: Root user - distribution email + MFA •CIS-3.0: 1.6 •ENS-RD2022: op.acc.6.r4.aws.iam.1 •CIS-6.0: 2.5 •AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.2 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.6 •NIS2: 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS critical iam us-east-2 iam_root_mfa_enabled Root account has MFA enabled arn:aws:iam::716468089330:root MFA is enabled for root account.

Without MFA, compromise of the root password or access keys can lead to full account takeover. An attacker with root can disable protections, steal or delete data, change billing, and create persistent admins, undermining confidentiality, integrity, and availability.

Enable MFA for the root user, preferably hardware-based or a dedicated, managed device. Remove root access keys and avoid using root for daily tasks. Apply least privilege with IAM Identity Center for admins, and use Organizations to centralize root access and eliminate long-lived root credentials.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.5 •CIS-1.4: 1.5 •CIS-1.5: 1.5 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •GDPR: article_25 •ISO27001-2013: A.9.2.K, A.9.4.K •KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 •C5-2025: OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-05.02B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_d •CIS-2.0: 1.5 •KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 •NIST-CSF-2.0: rr_1, po_4, ac_1, ac_6, ac_7, ip_1 •CIS-5.0: 1.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.4, 8.4.2.4, 8.4.3.4 •NIST-800-53-Revision-4: ac_2, ia_2_1, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •AWS-Account-Security-Onboarding: Root user - distribution email + MFA •CIS-3.0: 1.5 •ENS-RD2022: op.acc.6.r2.aws.iam.1 •CIS-6.0: 2.4 •AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.1 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.5 •NIS2: 11.3.2.a, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:root User <root_account> does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has not rotated access key 1 in over 90 days (322 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has not rotated access key 2 in over 90 days (319 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/aksinya User aksinya does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/Azamat User Azamat does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/Dilbag User Dilbag does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have access keys older than 90 days.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has not rotated access key 1 in over 90 days (316 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis does not have access keys older than 90 days.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user has not rotated access key 1 in over 90 days (161 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/Vasilii User Vasilii has not rotated access key 1 in over 90 days (147 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_rotate_access_key_90_days IAM user does not have active access keys older than 90 days arn:aws:iam::716468089330:user/Yegor User Yegor does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age

•CISA: your-systems-3 •CIS-7.0: 2.12 •CIS-1.4: 1.14 •CIS-1.5: 1.14 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.3 •ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B •HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.14 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 •NIST-CSF-2.0: ac_6 •CIS-5.0: 1.13 •PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 •NIST-800-53-Revision-4: ac_2_1, ac_2 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 •CIS-3.0: 1.14 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 •CIS-6.0: 2.13 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.IAM.CN06.AR01 •SecNumCloud-3.2: 9.4 •FFIEC: d3-pc-am-b-6 •ProwlerThreatScore-1.0: 1.1.11 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j •FedRAMP-Low-Revision-4: ac-2 •CIS-4.0.1: 1.14 •NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS low iam us-east-2 iam_securityaudit_role_created At least one IAM role has the SecurityAudit AWS managed policy attached arn:aws:iam::aws:policy/SecurityAudit SecurityAudit policy attached to role IntruderReadOnlyRole.

Without a dedicated read-only audit role, security teams lack safe visibility into configs and logs, enabling undetected misconfigurations, slower incident triage, and reliance on over-privileged access. This erodes confidentiality and integrity by letting exposure persist unnoticed.

Establish a dedicated audit role and attach the AWS managed SecurityAudit policy. Enforce least privilege and separation of duties: restrict who can assume it, require MFA, monitor usage, and avoid write permissions. Prefer federated access and regularly review and rotate access.

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-02.01B, OIS-02.02B, OIS-04.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-05.02B, IAM-06.06B, DEV-15.01B, SIM-01.02B, SIM-01.03B, COM-02.02B, COM-03.02B, INQ-02.01B, PSS-09.01AC •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •ENS-RD2022: op.acc.3.r2.aws.iam.1 •ISO27001-2022: A.5.3 •NIS2: 1.2.4, 2.1.1, 2.1.2.a, 2.1.2.e, 2.1.2.f, 2.2.1, 2.3.1, 3.1.2.c, 3.1.3, 6.2.2.a, 7.2.d, 7.2.e, 7.2.f

FAIL low iam us-east-2 iam_support_role_created At least one IAM role has the AWSSupportAccess managed policy attached arn:aws:iam::aws:policy/AWSSupportAccess AWS Support Access policy is not attached to any role.

Without a dedicated support role:
- Case creation and escalation can be delayed, prolonging outages (availability)
- Teams may use admin/root, increasing blast radius (confidentiality/integrity)
- Audit trails of support actions are weaker, hindering investigations

Create a dedicated IAM role for AWS Support with AWSSupportAccess and:
- Restrict who can assume it; require MFA and time-bound access
- Enforce least privilege and separation of duties
- Monitor usage via audit logs and review assignments regularly

•CIS-7.0: 2.15 •CIS-1.4: 1.17 •CIS-1.5: 1.17 •GDPR: article_25 •KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1 •C5-2025: OIS-02.01B, OIS-02.02B, HR-04.01B, OPS-13.02B, OPS-13.03AC, OPS-17.02B, OPS-24.01B, OPS-24.02B, IAM-01.01B, IAM-01.04B, IAM-06.06B, DEV-15.01B, SSO-05.06B, SIM-01.02B, SIM-01.03B •CIS-2.0: 1.17 •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1 •AWS-Well-Architected-Framework-Security-Pillar: SEC10-BP01 •CIS-5.0: 1.16 •AWS-Account-Security-Onboarding: Predefine IAM Roles •CIS-3.0: 1.17 •ENS-RD2022: op.acc.3.r1.aws.iam.1 •CIS-6.0: 2.16 •ProwlerThreatScore-1.0: 1.2.3 •CIS-4.0.1: 1.17 •NIS2: 2.1.1, 2.1.2.a, 2.2.1, 3.1.2.d, 4.3.2.a, 5.1.7.b

FAIL medium iam us-east-2 iam_user_access_not_stale_to_bedrock Regular Bedrock access ensures IAM users retain only actively used permissions arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya IAM User admin has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_access_not_stale_to_bedrock Regular Bedrock access ensures IAM users retain only actively used permissions arn:aws:iam::716468089330:user/aksinya IAM User aksinya has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_access_not_stale_to_bedrock Regular Bedrock access ensures IAM users retain only actively used permissions arn:aws:iam::716468089330:user/Dilbag IAM User Dilbag has not accessed Bedrock in 106 days (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_access_not_stale_to_bedrock Regular Bedrock access ensures IAM users retain only actively used permissions arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer IAM User igor@devteamspace.com has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_access_not_stale_to_bedrock Regular Bedrock access ensures IAM users retain only actively used permissions arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key IAM User louis has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.

An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.

Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

•MITRE-ATTACK: T1078 •ISO27001-2013: A.9.2.M •C5-2025: IAM-03.02B, IAM-10.01B •NIST-CSF-2.0: ac_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 •ENS-RD2022: op.acc.6.r7.aws.iam.1 •NIST-CSF-1.1: ac_1, ac_4 •SecNumCloud-3.2: 9.2, 9.4 •PCI-3.2.1: 8.1.4 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-05 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:root User <root_account> does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has not used access key 1 in the last 45 days (294 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has not used access key 2 in the last 45 days (318 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/aksinya User aksinya does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/Azamat User Azamat does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/Dilbag User Dilbag does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has not used access key 1 in the last 45 days (292 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user has not used access key 1 in the last 45 days (154 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/Vasilii User Vasilii does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_accesskey_unused IAM user does not have unused access keys older than 45 days arn:aws:iam::716468089330:user/Yegor User Yegor does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya IAM User admin does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/aksinya IAM User aksinya does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/Azamat IAM User Azamat does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/Dilbag IAM User Dilbag does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr IAM User gitlab-ci-ecr-push does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer IAM User igor@devteamspace.com does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key IAM User louis does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access IAM User scrivas-storage-user does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/Vasilii IAM User Vasilii does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

PASS critical iam us-east-2 iam_user_administrator_access_policy IAM user does not have AdministratorAccess policy attached arn:aws:iam::716468089330:user/Yegor IAM User Yegor does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials

•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B •KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 •NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 •ASD-Essential-Eight-Nov 2023: E8-4.2 •PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-02

FAIL medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has not logged in to the console in the past 45 days (113 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/aksinya User aksinya has not logged in to the console in the past 45 days (98 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/Azamat User Azamat has logged in to the console in the past 45 days (2 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/Dilbag User Dilbag has logged in to the console in the past 45 days (2 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have console access enabled or is unused.

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has not logged in to the console in the past 45 days (289 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis has logged in to the console in the past 45 days (-1 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user does not have console access enabled or is unused.

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/Vasilii User Vasilii has logged in to the console in the past 45 days (0 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

PASS medium iam us-east-2 iam_user_console_access_unused IAM user console access is disabled, used within the configured inactivity period, or never used arn:aws:iam::716468089330:user/Yegor User Yegor has logged in to the console in the past 45 days (1 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

•CISA: your-systems-3 •CIS-7.0: 2.11 •SOC2: cc_1_3 •CIS-1.4: 1.12 •CIS-1.5: 1.12 •MITRE-ATTACK: T1078, T1550, T1110 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 •ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B •HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d •CIS-2.0: 1.12 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •NIST-CSF-2.0: ac_1 •CIS-5.0: 1.11 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 •NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 •NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 •CIS-3.0: 1.12 •ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 •CIS-6.0: 2.11 •NIST-CSF-1.1: ac_1, ac_4 •CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 •SecNumCloud-3.2: 9.2, 9.4 •FFIEC: d3-pc-am-b-6 •PCI-3.2.1: 8.1, 8.1.4 •ProwlerThreatScore-1.0: 1.1.10 •ISO27001-2022: A.5.15 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 •FedRAMP-Low-Revision-4: ac-2, ac-3 •CIS-4.0.1: 1.12 •NIS2: 11.3.2.d, 11.5.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/aksinya User aksinya has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/Azamat User Azamat has hardware MFA enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/Dilbag User Dilbag has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have any type of MFA enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user does not have any type of MFA enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/Vasilii User Vasilii has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_hardware_mfa_enabled IAM user has hardware MFA enabled arn:aws:iam::716468089330:user/Yegor User Yegor has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

•CISA: booting-up-thing-to-do-first-2 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.6 •ISO27001-2022: A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRAMP-Low-Revision-4: ac-2 •NIS2: 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/aksinya User aksinya has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/Azamat User Azamat has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/Dilbag User Dilbag has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have Console Password enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user does not have Console Password enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/Vasilii User Vasilii has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS high iam us-east-2 iam_user_mfa_enabled_console_access IAM user has MFA enabled for console access or no console password is set arn:aws:iam::716468089330:user/Yegor User Yegor has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 •CIS-7.0: 2.10 •CIS-1.4: 1.10 •CIS-1.5: 1.10 •MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 •GDPR: article_25 •AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 •ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B •HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d •CIS-2.0: 1.10 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_7 •CIS-5.0: 1.9 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 •ASD-Essential-Eight-Nov 2023: E8-3.1 •PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 •NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 •NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 •CIS-3.0: 1.10 •ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 •CIS-6.0: 2.9 •AWS-Foundational-Technical-Review: IAM-001, IAM-0012 •NIST-CSF-1.1: ac_3, ac_7 •AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 •CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 •SecNumCloud-3.2: 9.5 •FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 •PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c •ProwlerThreatScore-1.0: 1.1.3 •ISO27001-2022: A.5.15, A.5.17, A.8.5 •AWS-AI-Security-Framework-1.0: AISF-IAM-01 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 •FedRAMP-Low-Revision-4: ac-2, ia-2 •CIS-4.0.1: 1.10 •NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:root User <root_account> does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/aksinya User aksinya does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/Azamat User Azamat does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/Dilbag User Dilbag does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/Vasilii User Vasilii does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_no_setup_initial_access_key IAM user does not have active access keys that have never been used arn:aws:iam::716468089330:user/Yegor User Yegor does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring

•CIS-1.4: 1.11 •CIS-1.5: 1.11 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B •CIS-2.0: 1.11 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •CIS-5.0: 1.1 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.11 •ENS-RD2022: op.acc.6.aws.iam.4 •CIS-6.0: 2.10 •CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.11 •NIS2: 9.2.c, 9.2.c.iii

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:root User <root_account> does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/aksinya User aksinya does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/Azamat User Azamat does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/Dilbag User Dilbag does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/Vasilii User Vasilii does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

PASS medium iam us-east-2 iam_user_two_active_access_key IAM user has at most one active access key arn:aws:iam::716468089330:user/Yegor User Yegor does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

•CIS-1.4: 1.13 •CIS-1.5: 1.13 •MITRE-ATTACK: T1078, T1550 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-10.01B, CRY-03.01B •CIS-2.0: 1.13 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 •NIST-CSF-2.0: ac_1, ac_6 •CIS-5.0: 1.12 •ASD-Essential-Eight-Nov 2023: E8-4.2 •CIS-3.0: 1.13 •ENS-RD2022: op.acc.6.aws.iam.1 •CIS-6.0: 2.12 •CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 •SecNumCloud-3.2: 9.3 •AWS-AI-Security-Framework-1.0: AISF-IAM-03 •CIS-4.0.1: 1.13 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/admin •AKIA2NUGTOHZOD7T5KWA=Deployment-Installation •AKIA2NUGTOHZBDLCH7XN=sai •AKIA2NUGTOHZO45UBFNB=aksinya User admin has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

PASS high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/aksinya User aksinya doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

PASS high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/Azamat User Azamat doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

PASS high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/Dilbag User Dilbag doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/gitlab-ci-ecr-push •AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr User gitlab-ci-ecr-push has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/igor@devteamspace.com •AKIA2NUGTOHZPMTQ6YNU=LocalComputer User igor@devteamspace.com has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/louis •AKIA2NUGTOHZGJX4RESB=Review Key User louis has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/scrivas-storage-user •AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access User scrivas-storage-user has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

FAIL high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/Vasilii User Vasilii has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

PASS high iam us-east-2 iam_user_with_temporary_credentials IAM user does not use long-lived credentials to access services other than IAM or STS arn:aws:iam::716468089330:user/Yegor User Yegor doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

•KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •NIST-CSF-2.0: ac_6 •AWS-Foundational-Technical-Review: IAM-002, IAM-0012 •AWS-AI-Security-Framework-1.0: AISF-IAM-03

PASS high inspector2 us-east-1 inspector2_active_findings_exist Inspector2 is enabled with no active findings arn:aws:inspector2:us-east-1:716468089330:inspector2 Inspector2 is enabled with no active findings.

Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.

This enables:
- Unauthorized access and data exfiltration (C)
- Code tampering and privilege escalation (I)
- Service disruption via exploitation or malware (A)

Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.

Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention.

•MITRE-ATTACK: T1190, T1562, T1110, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: AM-09.04AC, OPS-04.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: ov_2, ip_7, ip_12 •ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 •AWS-Foundational-Technical-Review: SECOPS-001 •SecNumCloud-3.2: 12.11 •NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr

FAIL high inspector2 us-east-2 inspector2_active_findings_exist Inspector2 is enabled with no active findings arn:aws:inspector2:us-east-2:716468089330:inspector2 There are active Inspector2 findings.

Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.

This enables:
- Unauthorized access and data exfiltration (C)
- Code tampering and privilege escalation (I)
- Service disruption via exploitation or malware (A)

Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.

Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention.

•MITRE-ATTACK: T1190, T1562, T1110, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: AM-09.04AC, OPS-04.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •NIST-CSF-2.0: ov_2, ip_7, ip_12 •ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5 •AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR •ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 •AWS-Foundational-Technical-Review: SECOPS-001 •SecNumCloud-3.2: 12.11 •NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr

PASS medium inspector2 us-east-1 inspector2_is_enabled Inspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda code arn:aws:inspector2:us-east-1:716468089330:inspector2 Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code.

Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.

Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability.

Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.

Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings.

•MITRE-ATTACK: T1190, T1562, T1110, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2 •C5-2025: OPS-32.01B, PSS-11.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2 •NIST-CSF-2.0: ip_7, ip_12, cm_1 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4 •AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR •ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 •AWS-Foundational-Technical-Review: SECOPS-001 •SecNumCloud-3.2: 12.11, 14.6, 18.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07

PASS medium inspector2 us-east-2 inspector2_is_enabled Inspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda code arn:aws:inspector2:us-east-2:716468089330:inspector2 Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code.

Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.

Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability.

Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.

Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings.

•MITRE-ATTACK: T1190, T1562, T1110, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2 •C5-2025: OPS-32.01B, PSS-11.01B •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2 •NIST-CSF-2.0: ip_7, ip_12, cm_1 •ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4 •AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR •ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 •AWS-Foundational-Technical-Review: SECOPS-001 •SecNumCloud-3.2: 12.11, 14.6, 18.4 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07

PASS low kms us-east-2 kms_cmk_are_used KMS customer managed key is enabled or scheduled for deletion arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is being used.

Keeping unused CMKs increases attack surface and cost.

If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability.

Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.

Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties.

•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01 •CCC-v2025.10: CCC.Core.CN11.AR03 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.5, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07

PASS low kms us-east-2 kms_cmk_are_used KMS customer managed key is enabled or scheduled for deletion arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is being used.

Keeping unused CMKs increases attack surface and cost.

If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability.

Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.

Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties.

•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01 •CCC-v2025.10: CCC.Core.CN11.AR03 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.5, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07

PASS critical kms us-east-2 kms_cmk_not_deleted_unintentionally AWS KMS customer managed key is not scheduled for deletion arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not scheduled for deletion.

A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window.

Prevent unintended deletion:
- Enforce least privilege and separation of duties for key admins
- Require change approvals and alerts on deletion events
- Prefer disabling unused keys over deleting
- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization

•AWS-Foundational-Security-Best-Practices: KMS.3 •KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1 •C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1 •NIST-CSF-2.0: ra_1, ds_3 •PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07

PASS critical kms us-east-2 kms_cmk_not_deleted_unintentionally AWS KMS customer managed key is not scheduled for deletion arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not scheduled for deletion.

A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window.

Prevent unintended deletion:
- Enforce least privilege and separation of duties for key admins
- Require change approvals and alerts on deletion events
- Prefer disabling unused keys over deleting
- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization

•AWS-Foundational-Security-Best-Practices: KMS.3 •KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1 •C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1 •NIST-CSF-2.0: ra_1, ds_3 •PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22 •CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07

PASS medium kms us-east-2 kms_cmk_not_multi_region AWS KMS customer managed key is single-Region arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is a single-region key.

Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability.

Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary.

•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC •NIST-CSF-2.0: ra_1 •ISO27001-2022: A.8.11, A.8.24

PASS medium kms us-east-2 kms_cmk_not_multi_region AWS KMS customer managed key is single-Region arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is a single-region key.

Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability.

Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary.

•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC •NIST-CSF-2.0: ra_1 •ISO27001-2022: A.8.11, A.8.24

FAIL high kms us-east-2 kms_cmk_rotation_enabled KMS customer-managed symmetric CMK has automatic rotation enabled arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d has automatic rotation disabled.

Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies.

Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected.

•CISA: your-systems-3 •CIS-7.0: 4.6 •SOC2: pi_1_5 •CIS-1.4: 3.8 •CIS-1.5: 3.8 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: KMS.4 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B •HIPAA: 164_312_a_2_iv •CIS-2.0: 3.8 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •CIS-5.0: 3.6 •PCI-4.0: 3.7.4.5, 3.7.5.2 •NIST-800-53-Revision-4: sc_12 •NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6 •CIS-3.0: 3.6 •ENS-RD2022: op.exp.10.aws.cmk.3 •CIS-6.0: 4.6 •CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01 •SecNumCloud-3.2: 10.5 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 3.2.1 •ISO27001-2022: A.8.5, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07 •FedRamp-Moderate-Revision-4: sc-12 •FedRAMP-Low-Revision-4: sc-12 •CIS-4.0.1: 3.6 •NIS2: 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL high kms us-east-2 kms_cmk_rotation_enabled KMS customer-managed symmetric CMK has automatic rotation enabled arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 has automatic rotation disabled.

Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies.

Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected.

•CISA: your-systems-3 •CIS-7.0: 4.6 •SOC2: pi_1_5 •CIS-1.4: 3.8 •CIS-1.5: 3.8 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: KMS.4 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B •HIPAA: 164_312_a_2_iv •CIS-2.0: 3.8 •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •CIS-5.0: 3.6 •PCI-4.0: 3.7.4.5, 3.7.5.2 •NIST-800-53-Revision-4: sc_12 •NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6 •CIS-3.0: 3.6 •ENS-RD2022: op.exp.10.aws.cmk.3 •CIS-6.0: 4.6 •CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01 •SecNumCloud-3.2: 10.5 •RBI-Cyber-Security-Framework: annex_i_1_3 •ProwlerThreatScore-1.0: 3.2.1 •ISO27001-2022: A.8.5, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07 •FedRamp-Moderate-Revision-4: sc-12 •FedRAMP-Low-Revision-4: sc-12 •CIS-4.0.1: 3.6 •NIS2: 11.6.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

MANUAL medium kms us-east-2 kms_key_enclave_attestation_unknown_image No enclave with an unknown image identity has called this KMS key arn:aws:kms:us-east-2:716468089330:enclave-debug-attestation Cannot verify unknown-image attestation activity: no 'enclave_golden_pcr_values' configured. Set a golden PCR list in audit_config and re-run this check.

An attestation event whose PCRs cannot be traced back to a known-good enclave build indicates either a stale golden list, a policy broad enough to accept unaudited images, or a compromise scenario in which an unknown image is being executed with legitimate KMS access. Materiality depends on the operator's threat model.

Treat the enclave_golden_pcr_values list as a live registry of trusted enclave images. Any runtime attestation from a PCR outside that list is either a documentation gap (extend the list) or a suspected incident (investigate).

•SOC2: cc_7_2 •MITRE-ATTACK: T1078 •HIPAA: 164_312_c_2 •NIST-CSF-2.0: cm_1 •PCI-4.0: 10.4.1.7 •NIST-800-53-Revision-5: si_4_2 •ISO27001-2022: A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-03 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

MANUAL high kms us-east-2 kms_key_enclave_debug_attestation_detected No Nitro Enclave debug-mode attestation observed against this KMS key arn:aws:kms:us-east-2:716468089330:enclave-debug-attestation No KMS-from-enclave attestation events found in the last 2160h. Debug-mode status cannot be determined from available data; enclaves that never call KMS in the window are not observable via this check.

Debug mode zeros the image, kernel and application PCRs (PCR0/1/2) in the attestation document, so PCR-bound key policies release material to enclaves whose measurement cannot be trusted. A debug enclave calling this KMS key is functionally equivalent to no enclave at all.

Never run production Nitro Enclaves with --debug-mode. Enforce non-debug launch flags in the enclave orchestration pipeline and pair with strict PCR bindings on KMS policies so debug enclaves are rejected at the key-policy layer.

•SOC2: cc_7_2 •MITRE-ATTACK: T1562 •HIPAA: 164_308_a_1_ii_d, 164_312_b •NIST-CSF-2.0: cm_1 •PCI-4.0: 3.5.1.36 •NIST-800-53-Revision-5: sc_28_1, si_4_2 •PCI-3.2.1: 10.2 •ISO27001-2022: A.8.16 •AWS-AI-Security-Framework-1.0: AISF-DETECT-03 •FedRamp-Moderate-Revision-4: sc-28, si-4-2 •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS critical kms us-east-2 kms_key_not_publicly_accessible Cloud KMS key does not grant access to allUsers or allAuthenticatedUsers arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d KMS key 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not exposed to Public.

Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key.

Apply least privilege to KMS keys:
- Restrict principals to specific roles and accounts
- Prefer narrow, time-bound grants
- Separate key administration from usage
- Use conditions to limit context
- Review regularly and remove wildcard or cross-account exposure

•CIS-7.0: 2.21 •AWS-Foundational-Security-Best-Practices: KMS.5 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.5 •ProwlerThreatScore-1.0: 2.2.14 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS critical kms us-east-2 kms_key_not_publicly_accessible Cloud KMS key does not grant access to allUsers or allAuthenticatedUsers arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 KMS key 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not exposed to Public.

Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key.

Apply least privilege to KMS keys:
- Restrict principals to specific roles and accounts
- Prefer narrow, time-bound grants
- Separate key administration from usage
- Use conditions to limit context
- Review regularly and remove wildcard or cross-account exposure

•CIS-7.0: 2.21 •AWS-Foundational-Security-Best-Practices: KMS.5 •KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 •C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.5 •ProwlerThreatScore-1.0: 2.2.14 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-07 •NIS2: 9.2.c •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS high macie us-east-2 macie_automated_sensitive_data_discovery_enabled Macie automated sensitive data discovery is enabled arn:aws:macie:us-east-2:716468089330:session Macie has automated sensitive data discovery enabled.

Without continuous discovery, sensitive S3 objects remain unclassified and unnoticed, weakening confidentiality. Over-permissive or public access can persist undetected, enabling data exfiltration and delaying containment and forensic response.

Enable and maintain automated sensitive data discovery for the Macie administrator across required Regions. Include relevant buckets, tune identifiers and allow lists to reduce noise, and route findings to monitoring. Complement with least privilege on S3 and defense in depth for data protection.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •PCI-4.0: A3.2.5.1.1, A3.2.5.1.3 •AWS-AI-Security-Framework-1.0: AISF-DATA-01

FAIL medium macie us-east-1 macie_is_enabled Amazon Macie is enabled arn:aws:macie:us-east-1:716468089330:session Macie is not enabled.

Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides.

Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls.

•CIS-7.0: 3.1.3 •CIS-1.4: 2.1.4 •CIS-1.5: 2.1.4 •MITRE-ATTACK: T1552, T1537, T1530 •AWS-Foundational-Security-Best-Practices: Macie.1 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •CIS-2.0: 2.1.3 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •CIS-5.0: 2.1.3 •PCI-4.0: A3.2.5.1.2, A3.2.5.1.4 •AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only •CIS-3.0: 2.1.3 •CIS-6.0: 3.1.3 •ProwlerThreatScore-1.0: 2.2.2 •AWS-AI-Security-Framework-1.0: AISF-DATA-01 •CIS-4.0.1: 2.1.3

PASS medium macie us-east-2 macie_is_enabled Amazon Macie is enabled arn:aws:macie:us-east-2:716468089330:session Macie is enabled.

Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides.

Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls.

•CIS-7.0: 3.1.3 •CIS-1.4: 2.1.4 •CIS-1.5: 2.1.4 •MITRE-ATTACK: T1552, T1537, T1530 •AWS-Foundational-Security-Best-Practices: Macie.1 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •CIS-2.0: 2.1.3 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •CIS-5.0: 2.1.3 •PCI-4.0: A3.2.5.1.2, A3.2.5.1.4 •AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only •CIS-3.0: 2.1.3 •CIS-6.0: 3.1.3 •ProwlerThreatScore-1.0: 2.2.2 •AWS-AI-Security-Framework-1.0: AISF-DATA-01 •CIS-4.0.1: 2.1.3

FAIL medium networkfirewall us-east-2 networkfirewall_in_all_vpc VPC has Network Firewall enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 VPC vpc-027f26d26f17ab361 does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.

Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •ENS-RD2022: mp.com.1.aws.nfw.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-02 •NIS2: 6.2.1, 6.7.2.b

FAIL medium networkfirewall us-east-2 networkfirewall_in_all_vpc VPC has Network Firewall enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c •Name=Scrivas_prod_vpc VPC Scrivas_prod_vpc does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.

Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •ENS-RD2022: mp.com.1.aws.nfw.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-02 •NIS2: 6.2.1, 6.7.2.b

FAIL medium networkfirewall us-east-2 networkfirewall_in_all_vpc VPC has Network Firewall enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 •Name=Scrivas_vpc VPC Scrivas_vpc does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.

Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •ENS-RD2022: mp.com.1.aws.nfw.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-02 •NIS2: 6.2.1, 6.7.2.b

PASS medium organizations us-east-2 organizations_account_part_of_organizations AWS account is a member of an active AWS Organization arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 AWS Organization o-qfj0pvhhv7 contains this AWS account.

Absence of AWS Organizations weakens governance across accounts. Without SCP guardrails and centralized policy, excessive permissions, unsafe network settings, or risky services may be enabled, threatening confidentiality and integrity. Fragmented logging and response slow containment, impacting availability and increasing cost exposure.

Operate all accounts under AWS Organizations (preferably with all features). Structure OUs, enforce SCPs for least privilege, and apply separation of duties between management and member accounts. Centralize logging and billing to support defense-in-depth, and routinely review org membership and policies.

•MITRE-ATTACK: T1078, T1087, T1580, T1538 •KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP01, SEC03-BP05, SEC08-BP04 •NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, am_6 •PCI-4.0: 7.2.1.1, 7.2.2.1, 7.2.5.1, 7.3.1.1, 7.3.2.1, 7.3.3.1, 8.2.7.1, 8.2.8.1, 8.3.4.1 •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8 •SecNumCloud-3.2: 9.6, 12.3, 14.4 •RBI-Cyber-Security-Framework: annex_i_1_1 •ISO27001-2022: A.8.3 •AWS-AI-Security-Framework-1.0: AISF-GOV-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-piy

PASS critical organizations us-east-2 organizations_delegated_administrators AWS Organization has only trusted delegated administrators arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 AWS Organization o-qfj0pvhhv7 has no Delegated Administrators.

Unapproved delegated administrators can alter SCPs, invite/move accounts, and create privileged roles, enabling privilege escalation. This undermines guardrails, risking loss of integrity, exposure of confidentiality across accounts, and impacts availability through organization-wide policy changes.

Restrict delegation to vetted accounts using least privilege and separation of duties. Maintain a centrally governed approved allowlist, review it regularly, and remove unused delegations. Enforce strong authentication for admin roles and monitor Organizations policy changes for defense in depth.

•CIS-7.0: 2.1.5, 2.1.6 •MITRE-ATTACK: T1078 •KISA-ISMS-P-2023: 2.5.5, 2.10.2 •C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B •KISA-ISMS-P-2023-korean: 2.5.5, 2.10.2 •NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, ov_3, am_6 •AWS-AI-Security-Framework-1.0: AISF-GOV-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-iam-07

FAIL medium organizations us-east-2 organizations_opt_out_ai_services_policy AWS Organization has opted out of all AI services and child accounts cannot override the policy arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 AWS Organization o-qfj0pvhhv7 has no opt-out policy for AI services.

Without an enforced opt-out, AI services may store and use your content for model training, weakening confidentiality and data sovereignty. If child accounts can override, they can re-enable data use, risking unintended cross-Region retention and exposure of logs, documents, or code processed by these services.

Establish an org-wide AI services opt-out: set the default to optOut and prohibit child policy overrides (@@none). Apply at the highest scope, gate exceptions through change control, and review periodically. Align with least privilege and data minimization to prevent unintended content sharing with managed AI services.

•KISA-ISMS-P-2023: 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.2 •NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3 •AWS-AI-Security-Framework-1.0: AISF-DATA-06 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam

FAIL high organizations us-east-2 organizations_scp_check_deny_regions AWS Organization restricts operations to only the configured AWS Regions with SCP policies arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 AWS Organization o-qfj0pvhhv7 has SCP policies but don't restrict AWS Regions.

Without comprehensive Region limits, users or attackers can deploy resources in ungoverned locations, bypassing monitoring and guardrails.

Impacts:
- Data outside approved jurisdictions (confidentiality)
- Policy gaps and drift (integrity)
- IR blind spots and unexpected cost (availability)

Enforce Region governance with SCPs that allow only approved regions via aws:RequestedRegion conditions (deny-by-default).

Apply across relevant OUs and accounts, with narrow exceptions for required global services. Review often; align to least privilege, data residency, and continuous monitoring.

•MITRE-ATTACK: T1078, T1535 •KISA-ISMS-P-2023: 2.10.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS, PSS-12.02AC •KISA-ISMS-P-2023-korean: 2.10.2 •NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, ov_3 •AWS-Account-Security-Onboarding: Block unused regions •ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8 •CCC-v2025.10: CCC.Core.CN06.AR01, CCC.Core.CN06.AR02 •SecNumCloud-3.2: 9.1, 19.2 •AWS-AI-Security-Framework-1.0: AISF-GOV-02 •FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-piy

FAIL low organizations us-east-2 organizations_tags_policies_enabled_and_attached AWS Organization has tag policies enabled and attached arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 AWS Organizations o-qfj0pvhhv7 does not have tag policies.

Absent or unattached tag policies cause inconsistent or missing tags, undermining:
- Confidentiality via bypassed tag-based access conditions
- Integrity through misclassified resources and drift
- Availability when automation, cost routing, or incident scoping that rely on tags break

Enable tag policies and attach them to relevant roots/OUs/accounts. Define mandatory keys (e.g., Environment, CostCenter) with allowed values. Apply defense in depth by using tags in IAM conditions and SCPs. Start with validation-only, then enforce, and continuously monitor compliance across accounts.

•KISA-ISMS-P-2023: 2.1.3 •C5-2025: AM-09.01B •KISA-ISMS-P-2023-korean: 2.1.3 •NIST-CSF-2.0: rm_1, po_3, ov_3 •ENS-RD2022: op.exp.1.aws.sys.2, op.exp.1.aws.tag.1, op.exp.10.aws.tag.1, mp.info.6.aws.tag.1 •ISO27001-2022: A.5.13 •AWS-AI-Security-Framework-1.0: AISF-GOV-02 •NIS2: 11.5.2.a •FedRAMP-20x-KSI-Low-25.05C: ksi-piy

PASS high rds us-east-2 rds_snapshots_encrypted RDS DB instance snapshot or DB cluster snapshot is encrypted arn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frame RDS Instance Snapshot for-secure-frame is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

•AWS-Foundational-Security-Best-Practices: RDS.4 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: ds_1 •ASD-Essential-Eight-Nov 2023: E8-8.3 •PCI-4.0: 3.5.1.26, 8.3.2.43 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •FedRAMP-20x-KSI-Low-25.05C: ksi-rpl

PASS high rds us-east-2 rds_snapshots_encrypted RDS DB instance snapshot or DB cluster snapshot is encrypted arn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshot RDS Instance Snapshot scrivas-encounter-dev-snapshot is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

•AWS-Foundational-Security-Best-Practices: RDS.4 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: ds_1 •ASD-Essential-Eight-Nov 2023: E8-8.3 •PCI-4.0: 3.5.1.26, 8.3.2.43 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •FedRAMP-20x-KSI-Low-25.05C: ksi-rpl

PASS high rds us-east-2 rds_snapshots_encrypted RDS DB instance snapshot or DB cluster snapshot is encrypted arn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot •Owner=DevTeamSpace •Purpose=BackupRestoreTest •Date=2025-10-20 RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

•AWS-Foundational-Security-Best-Practices: RDS.4 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: ds_1 •ASD-Essential-Eight-Nov 2023: E8-8.3 •PCI-4.0: 3.5.1.26, 8.3.2.43 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •FedRAMP-20x-KSI-Low-25.05C: ksi-rpl

PASS critical rds us-east-2 rds_snapshots_public_access RDS snapshot is not publicly shared arn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frame RDS Instance Snapshot for-secure-frame is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.

Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

•CISA: your-systems-3, your-data-2 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: RDS.1 •ISO27001-2013: A.12.6.H, A.13.1.G •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 •ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 •PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 •CCC-v2025.10: CCC.RDMS.CN05.AR01 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical rds us-east-2 rds_snapshots_public_access RDS snapshot is not publicly shared arn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshot RDS Instance Snapshot scrivas-encounter-dev-snapshot is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.

Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

•CISA: your-systems-3, your-data-2 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: RDS.1 •ISO27001-2013: A.12.6.H, A.13.1.G •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 •ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 •PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 •CCC-v2025.10: CCC.RDMS.CN05.AR01 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical rds us-east-2 rds_snapshots_public_access RDS snapshot is not publicly shared arn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot •Owner=DevTeamSpace •Purpose=BackupRestoreTest •Date=2025-10-20 RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.

Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

•CISA: your-systems-3, your-data-2 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: RDS.1 •ISO27001-2013: A.12.6.H, A.13.1.G •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 •ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 •PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 •CCC-v2025.10: CCC.RDMS.CN05.AR01 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS low resourceexplorer2 ap-northeast-1 resourceexplorer2_indexes_found Resource Explorer indexes exist arn:aws:resource-explorer-2:ap-northeast-1:716468089330:index/d4aa7318-d5e6-473d-b3c0-8328855a8bdc Resource Explorer Indexes found: 12.

Absent indexes reduce asset visibility, creating blind spots where misconfigured or orphaned resources go unnoticed. This degrades confidentiality (unseen public exposure), integrity (unauthorized changes undetected), and availability (slower containment and recovery), prolonging incident response and enabling lateral movement.

Create Resource Explorer indexes in all active Regions and designate an aggregator index for cross-Region search. Apply least-privilege access to views, align with tagging standards, and routinely verify indexing status. This improves inventory accuracy, supports defense-in-depth, and speeds detection and remediation.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •ENS-RD2022: op.exp.1.aws.re.1

FAIL high s3 us-east-2 s3_account_level_public_access_blocks S3 account-level Block Public Access ignores public ACLs and restricts public buckets arn:aws:s3:us-east-2:716468089330:account Block Public Access is not configured for the account 716468089330.

Absent these settings, public ACLs and broad bucket policies may grant internet or cross-account access. This risks:
- Confidentiality: bulk data exfiltration
- Integrity: object overwrite/tampering
- Availability: malicious deletions or malware hosting, triggering takedowns

Turn on account-level Block Public Access (prefer enabling all four: block_public_acls, ignore_public_acls, block_public_policy, restrict_public_buckets) to enforce least privilege. For legitimate access, use private buckets with CloudFront, VPC endpoints, or presigned URLs. Regularly review policies with IAM Access Analyzer.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.1 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.31, 1.2.8.32, 1.3.1.35, 1.3.1.36, 1.3.2.35, 1.3.2.36, 1.4.2.33, 1.4.2.34, 1.5.1.31, 1.5.1.32, 10.3.2.19, 10.3.2.20, 3.5.1.3.24, 3.5.1.3.25, A1.1.2.15, A1.1.2.16, A1.1.3.31, A1.1.3.32, A3.4.1.17, A3.4.1.18 •NIST-800-53-Revision-4: sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 •CIS-4.0.1: 2.1.4

PASS medium s3 us-east-1 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS medium s3 us-east-2 s3_bucket_acl_prohibited S3 bucket has bucket ACLs disabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

•CISA: your-data-2 •AWS-Foundational-Security-Best-Practices: S3.12 •KISA-ISMS-P-2023: 2.6.2, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •NIST-CSF-2.0: ds_5 •PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-1 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

FAIL high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has a bucket policy allowing cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

FAIL high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has a bucket policy allowing cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have a bucket policy.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

PASS high s3 us-east-2 s3_bucket_cross_account_access S3 bucket policy does not allow cross-account access arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.

Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: IAM-10.01B, IAM-10.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5, ip_1 •PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 •AWS-AI-Security-Framework-1.0: AISF-DATA-04

FAIL low s3 us-east-1 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

FAIL low s3 us-east-2 s3_bucket_cross_region_replication S3 bucket has cross-region replication configured to a bucket in a different region arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.

Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles.

  • Replicate needed prefixes and metadata
  • Consider S3 Replication Time Control for tighter RPO
  • Protect deletes via delete marker strategy and Object Lock
  • Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ds_4, pt_5 •ASD-Essential-Eight-Nov 2023: E8-8.3 •CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 •SecNumCloud-3.2: 12.5 •PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 •ISO27001-2022: A.8.14

PASS medium s3 us-east-1 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_default_encryption [DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •CIS-1.4: 2.1.1 •CIS-1.5: 2.1.1 •MITRE-ATTACK: T1119, T1530 •GDPR: article_32 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: ds_1, ds_3 •NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.30, 8.3.2.48 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 •ENS-RD2022: mp.si.2.aws.s3.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL low s3 us-east-1 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL low s3 us-east-2 s3_bucket_event_notifications_enabled S3 bucket has event notifications enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).

Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

•KISA-ISMS-P-2023: 2.10.2, 2.11.3 •C5-2025: OPS-13.01AC, OPS-13.03AC •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 •NIST-CSF-2.0: dp_4 •PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8

FAIL medium s3 us-east-1 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::config-bucket-716468089330 Server Side Encryption is not configured with kms for S3 Bucket config-bucket-716468089330.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 Server Side Encryption is not configured with kms for S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::maciedata1902 Server Side Encryption is not configured with kms for S3 Bucket maciedata1902.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::scrivas-access-logs Server Side Encryption is not configured with kms for S3 Bucket scrivas-access-logs.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform Server Side Encryption is not configured with kms for S3 Bucket scrivas-tf-statefile.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service Server Side Encryption is not configured with kms for S3 Bucket scrivasbackendstorage.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::scrivasbackupsdb Server Side Encryption is not configured with kms for S3 Bucket scrivasbackupsdb.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::scrivasloggsbucket Server Side Encryption is not configured with kms for S3 Bucket scrivasloggsbucket.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

FAIL medium s3 us-east-2 s3_bucket_kms_encryption S3 bucket has server-side encryption with AWS KMS arn:aws:s3:::vulnerability-reports-scrivas Server Side Encryption is not configured with kms for S3 Bucket vulnerability-reports-scrivas.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

•SOC2: pi_1_4 •AWS-Foundational-Security-Best-Practices: S3.17 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 •PCI-4.0: 3.5.1.31, 8.3.2.50 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 •SecNumCloud-3.2: 10.1 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04

PASS high s3 us-east-1 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::config-bucket-716468089330 Block Public Access is configured for the S3 Bucket config-bucket-716468089330.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 Block Public Access is configured for the S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::maciedata1902 Block Public Access is configured for the S3 Bucket maciedata1902.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::scrivas-access-logs Block Public Access is configured for the S3 Bucket scrivas-access-logs.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform Block Public Access is configured for the S3 Bucket scrivas-tf-statefile.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service Block Public Access is configured for the S3 Bucket scrivasbackendstorage.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::scrivasbackupsdb Block Public Access is configured for the S3 Bucket scrivasbackupsdb.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::scrivasloggsbucket Block Public Access is configured for the S3 Bucket scrivasloggsbucket.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

PASS high s3 us-east-2 s3_bucket_level_public_access_block S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level arn:aws:s3:::vulnerability-reports-scrivas Block Public Access is configured for the S3 Bucket vulnerability-reports-scrivas.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

•CIS-7.0: 3.1.4 •CIS-1.4: 2.1.5 •CIS-1.5: 2.1.5 •MITRE-ATTACK: T1530 •AWS-Foundational-Security-Best-Practices: S3.8 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •CIS-2.0: 2.1.4 •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •NIST-CSF-2.0: ac_3 •CIS-5.0: 2.1.4 •AWS-Account-Security-Onboarding: S3 Block Public Access •CIS-3.0: 2.1.4 •CIS-6.0: 3.1.4 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Logging.CN05.AR01 •SecNumCloud-3.2: 9.7 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •CIS-4.0.1: 2.1.4

FAIL low s3 us-east-1 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL low s3 us-east-2 s3_bucket_lifecycle_enabled S3 bucket has a lifecycle configuration enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

•AWS-Foundational-Security-Best-Practices: S3.13 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-32.02B •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •NIST-CSF-2.0: ds_3, ds_4 •PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 •CCC-v2025.10: CCC.AuditLog.CN06.AR01 •PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a •ISO27001-2022: A.8.10 •NIS2: 12.2.2.a

FAIL medium s3 us-east-1 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL medium s3 us-east-2 s3_bucket_no_mfa_delete S3 bucket has MFA Delete enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.

This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

•CIS-7.0: 3.1.2 •CIS-1.4: 2.1.3 •CIS-1.5: 2.1.3 •MITRE-ATTACK: T1485 •AWS-Foundational-Security-Best-Practices: S3.20 •KISA-ISMS-P-2023: 2.5.3, 2.10.2 •C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B •CIS-2.0: 2.1.2 •KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 •CIS-5.0: 2.1.2 •PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 •CIS-3.0: 2.1.2 •CIS-6.0: 3.1.2 •CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 •ProwlerThreatScore-1.0: 2.2.1 •CIS-4.0.1: 2.1.2 •NIS2: 11.7.2

FAIL low s3 us-east-1 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL low s3 us-east-2 s3_bucket_object_lock S3 bucket has Object Lock enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.

Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.

Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

•SOC2: pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.15 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •PCI-4.0: 10.3.4.7 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02

FAIL medium s3 us-east-1 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

PASS medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has versioning enabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

FAIL medium s3 us-east-2 s3_bucket_object_versioning S3 bucket has object versioning enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth

•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 •SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.14 •KISA-ISMS-P-2023: 2.9.3, 2.12.1 •C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 •KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 •GxP-21-CFR-Part-11: 11.10-a, 11.10-c •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer •NIST-800-171-Revision-2: 3_3_8 •ASD-Essential-Eight-Nov 2023: E8-8.2 •PCI-4.0: 10.3.4.9 •NIST-800-53-Revision-4: cp_10, si_12 •NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 •NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 •AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 •CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 •SecNumCloud-3.2: 12.5, 17.6 •RBI-Cyber-Security-Framework: annex_i_12 •FFIEC: d5-ir-pl-b-6 •PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 •ISO27001-2022: A.8.3, A.8.10 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 •FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5

PASS critical s3 us-east-1 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::config-bucket-716468089330 S3 public access blocked at bucket level for config-bucket-716468089330.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 public access blocked at bucket level for aws-cloudtrail-logs-716468089330-fb4a4f88.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::maciedata1902 S3 public access blocked at bucket level for maciedata1902.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::scrivas-access-logs S3 public access blocked at bucket level for scrivas-access-logs.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 public access blocked at bucket level for scrivas-tf-statefile.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 public access blocked at bucket level for scrivasbackendstorage.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have a bucket policy.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::scrivasloggsbucket S3 public access blocked at bucket level for scrivasloggsbucket.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_policy_public_write_access S3 bucket policy does not allow public write access arn:aws:s3:::vulnerability-reports-scrivas S3 public access blocked at bucket level for vulnerability-reports-scrivas.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 2.21 •MITRE-ATTACK: T1485, T1486 •AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 •CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.15 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-1 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-2 s3_bucket_public_access S3 bucket is not publicly accessible to Everyone or Authenticated Users arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

•CISA: your-systems-3, your-data-2 •SOC2: cc_6_1 •MITRE-ATTACK: T1530 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 •NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 •PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 •NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 •NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 •AWS-Account-Security-Onboarding: S3 Block Public Access •ENS-RD2022: op.exp.8.r4.aws.ct.2 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-im-b-1 •ISO27001-2022: A.8.1 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 •FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7

PASS critical s3 us-east-1 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-2 s3_bucket_public_list_acl S3 bucket is not publicly listable by Everyone or any authenticated AWS user arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ds_5 •AWS-Foundational-Technical-Review: S3-001 •AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •ProwlerThreatScore-1.0: 2.2.16

PASS critical s3 us-east-1 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

PASS critical s3 us-east-2 s3_bucket_public_write_acl S3 bucket ACL does not grant write access to Everyone or any AWS customer arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

•AWS-Foundational-Security-Best-Practices: S3.3 •KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 •NIST-CSF-2.0: ra_1, ds_5 •PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 •AWS-Foundational-Technical-Review: S3-001 •CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 •PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 •ProwlerThreatScore-1.0: 2.2.17

FAIL medium s3 us-east-1 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has a bucket policy to deny requests over insecure transport.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb does not have a bucket policy, thus it allows HTTP requests.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

FAIL medium s3 us-east-2 s3_bucket_secure_transport_policy S3 bucket policy denies requests over insecure transport arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.

Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

•CISA: your-systems-3, your-data-2 •CIS-7.0: 3.1.1 •CIS-1.4: 2.1.2 •CIS-1.5: 2.1.2 •MITRE-ATTACK: T1040 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: S3.5 •KISA-ISMS-P-2023: 2.7.1, 2.10.2 •HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii •CIS-2.0: 2.1.1 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •GxP-21-CFR-Part-11: 11.10-c, 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 •NIST-CSF-2.0: ds_2, pt_4 •CIS-5.0: 2.1.1 •NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 •PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 •NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 •NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 •CIS-3.0: 2.1.1 •ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 •CIS-6.0: 3.1.1 •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ds_2 •CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 •SecNumCloud-3.2: 10.2 •RBI-Cyber-Security-Framework: annex_i_1_3 •FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 •ProwlerThreatScore-1.0: 4.1.1 •AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 •FedRAMP-Low-Revision-4: ac-17, sc-7 •CIS-4.0.1: 2.1.1 •FedRAMP-20x-KSI-Low-25.05C: ksi-svc

PASS medium s3 us-east-1 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::config-bucket-716468089330 S3 Bucket config-bucket-716468089330 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::maciedata1902 S3 Bucket maciedata1902 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::scrivas-access-logs S3 Bucket scrivas-access-logs has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::scrivas-tf-statefile •Purpose=terraform-backend •ManagedBy=terraform S3 Bucket scrivas-tf-statefile has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::scrivasbackendstorage •Project = =scrivas Service S3 Bucket scrivasbackendstorage has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::scrivasbackupsdb S3 Bucket scrivasbackupsdb has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::scrivasloggsbucket S3 Bucket scrivasloggsbucket has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium s3 us-east-2 s3_bucket_server_access_logging_enabled S3 bucket has server access logging enabled arn:aws:s3:::vulnerability-reports-scrivas S3 Bucket vulnerability-reports-scrivas has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

•CISA: your-systems-3, your-data-2 •SOC2: cc_7_2, cc_7_3, cc_a_1_1 •AWS-Foundational-Security-Best-Practices: S3.9 •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e, 11.10-k •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 •NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c •AWS-Foundational-Technical-Review: S3-001 •NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 •SecNumCloud-3.2: 12.6 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 •PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 •ISO27001-2022: A.8.15 •AWS-AI-Security-Framework-1.0: AISF-DATA-04 •FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: ac-2, au-2 •NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

FAIL low sagemaker us-east-1 sagemaker_clarify_exists Amazon SageMaker Clarify processing jobs exist in the region arn:aws:sagemaker:us-east-1:716468089330:processing-job No SageMaker Clarify processing jobs found in region us-east-1.

Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
- Regulatory non-compliance with AI governance frameworks
- Undetected bias in model predictions affecting protected groups
- Lack of accountability for ML model decisions in production

Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices.

FAIL low sagemaker us-east-2 sagemaker_clarify_exists Amazon SageMaker Clarify processing jobs exist in the region arn:aws:sagemaker:us-east-2:716468089330:processing-job No SageMaker Clarify processing jobs found in region us-east-2.

Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
- Regulatory non-compliance with AI governance frameworks
- Undetected bias in model predictions affecting protected groups
- Lack of accountability for ML model decisions in production

Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices.

FAIL low sagemaker us-east-1 sagemaker_models_monitor_enabled Amazon SageMaker has a monitoring schedule scheduled arn:aws:sagemaker:us-east-1:716468089330:monitoring-schedule/unknown No SageMaker monitoring schedules found in region us-east-1.

Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model.

Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline.

FAIL low sagemaker us-east-2 sagemaker_models_monitor_enabled Amazon SageMaker has a monitoring schedule scheduled arn:aws:sagemaker:us-east-2:716468089330:monitoring-schedule/unknown No SageMaker monitoring schedules found in region us-east-2.

Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model.

Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline.

FAIL low sagemaker us-east-1 sagemaker_models_registry_in_use Amazon SageMaker Model Registry should have at least one approved model package arn:aws:sagemaker:us-east-1:716468089330:model-registry/unknown SageMaker Model Registry in region us-east-1 has no Model Package Groups.

An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows.

Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration.

•AWS-AI-Security-Framework-1.0: AISF-ML-04

FAIL low sagemaker us-east-2 sagemaker_models_registry_in_use Amazon SageMaker Model Registry should have at least one approved model package arn:aws:sagemaker:us-east-2:716468089330:model-registry/unknown SageMaker Model Registry in region us-east-2 has no Model Package Groups.

An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows.

Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration.

•AWS-AI-Security-Framework-1.0: AISF-ML-04

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz SecretsManager secret ScrivasML_post_processor_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc SecretsManager secret ScrivasML_post_processor_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC SecretsManager secret ScrivasML_post_processor_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 SecretsManager secret ScrivasML_patient_summary_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a SecretsManager secret ScrivasML_patient_summary_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF SecretsManager secret ScrivasML_patient_summary_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj SecretsManager secret ScrivasML_patient_document_parser_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD SecretsManager secret ScrivasML_patient_document_parser_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib SecretsManager secret ScrivasML_patient_document_parser_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF SecretsManager secret ScrivasML_sai_suggestions_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl SecretsManager secret ScrivasML_soniox_transcriber_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD SecretsManager secret ScrivasML_sai_suggestions_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq SecretsManager secret ScrivasML_sai_suggestions_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX SecretsManager secret ScrivasML_soniox_transcriber_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT SecretsManager secret ScrivasML_soniox_transcriber_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw SecretsManager secret ScrivasML_Monitoring_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU SecretsManager secret ScrivasML_Monitoring_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 SecretsManager secret ScrivasML_Monitoring_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_automatic_rotation_enabled Secrets Manager secret has rotation enabled arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 SecretsManager secret ScrivasBKPatientDev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

•CISA: your-systems-3 •MITRE-ATTACK: T1552 •AWS-Foundational-Security-Best-Practices: SecretsManager.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B •HIPAA: 164_308_a_4_ii_c •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b •AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 •NIST-CSF-2.0: ip_7 •PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 •NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 •NIST-CSF-1.1: ac_1 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv, 11.6.2.c

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz SecretsManager secret 'ScrivasML_post_processor_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc SecretsManager secret 'ScrivasML_post_processor_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC SecretsManager secret 'ScrivasML_post_processor_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 SecretsManager secret 'ScrivasML_patient_summary_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a SecretsManager secret 'ScrivasML_patient_summary_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF SecretsManager secret 'ScrivasML_patient_summary_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj SecretsManager secret 'ScrivasML_patient_document_parser_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD SecretsManager secret 'ScrivasML_patient_document_parser_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib SecretsManager secret 'ScrivasML_patient_document_parser_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF SecretsManager secret 'ScrivasML_sai_suggestions_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl SecretsManager secret 'ScrivasML_soniox_transcriber_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD SecretsManager secret 'ScrivasML_sai_suggestions_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq SecretsManager secret 'ScrivasML_sai_suggestions_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX SecretsManager secret 'ScrivasML_soniox_transcriber_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT SecretsManager secret 'ScrivasML_soniox_transcriber_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw SecretsManager secret 'ScrivasML_Monitoring_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU SecretsManager secret 'ScrivasML_Monitoring_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 SecretsManager secret 'ScrivasML_Monitoring_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL high secretsmanager us-east-2 secretsmanager_has_restrictive_resource_policy Secrets Manager secret has a restrictive resource-based policy arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 SecretsManager secret 'ScrivasBKPatientDev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

•AWS-AI-Security-Framework-1.0: AISF-DATA-03

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz Secret ScrivasML_post_processor_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc Secret ScrivasML_post_processor_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC Secret ScrivasML_post_processor_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 Secret ScrivasML_patient_summary_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a Secret ScrivasML_patient_summary_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF Secret ScrivasML_patient_summary_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj Secret ScrivasML_patient_document_parser_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD Secret ScrivasML_patient_document_parser_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib Secret ScrivasML_patient_document_parser_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF Secret ScrivasML_sai_suggestions_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl Secret ScrivasML_soniox_transcriber_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD Secret ScrivasML_sai_suggestions_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq Secret ScrivasML_sai_suggestions_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX Secret ScrivasML_soniox_transcriber_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT Secret ScrivasML_soniox_transcriber_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw Secret ScrivasML_Monitoring_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU Secret ScrivasML_Monitoring_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 Secret ScrivasML_Monitoring_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

FAIL medium secretsmanager us-east-2 secretsmanager_secret_rotated_periodically AWS Secrets Manager secret is rotated within the configured maximum number of days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 Secret ScrivasBKPatientDev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •NIST-CSF-2.0: ip_7 •CCC-v2025.10: CCC.SecMgmt.CN01.AR01 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz Secret ScrivasML_post_processor_Dev has been accessed recently, last accessed on August 17, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc Secret ScrivasML_post_processor_Stage has been accessed recently, last accessed on August 16, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC Secret ScrivasML_post_processor_Prod has been accessed recently, last accessed on August 16, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 Secret ScrivasML_patient_summary_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a Secret ScrivasML_patient_summary_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF Secret ScrivasML_patient_summary_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj Secret ScrivasML_patient_document_parser_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD Secret ScrivasML_patient_document_parser_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib Secret ScrivasML_patient_document_parser_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF Secret ScrivasML_sai_suggestions_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl Secret ScrivasML_soniox_transcriber_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD Secret ScrivasML_sai_suggestions_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq Secret ScrivasML_sai_suggestions_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX Secret ScrivasML_soniox_transcriber_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT Secret ScrivasML_soniox_transcriber_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw Secret ScrivasML_Monitoring_Dev has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU Secret ScrivasML_Monitoring_Stage has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 Secret ScrivasML_Monitoring_Prod has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

PASS medium secretsmanager us-east-2 secretsmanager_secret_unused Secrets Manager secret has been accessed within the last 90 days arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 Secret ScrivasBKPatientDev has been accessed recently, last accessed on July 29, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss

•KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 •SecNumCloud-3.2: 10.5 •AWS-AI-Security-Framework-1.0: AISF-DATA-03 •NIS2: 9.2.c.iv

FAIL high securityhub us-east-1 securityhub_delegated_admin_enabled_all_regions Security Hub has delegated admin configured and is enabled in all regions with organization auto-enable arn:aws:securityhub:us-east-1:716468089330:hub/default Security Hub in region us-east-1 has issues: no delegated administrator configured.

Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization.

Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization.

FAIL high securityhub us-east-2 securityhub_delegated_admin_enabled_all_regions Security Hub has delegated admin configured and is enabled in all regions with organization auto-enable arn:aws:securityhub:us-east-2:716468089330:hub/default Security Hub in region us-east-2 has issues: no delegated administrator configured.

Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization.

Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization.

PASS high securityhub us-east-1 securityhub_enabled Security Hub is enabled with standards or integrations configured arn:aws:securityhub:us-east-1:716468089330:hub/default Security Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices .

Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions.

  • Enable in all required accounts/Regions
  • Turn on relevant standards (AWS FSBP, CIS)
  • Connect AWS and third-party integrations
  • Use central configuration and least privilege
  • Automate triage and monitor continuously for defense in depth

•CISA: your-systems-3, your-crisis-response-2 •CIS-7.0: 5.16 •SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 •CIS-1.5: 4.16 •MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i •CIS-2.0: 4.16 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •GxP-EU-Annex-11: 1-risk-management •NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3 •CIS-5.0: 4.16 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9 •NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31 •AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account •CIS-3.0: 4.16 •ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1 •CIS-6.0: 5.16 •NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8 •SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.17 •ISO27001-2022: A.5.1, A.8.23 •AWS-AI-Security-Framework-1.0: AISF-DETECT-04 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4 •CIS-4.0.1: 4.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high securityhub us-east-2 securityhub_enabled Security Hub is enabled with standards or integrations configured arn:aws:securityhub:us-east-2:716468089330:hub/default Security Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices .

Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions.

  • Enable in all required accounts/Regions
  • Turn on relevant standards (AWS FSBP, CIS)
  • Connect AWS and third-party integrations
  • Use central configuration and least privilege
  • Automate triage and monitor continuously for defense in depth

•CISA: your-systems-3, your-crisis-response-2 •CIS-7.0: 5.16 •SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 •CIS-1.5: 4.16 •MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580 •KISA-ISMS-P-2023: 2.10.1, 2.10.2 •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i •CIS-2.0: 4.16 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •GxP-21-CFR-Part-11: 11.300-d •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 •GxP-EU-Annex-11: 1-risk-management •NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3 •CIS-5.0: 4.16 •NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9 •NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4 •NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31 •AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account •CIS-3.0: 4.16 •ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1 •CIS-6.0: 5.16 •NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8 •SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 •ProwlerThreatScore-1.0: 3.3.17 •ISO27001-2022: A.5.1, A.8.23 •AWS-AI-Security-Framework-1.0: AISF-DETECT-04 •FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c •FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4 •CIS-4.0.1: 4.16 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr

PASS high sns us-east-2 sns_subscription_not_using_http_endpoints SNS subscription uses an HTTPS endpoint arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8 Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8 is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

•KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: dp_4 •CCC-v2025.10: CCC.Core.CN01.AR01

PASS high sns us-east-2 sns_subscription_not_using_http_endpoints SNS subscription uses an HTTPS endpoint arn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93 Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93 is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

•KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: dp_4 •CCC-v2025.10: CCC.Core.CN01.AR01

PASS high sns us-east-2 sns_subscription_not_using_http_endpoints SNS subscription uses an HTTPS endpoint arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769ab Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769ab is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

•KISA-ISMS-P-2023: 2.7.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 •NIST-CSF-2.0: dp_4 •CCC-v2025.10: CCC.Core.CN01.AR01

FAIL high sns us-east-2 sns_topics_kms_encryption_at_rest_enabled SNS topic is encrypted at rest with KMS arn:aws:sns:us-east-2:716468089330:scrivas-alerts SNS topic scrivas-alerts is not encrypted.

Without KMS-backed SSE, SNS stores message bodies unencrypted at rest, undermining confidentiality.

Privileged insiders or compromised service components could access plaintext during persistence windows, causing data exposure. You also lose KMS controls such as key policies, rotation, and detailed audit trails.

Enable server-side encryption on all SNS topics with AWS KMS; prefer customer-managed keys for control.

Apply least privilege on key use, enforce rotation, and monitor key/access logs. Minimize sensitive data in messages and use end-to-end encryption where feasible to add defense in depth.

•CISA: your-systems-3, your-data-1, your-data-2 •SOC2: pi_1_4 •MITRE-ATTACK: T1530 •GDPR: article_32 •AWS-Foundational-Security-Best-Practices: SNS.1 •KISA-ISMS-P-2023: 2.7.2, 2.10.2 •C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01B, CRY-05.02B, CRY-05.01AC, PSS-10.01B, PSS-12.02B •HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii •KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 •GxP-21-CFR-Part-11: 11.30 •AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 •GxP-EU-Annex-11: 7.1-data-storage-damage-protection •NIST-CSF-2.0: be_5 •NIST-800-171-Revision-2: 3_13_11, 3_13_16 •PCI-4.0: 3.5.1.35, 8.3.2.54 •NIST-800-53-Revision-4: sc_28 •NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1 •AWS-Foundational-Technical-Review: SDAT-002 •NIST-CSF-1.1: ds_1 •CCC-v2025.10: CCC.Core.CN02.AR01, CCC.Message.CN01.AR01 •SecNumCloud-3.2: 10.1 •RBI-Cyber-Security-Framework: annex_i_1_3 •PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a •ISO27001-2022: A.8.3, A.8.11, A.8.24 •AWS-AI-Security-Framework-1.0: AISF-INFRA-05 •FedRamp-Moderate-Revision-4: sc-13, sc-28 •FedRAMP-Low-Revision-4: sc-13 •FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-svc

PASS high sns us-east-2 sns_topics_not_publicly_accessible SNS topic is not publicly accessible arn:aws:sns:us-east-2:716468089330:scrivas-alerts SNS topic scrivas-alerts is not public because its policy only allows access from the account 716468089330.

Public SNS topics allow anyone or unknown accounts to:
- Subscribe and siphon messages (confidentiality)
- Publish spoofed payloads that alter workflows (integrity)
- Flood messages causing outages and costs (availability)
They also enable cross-account abuse and bypass expected trust boundaries.

Restrict the topic policy to specific principals and minimal actions:
- Avoid Principal:*
- Allow only needed actions (e.g., sns:Publish)
- Add conditions like aws:SourceArn, aws:SourceAccount, aws:PrincipalOrgID, or sns:Endpoint
Apply least privilege, separate duties, and review policies regularly.

•CIS-7.0: 2.21 •ISO27001-2013: A.12.6.F, A.13.1.E •KISA-ISMS-P-2023: 2.5.6, 2.10.2 •C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B •KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 •CCC-v2025.10: CCC.Core.CN05.AR05 •ProwlerThreatScore-1.0: 2.3.1 •ISO27001-2022: A.8.1

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 •Name=Ml_prod EC2 managed instance i-0055a6b877ba156e7 is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e •Name=Scrivas_dev_env EC2 managed instance i-010066e6c9027aa6e is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

FAIL high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db •Name=Netbird_scrivas EC2 managed instance i-02754e7ae419cd5db is non-compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 •Name=ML_stage EC2 managed instance i-046e7fc4677eaa796 is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb •Name=Scrivas_stage_env EC2 managed instance i-067bdb5e3e09fa4bb is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd •Name=scrivas_prod_env EC2 managed instance i-073154fb4fa773bbd is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

PASS high ssm us-east-2 ssm_managed_compliant_patching EC2 managed instance is compliant with Systems Manager patching requirements arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b •Name=ML_dev EC2 managed instance i-095bd68aff22b103b is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.

This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.

Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 •SOC2: cc_3_2, cc_7_1 •AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 •KISA-ISMS-P-2023: 2.10.2, 2.10.8 •C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B •HIPAA: 164_308_a_5_ii_b •KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 •GxP-21-CFR-Part-11: 11.10-a, 11.10-h •AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 •NIST-CSF-2.0: ac_3 •NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 •ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 •PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 •NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 •NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 •ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 •NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 •SecNumCloud-3.2: 12.10 •RBI-Cyber-Security-Framework: annex_i_6 •FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 •PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b •ISO27001-2022: A.8.27 •FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 •FedRAMP-Low-Revision-4: cm-2, cm-8 •NIS2: 6.6.1.a •FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr

FAIL medium ssmincidents us-east-2 ssmincidents_enabled_with_plans SSM Incidents replication set is ACTIVE and has at least one response plan arn:aws:ssm-incidents:us-east-2:716468089330:replication-set No SSM Incidents replication set exists.

Without an ACTIVE replication set or response plans, incidents lack coordinated engagement and automation, raising MTTR and impacting availability and integrity.

Threats include prolonged outages, lateral movement, and data exfiltration from delayed containment and misrouted escalation.

Establish an ACTIVE replication set and create response plans that define engagement, escalation, runbooks, severity, and communication.

Apply least privilege to automation roles, test plans regularly, integrate with monitoring to trigger them, and use defense in depth with redundant contacts and Regions.

•KISA-ISMS-P-2023: 2.10.2, 2.11.1 •C5-2025: OIS-03.02B, OIS-03.05B, OIS-03.06B, OIS-05.03B, OIS-08.01B, OIS-08.09B, OPS-13.02B, OPS-13.03AC, OPS-22.08B, DEV-15.01B, SIM-01.02AC, SIM-02.01B, SIM-03.01B, SIM-03.04B, SIM-04.01B, SIM-06.01B, BCM-01.05B •KISA-ISMS-P-2023-korean: 2.10.2, 2.11.1 •NIST-CSF-2.0: ip_9, rp_1 •ENS-RD2022: op.exp.9.aws.img.1 •NIS2: 2.1.1, 2.1.2.a, 2.1.2.i, 3.1.1, 3.1.2.a, 3.1.2.c, 3.1.2.d, 3.5.1, 3.6.1, 3.6.2, 3.6.3, 4.3.1, 5.1.7.b, 12.1.2.c, 12.2.2.b

MANUAL medium trustedadvisor us-east-1 trustedadvisor_errors_and_warnings Trusted Advisor check has no errors or warnings arn:aws:trusted-advisor:us-east-1:716468089330:account Amazon Web Services Premium Support Subscription is required to use this service.

Unaddressed warnings/errors can leave misconfigurations that impact CIA:
- Confidentiality: public access or weak auth exposes data
- Integrity: overly permissive settings allow unwanted changes
- Availability: limit exhaustion or poor resilience triggers outages
They can also increase unnecessary cost.

Adopt a continuous process to remediate Trusted Advisor findings:
- Prioritize error then warning
- Assign ownership and SLAs
- Integrate alerts with workflows
- Enforce least privilege, segmentation, encryption, MFA, and tested backups
- Reassess regularly to confirm fixes and prevent regression

•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 •NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3

FAIL low trustedadvisor us-east-1 trustedadvisor_premium_support_plan_subscribed AWS account is subscribed to an AWS Premium Support plan arn:aws:trusted-advisor:us-east-1:716468089330:account Amazon Web Services Premium Support Plan isn't subscribed.

Without Premium Support, critical incidents face slower response, reducing availability and delaying containment of security events. Limited Trusted Advisor coverage lets misconfigurations persist, risking data exposure and privilege misuse. Lack of expert guidance increases change risk during production impacts.

Adopt Business or higher for production and mission-critical accounts.
- Integrate Support into IR with defined contacts/severity
- Enforce least privilege for case access
- Use Trusted Advisor for proactive hardening
- If opting out, ensure an equivalent 24/7 support and escalation path

•C5-2025: SSO-05.06B •NIST-CSF-2.0: rm_1, po_3, po_4, ov_3 •FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-tpr

FAIL medium vpc us-east-2 vpc_different_regions VPCs are present in more than one region arn:aws:ec2:us-east-2:716468089330:vpc VPCs found only in one region.

Single-region VPC deployment weakens availability and resilience. A regional outage, service disruption, or network control misconfiguration can cause broad downtime, hinder recovery, and increase the blast radius of incidents impacting business continuity.

Adopt a multi-region network design:
- Create VPCs in at least two regions for critical workloads
- Replicate routing, security controls, and endpoints consistently
- Apply fault tolerance and defense in depth with data replication and resilient DNS/failover to avoid single-region dependency

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 •ISO27001-2022: A.8.20, A.8.21, A.8.22

FAIL high vpc us-east-2 vpc_endpoint_connections_trust_boundaries VPC endpoint policy allows access only from trusted AWS accounts arn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d •GuardDutyManaged=true VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c can be accessed from non-trusted accounts.

Non-trusted principals using your endpoint can access AWS services as if from your VPC, weakening segmentation. This enables unauthorized reads/writes and data exfiltration from resources tied to the endpoint, harming confidentiality and integrity, and potentially increasing costs.

Apply least privilege: restrict endpoint policies to your account and an explicit allowlist of trusted accounts. Avoid * principals unless coupled with strict conditions. Prevent transitive trust across network links, and use resource policies and monitoring as defense in depth to limit endpoint use.

•CISA: your-systems-3 •KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 •C5-2025: COS-03.01B •KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 •AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP01 •NIST-CSF-2.0: rr_1, po_3, ov_3, ra_5, ac_5, ae_1 •AWS-Foundational-Technical-Review: NETSEC-002 •CCC-v2025.10: CCC.Core.CN05.AR03, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.Core.CN05.AR06, CCC.LB.CN09.AR01 •SecNumCloud-3.2: 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08 •NIS2: 6.8.2.a

FAIL medium vpc us-east-2 vpc_endpoint_for_ec2_enabled VPC has an Amazon EC2 VPC endpoint arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 VPC vpc-027f26d26f17ab361 has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth

•AWS-Foundational-Security-Best-Practices: EC2.10 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: ra_5, ae_1 •PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 •CCC-v2025.10: CCC.Core.CN05.AR05 •PCI-3.2.1: 1.3, 2.2, 2.2.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium vpc us-east-2 vpc_endpoint_for_ec2_enabled VPC has an Amazon EC2 VPC endpoint arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c •Name=Scrivas_prod_vpc VPC vpc-074cd9d22ca5c317c has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth

•AWS-Foundational-Security-Best-Practices: EC2.10 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: ra_5, ae_1 •PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 •CCC-v2025.10: CCC.Core.CN05.AR05 •PCI-3.2.1: 1.3, 2.2, 2.2.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium vpc us-east-2 vpc_endpoint_for_ec2_enabled VPC has an Amazon EC2 VPC endpoint arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 •Name=Scrivas_vpc VPC vpc-03b6368ab9a21d2c7 has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth

•AWS-Foundational-Security-Best-Practices: EC2.10 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: ra_5, ae_1 •PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 •CCC-v2025.10: CCC.Core.CN05.AR05 •PCI-3.2.1: 1.3, 2.2, 2.2.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

PASS medium vpc us-east-2 vpc_endpoint_multi_az_enabled Amazon VPC interface endpoint has subnets in multiple Availability Zones arn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d •GuardDutyManaged=true VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c has subnets in different AZs.

A single-subnet endpoint creates a single-AZ dependency. An AZ outage or routing issue can cut access to the service, reducing availability. Workloads may revert to public endpoints, exposing traffic to the Internet and risking confidentiality through interception or tampering.

Place interface endpoints in multiple subnets across distinct AZs to remove single-AZ reliance. Prefer zone-local routing so clients use the nearest endpoint, and combine with private DNS and restrictive security groups to limit exposure-supporting defense in depth and resilient connectivity.

•KISA-ISMS-P-2023: 2.9.2 •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, pt_5 •ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22

PASS medium vpc us-east-2 vpc_flow_logs_enabled VPC flow logs are enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 VPC vpc-027f26d26f17ab361 Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

•CISA: your-surroundings-1, your-data-2 •CIS-7.0: 4.7 •SOC2: cc_7_2, cc_7_3 •CIS-1.4: 3.9 •CIS-1.5: 3.9 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: EC2.6 •ISO27001-2013: A.12.4.R •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 •CIS-2.0: 3.9 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 •NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 •CIS-5.0: 3.7 •NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 •NIST-800-53-Revision-4: au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 •AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket •CIS-3.0: 3.7 •ENS-RD2022: op.mon.1.aws.flow.1 •CIS-6.0: 4.7 •NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 •SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 •PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 •ProwlerThreatScore-1.0: 3.1.4 •ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08 •FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: au-2 •CIS-4.0.1: 3.7 •NIS2: 3.2.3.c •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium vpc us-east-2 vpc_flow_logs_enabled VPC flow logs are enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c •Name=Scrivas_prod_vpc VPC Scrivas_prod_vpc Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

•CISA: your-surroundings-1, your-data-2 •CIS-7.0: 4.7 •SOC2: cc_7_2, cc_7_3 •CIS-1.4: 3.9 •CIS-1.5: 3.9 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: EC2.6 •ISO27001-2013: A.12.4.R •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 •CIS-2.0: 3.9 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 •NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 •CIS-5.0: 3.7 •NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 •NIST-800-53-Revision-4: au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 •AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket •CIS-3.0: 3.7 •ENS-RD2022: op.mon.1.aws.flow.1 •CIS-6.0: 4.7 •NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 •SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 •PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 •ProwlerThreatScore-1.0: 3.1.4 •ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08 •FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: au-2 •CIS-4.0.1: 3.7 •NIS2: 3.2.3.c •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium vpc us-east-2 vpc_flow_logs_enabled VPC flow logs are enabled arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 •Name=Scrivas_vpc VPC Scrivas_vpc Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

•CISA: your-surroundings-1, your-data-2 •CIS-7.0: 4.7 •SOC2: cc_7_2, cc_7_3 •CIS-1.4: 3.9 •CIS-1.5: 3.9 •GDPR: article_25, article_30 •AWS-Foundational-Security-Best-Practices: EC2.6 •ISO27001-2013: A.12.4.R •KISA-ISMS-P-2023: 2.9.4, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS •HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 •CIS-2.0: 3.9 •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 •GxP-21-CFR-Part-11: 11.10-e •AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 •NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 •CIS-5.0: 3.7 •NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 •PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 •NIST-800-53-Revision-4: au_2, au_3, au_12 •NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 •AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket •CIS-3.0: 3.7 •ENS-RD2022: op.mon.1.aws.flow.1 •CIS-6.0: 4.7 •NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 •CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 •SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 •RBI-Cyber-Security-Framework: annex_i_7_4 •FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 •PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 •ProwlerThreatScore-1.0: 3.1.4 •ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08 •FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c •FedRAMP-Low-Revision-4: au-2 •CIS-4.0.1: 3.7 •NIS2: 3.2.3.c •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium vpc us-east-2 vpc_subnet_different_az VPC has subnets in more than one Availability Zone arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 VPC vpc-027f26d26f17ab361 has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 •SecNumCloud-3.2: 17.2 •ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22

PASS medium vpc us-east-2 vpc_subnet_different_az VPC has subnets in more than one Availability Zone arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c •Name=Scrivas_prod_vpc VPC Scrivas_prod_vpc has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 •SecNumCloud-3.2: 17.2 •ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22

PASS medium vpc us-east-2 vpc_subnet_different_az VPC has subnets in more than one Availability Zone arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 •Name=Scrivas_vpc VPC Scrivas_vpc has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

•KISA-ISMS-P-2023: 2.9.2 •C5-2025: PS-02.01B, PS-02.02AS •KISA-ISMS-P-2023-korean: 2.9.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 •SecNumCloud-3.2: 17.2 •ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22

FAIL high vpc us-east-2 vpc_subnet_no_public_ip_by_default VPC subnet does not assign public IP addresses by default arn:aws:ec2:us-east-2:716468089330:subnet/subnet-028925e3b66ac3546 VPC subnet subnet-028925e3b66ac3546 assigns public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.

When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.15 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL high vpc us-east-2 vpc_subnet_no_public_ip_by_default VPC subnet does not assign public IP addresses by default arn:aws:ec2:us-east-2:716468089330:subnet/subnet-05e591b90cc4ce834 VPC subnet subnet-05e591b90cc4ce834 assigns public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.

When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.15 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

PASS high vpc us-east-2 vpc_subnet_no_public_ip_by_default VPC subnet does not assign public IP addresses by default arn:aws:ec2:us-east-2:716468089330:subnet/subnet-029a31cc702e7daaa •Name=prod-public-1b VPC subnet prod-public-1b does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.

When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.15 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

PASS high vpc us-east-2 vpc_subnet_no_public_ip_by_default VPC subnet does not assign public IP addresses by default arn:aws:ec2:us-east-2:716468089330:subnet/subnet-0cd1dad930562f3cd •Name=prod-public-1a VPC subnet prod-public-1a does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.

When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.15 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

PASS high vpc us-east-2 vpc_subnet_no_public_ip_by_default VPC subnet does not assign public IP addresses by default arn:aws:ec2:us-east-2:716468089330:subnet/subnet-04082d4e496af0c4c •Name=Scrivas_subnet1 VPC subnet Scrivas_subnet1 does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.

When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

•SOC2: cc_6_6 •AWS-Foundational-Security-Best-Practices: EC2.15 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 9.7 •RBI-Cyber-Security-Framework: annex_i_1_3 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium vpc us-east-2 vpc_subnet_separate_private_public VPC has both public and private subnets arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 VPC vpc-027f26d26f17ab361 has only public subnets.

Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, COS-02.01B, COS-07.04B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium vpc us-east-2 vpc_subnet_separate_private_public VPC has both public and private subnets arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c •Name=Scrivas_prod_vpc VPC Scrivas_prod_vpc has only public subnets.

Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, COS-02.01B, COS-07.04B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium vpc us-east-2 vpc_subnet_separate_private_public VPC has both public and private subnets arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 •Name=Scrivas_vpc VPC Scrivas_vpc has only public subnets.

Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

•SOC2: cc_6_6 •KISA-ISMS-P-2023: 2.6.1, 2.10.2 •C5-2025: PS-03.02B, COS-02.01B, COS-07.04B •KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 •NIST-CSF-2.0: be_5, ac_5 •ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 •AWS-Foundational-Technical-Review: NETSEC-002 •SecNumCloud-3.2: 13.2 •ISO27001-2022: A.8.20, A.8.21, A.8.22 •AWS-AI-Security-Framework-1.0: AISF-INFRA-08

FAIL medium wafv2 us-east-2 wafv2_webacl_logging_enabled AWS WAFv2 Web ACL has logging enabled arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d AWS WAFv2 Web ACL acl-alb-ec2-general does not have logging enabled.

Without WAF logging, visibility into allowed/blocked requests is lost, degrading detection and response. SQLi, credential stuffing, and bot/DDoS probes can go unnoticed, risking data exposure (C), undetected rule misuse (I), and service instability from unseen abuse (A).

Enable logging on all WAFv2 Web ACLs to a centralized destination. Apply least privilege for log delivery, redact sensitive fields, and filter to retain high-value events. Integrate with monitoring/SIEM for alerting and correlation, and review routinely as part of defense in depth.

•SOC2: cc_a_1_1, pi_1_2 •AWS-Foundational-Security-Best-Practices: WAF.11 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •PCI-4.0: 10.2.1.1.35, 10.2.1.2.30, 10.2.1.3.30, 10.2.1.4.30, 10.2.1.5.30, 10.2.1.6.30, 10.2.1.7.30, 10.2.1.30, 10.2.2.30, 10.3.1.30, 10.6.3.40, 5.3.4.35, A1.2.1.35 •AWS-Account-Security-Onboarding: Export metrics in centralized collector •CCC-v2025.10: CCC.LB.CN01.AR02 •SecNumCloud-3.2: 12.6 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-INFRA-03 •NIS2: 3.2.3.c, 11.2.2.f •FedRAMP-20x-KSI-Low-25.05C: ksi-mla

PASS medium wafv2 us-east-2 wafv2_webacl_rule_logging_enabled AWS WAFv2 Web ACL has Amazon CloudWatch metrics enabled for all rules and rule groups arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d AWS WAFv2 Web ACL acl-alb-ec2-general does have CloudWatch Metrics enabled in all its rules.

Absent CloudWatch metrics, WAF telemetry is lost, masking spikes, rule bypasses, and misconfigurations. This delays detection of SQLi/XSS probes and bot floods, risking data confidentiality, request integrity, and application availability.

Enable CloudWatch metrics for all WAF rules and rule groups (including managed rule groups). Use consistent metric names, centralize dashboards and alerts, and review trends to validate rule efficacy. Integrate with a SIEM for defense in depth and tune rules based on telemetry.

•SOC2: cc_a_1_1 •KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 •C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B •KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 •PCI-4.0: 10.2.1.1.36, 10.4.1.1.7, 10.4.1.6, 10.4.2.7, 10.6.3.41, 10.7.1.8, 10.7.2.8, A3.3.1.11, A3.5.1.11 •ISO27001-2022: A.8.15, A.8.16 •AWS-AI-Security-Framework-1.0: AISF-INFRA-03 •NIS2: 3.2.3.c

PASS high wafv2 us-east-2 wafv2_webacl_with_rules AWS WAFv2 Web ACL has at least one rule or rule group attached arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d AWS WAFv2 Web ACL acl-alb-ec2-general does have rules or rule groups attached.

Without rules, traffic is governed only by the web ACL DefaultAction, often allowing requests without inspection. This increases risks to confidentiality (data exfiltration via injection), integrity (XSS/parameter tampering), and availability (layer-7 DDoS, bot abuse).

Populate each web ACL with targeted rules or managed rule groups to enforce least-privilege web access: cover common exploits (SQLi/XSS), IP reputation, and rate limits, scoped to your apps. Use a conservative DefaultAction, monitor metrics/logs, and continually tune-supporting defense in depth and zero trust.

•KISA-ISMS-P-2023: 2.10.1, 2.10.2 •KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 •PCI-4.0: 6.4.1.8, 6.4.2.8 •CCC-v2025.10: CCC.LB.CN01.AR01 •SecNumCloud-3.2: 13.2 •AWS-AI-Security-Framework-1.0: AISF-INFRA-03