commit 3cce1fa61f6f3d1bfcf73755d9c11b883c78d7dd Author: Alvaro Del Valle Date: Wed Aug 19 14:50:09 2026 -0400 Initial Scrivas AWS discovery deliverables Read-only cloud discovery of the Scrivas AWS Organization (o-qfj0pvhhv7) to inform a proposal. - scripts/: boto3 org assessment, member-account assessment, fast discovery - findings/: self-contained HTML dashboards, written report, summary JSON, and the rendered Prowler benchmark report - docs/full_discovery_plan.md: phased full-discovery plan - index.html: landing page linking all reports - Pipfile/.python-version: reproducible pipenv env (Python 3.12.11) Large raw scans (OCSF JSON, CSV, compliance/) are git-ignored. diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..fe93fa6 --- /dev/null +++ b/.gitignore @@ -0,0 +1,24 @@ +# --- Python environment (rebuild from Pipfile.lock) --- +.venv/ +__pycache__/ +*.py[cod] +# note: .python-version IS committed (pins pyenv interpreter for the repo) + +# --- Large raw scan artifacts (keep rendered HTML + summary JSON) --- +findings/prowler/*.ocsf.json +findings/prowler/*.csv +findings/prowler/*.json.ocsf +findings/prowler/prowler_run.log +findings/prowler/compliance/ +output/ + +# --- Local AWS / secrets (never commit) --- +.aws/ +*.pem +*.env +.env + +# --- OS / editor cruft --- +.DS_Store +*.swp +.idea/ diff --git a/.python-version b/.python-version new file mode 100644 index 0000000..7eebfaf --- /dev/null +++ b/.python-version @@ -0,0 +1 @@ +3.12.11 diff --git a/.vscode/settings.json b/.vscode/settings.json new file mode 100644 index 0000000..bfc6e82 --- /dev/null +++ b/.vscode/settings.json @@ -0,0 +1,8 @@ +{ + "python.defaultInterpreterPath": "${workspaceFolder}/.venv/bin/python", + "python.terminal.activateEnvironment": true, + "python.venvPath": "${workspaceFolder}", + "files.exclude": { + "**/.venv": false + } +} diff --git a/Pipfile b/Pipfile new file mode 100644 index 0000000..a41184b --- /dev/null +++ b/Pipfile @@ -0,0 +1,18 @@ +[[source]] +url = "https://pypi.org/simple" +verify_ssl = true +name = "pypi" + +[packages] +boto3 = "*" +prowler = "*" + +[dev-packages] + +[requires] +python_version = "3.12" + +[scripts] +org-assessment = "python scripts/org_assessment.py" +member-assessment = "python scripts/assess_member_account.py" +fast-discovery = "python scripts/fast_discovery.py" diff --git a/Pipfile.lock b/Pipfile.lock new file mode 100644 index 0000000..0e1c9fd --- /dev/null +++ b/Pipfile.lock @@ -0,0 +1,3957 @@ +{ + "_meta": { + "hash": { + "sha256": "3baf7be393e1080cb3b4492a8e89f8c4dc694add773253ae532868ea3ddf008a" + }, + "pipfile-spec": 6, + "requires": { + "python_version": "3.12" + }, + "sources": [ + { + "name": "pypi", + "url": "https://pypi.org/simple", + "verify_ssl": true + } + ] + }, + "default": { + "about-time": { + "hashes": [ + "sha256:6a538862d33ce67d997429d14998310e1dbfda6cb7d9bbfbf799c4709847fece", + "sha256:8bbf4c75fe13cbd3d72f49a03b02c5c7dca32169b6d49117c257e7eb3eaee341" + ], + "markers": "python_version >= '3.7' and python_version < '4'", + "version": "==4.2.1" + }, + "aenum": { + "hashes": [ + "sha256:0dad0421b2fbe30e3fb623b2a0a23eff823407df53829d6a72595e7f76f3d872", + "sha256:8b883a37a04e74cc838ac442bdd28c266eae5bbf13e1342c7ef123ed25230139", + "sha256:a969a4516b194895de72c875ece355f17c0d272146f7fda346ef74f93cf4d5ba" + ], + "version": "==3.1.17" + }, + "aiofiles": { + "hashes": [ + "sha256:22a075c9e5a3810f0c2e48f3008c94d68c65d763b9b03857924c99e57355166c", + "sha256:b4ec55f4195e3eb5d7abd1bf7e061763e864dd4954231fb8539a0ef8bb8260e5" + ], + "markers": "python_version >= '3.8'", + "version": "==24.1.0" + }, + "aiohappyeyeballs": { + "hashes": [ + "sha256:065665c041c42a5938ed220bdcd7230f22527fbec085e1853d2402c8a3615d9d", + "sha256:9243213661e29250eb41368e5daa826fc017156c3b8a11440826b2e3ed376472" + ], + "markers": "python_version >= '3.10'", + "version": "==2.7.1" + }, + "aiohttp": { + "hashes": [ + "sha256:03cd2bde3d7f085b64e549c985f4bb928cad7e8ecf5323bfca320db548d81b39", + "sha256:041badb8f84396357c4d3ad26de6afd7a32b112f43d3c63045c0c8278cfd2043", + "sha256:0a5ff2dfbb9ce645fa5b8ef3e02c6c0b9cc3f6030ff863d0c51fffc50cb5541b", + "sha256:0fdea2281997af69da84c77ffa6f5938a0285f21fb3887c249d67419ca865b3d", + "sha256:11fb37ef075669eee52ab1928fbf6e1741fada40409fa309ebde9607a962aebf", + "sha256:134ac5ddcf61c6fad984b9a5727d83492ada43d63471db20fb73042c13fca62f", + "sha256:152516815ef926786a0b6ae2b8f1fd2e0c71582dee0b435636865316fd4891b7", + "sha256:1576145bdceeb92382d899751e12743a3a5b8e460a841e3e50543859e54864dc", + "sha256:16100ad3ab8d649fdfbee87602d9d2dcdca9df0b9eda8a1b5fdc0d41f96da559", + "sha256:16ea7e24c309fb7c0bbd505d149abe4fe4dccfb8db911db7dbec0921bc889a6f", + "sha256:18c441d0a8fca6de8d1f546849b9f0ab20d435993e2c5b59562b2fae6be2f929", + "sha256:18cb43369747b2ae007bd2655fb8e63a099c2ff1d207962943636dac989b3147", + "sha256:1b59533861b70a2185c8f4f350f791f39d64358ef6944ce71c5240c9ec0982c9", + "sha256:1c5281acc88b92396f88c7e1e2748f8466689df22b80170e4f51efa712fb47a8", + "sha256:1c5ec8fb1bcc31a8466f74aaf26c345d5c386fa4bd08a3f0eb9c7a4a3fe8b5bf", + "sha256:1caa7b0d05f3e3a36f87788c59e970a7ee1cefcfcbb924a9f138c4a6551c9cb7", + "sha256:21c016079415ed3fd676963e9793700a566d85dbbd6bfc564b9b2d209147dcc8", + "sha256:2498f0fe69ead802f9675beca44a7c21c62fdaa4ec5145ea1c3ad6edbee29f85", + "sha256:25bd2708db6bdf6a6630dd37bdcdfcb47c4434d22ac69c64665b802910140b30", + "sha256:270d3dace9ca2f10f0da5d8ebe519b7a310fc6112ed916e32df5866df0888553", + "sha256:2e1161602f45a54de2ce0905243a95f58cb42dcd378402f3697f5e0b21e9d2e7", + "sha256:2e9878ae68e4a5f1c0abe4dd497dbc3d51946f5837b56759e2a02e78fa90ef86", + "sha256:30402d03a7c0ff52bce290b57e564e9079fd9d0cb545c8aba73f86a103162d2e", + "sha256:33a2d7c28d33797a2e99923dffa63f83d908a19b6bf26cfe80fa790aa5e1a75a", + "sha256:362a3fd481769cac1a824514bcd86fda51c65e8fe6e051099e008fddde6db17c", + "sha256:38901a84da3ce22249f6e860bf8f90d141bcab7da090cc398f8bb58c0e44b7da", + "sha256:39aded8c7f3b935b54aab1d8d73c70ec0ee2d3ec3b943e0e86611bc150ba47f5", + "sha256:3a26434dafe408229ff3403458ca58de24fb51936504decac49ce6755f77e59d", + "sha256:3ae5b3a59436d089b5395d910121a390feed4d00578eb95a0fd1a329fe963100", + "sha256:3d4f72af88ac2474bb5bca640030320e3d38a0163a1d7533500e87be458eef71", + "sha256:3f42e9b78301f11c8f861746175d8b9c1ccef713fcad9eab396e2f6db8ed4a22", + "sha256:42a67efc36300d052fb4508a53e8b6901b9284b599ae63945c377569c5fcc1e1", + "sha256:48d67b87db6279c044760787eb01f6413032c2e6f3ba1cafaa492b1c8e578479", + "sha256:498c6c623134f8e09a3c4e60bcd607a0b4590dd7dbf08dd40851b27cbb520ccb", + "sha256:49f7325beb0f85ef4aef5f48f490269575f83e6e2acad00a1d80b807eb027062", + "sha256:4e3ac92d90e92773b2362d506068e9a948192bd553e743c5b2429e28527c8661", + "sha256:530125ee1163c4219af35dc3aa1206e541e7b31b6efc1a3f93b70a136f65d427", + "sha256:5373dc80ad1aa2fb9ad95c83f24eef418bbda3a61375f128e5b0192e4f3f9b32", + "sha256:53e5179d8abb5710f8e83ba207c41c8d1261fcffd4616500e15ca2b7a33be10a", + "sha256:53e7b4ce82b54a8bcc71b3b67a5cbd177ca1d7f592cbc92cd38b7349f73482db", + "sha256:543906c127fb1d929b95076db19b83fa2d46751006ff1e23b093aa5ac4d8db42", + "sha256:54cfcdee2770dac994417cbb0ee1f3eb0e7cb6b30c79bf44f2c02ff79ec5124a", + "sha256:55bdcc472aafe2de4a253045cc128007a64f1e0264fb675791e132ea5edaa3bd", + "sha256:56f355e79f71aef2a85c80305cc915f894b170dba76de5fe84f6351939b83c06", + "sha256:5895ef58c4620afe02fa16044f023dc4dafec08158f9d08874a46a7dbc0341b8", + "sha256:5bcb6ff3fdab1258a192679ff1a05d44f59626430aa05cd1a9d2447423599228", + "sha256:5f08ec777f35ee70720233b8b9811d3bb5d728137f30ac91b7457709c3261ac0", + "sha256:614c61d478b83953e261d02bb2df750f17227cd33ef8002945bf5aebbde21919", + "sha256:617105e2c3018ee38d0c8ce5ee3c84f621a6d8b9f723202aacaff28449ca91ee", + "sha256:6debfa7312ff9d4c124dc71d72e9a0a4b9e0879e48ba6fcb42bef5c3300289e2", + "sha256:7041d52c3a7fa20c9e8c182b534704abb19502c8bdcbde7ab23bfda6f642394f", + "sha256:70c987b27534f9ae1a723f47ae921571d616da21d3208282bf4c52af5164ac43", + "sha256:74ab5b6a9fb13e873e5a90946588baecaf488745e1db1a4a5c433f971f035098", + "sha256:78253b573e6ffab5028924fc98bc281aae05445969982a10864bc360dea2016c", + "sha256:7a75aa63cbf9b21cfaf60dc2657e19df2c2867d91707d653fee171ffeedd1371", + "sha256:8800c996b01c2772a783e3e46f3e1abd5823029adca0df54231960de9bfefa5b", + "sha256:89176250f686cb9853c0fb7ead90e639e915b84a6f43eedc2a4e7ec21f1037f0", + "sha256:8a5fd34f7f7410d1730d5c2ba873cacb2eed3fede366feb268a70ba22581ed8f", + "sha256:8b3b60de05f3dcb6f6a00f818bb2ec781cee4de0645f59ccaf99b1d1823b6100", + "sha256:8f2f1c4c032c7cedd7d8da6f54c97b70266c6570c3108d3fdffee7188bb70529", + "sha256:9491196535a88924a60afd5b5f434b5b203b6cc616250878dbdb223a8f7844bc", + "sha256:9aa6e61fdf20105c4144e755bd586008ff450791d67b1c8146fdc15959c4d51c", + "sha256:9d9edccfe496b476db5f398d97b865e9a6752bcf8aec4eef8390ce20fb64bb41", + "sha256:9fc7b5bfec6573f3ae844f457fdde5adeb713f8b8e4a81ad64fc207b49383716", + "sha256:a0dc483c00da8b673abbb367eb6f8d8f4bcec30eb58529ea13cb42e7fd2dfa33", + "sha256:a3a8296e7ab5c295f53f1041487cb088e1480775aafbf7fe545d93b770a0f96f", + "sha256:a3e22975f905b89a55a488c2a08f2fdb2186175349e917d48985cc468a3d4c6e", + "sha256:a4af35c443e0b1a1bd6a8af3f3485d7fda15c142751a00f3ff8090f0b93346fa", + "sha256:a94dbaae5ae27bd849c93570669bff91e0510f33a80805738e3de72a7be0447b", + "sha256:ac74facc01463f138b0da5580329cfcc82818dea5656e83ddcd11268fc12ff80", + "sha256:ad4c8b7488d745d2ca4838ebd8ae5ba9b56341d30b1da43640e4ce87f9f49646", + "sha256:b014a6ed7cf912e787149fdc529166d3ceabac23f26efeea3158c9aba2354e7e", + "sha256:b20032766aedf6261c7a566585a40867d092ac03a0d81592d5370ef9b054f99b", + "sha256:b2466434105a4e03113c36ec775cc2ebe6676b62eae326fa670bb607ef788c1c", + "sha256:b304db572b4368edd8dda8a2274f73156fe15558fca4a917cb8a09fc47af5963", + "sha256:ba59d59aba08ac02fc03b0c8983ccd5ee39a199d0552ce9e6d2b4845b34d59ae", + "sha256:bd52f811e65f6fb634b1047159657c98f52b407f8efec907bcfc09da9a4c0a25", + "sha256:bdd0e2834dce1a26c1bbe26464861e16bbe217042cbff619247c11594472518c", + "sha256:c23ec8ee9d5ab2f5421f9c7fffce208435607af27fd46d4a44e031954352838f", + "sha256:c39846c3aad97a8530c89d7a3869a8f8e9e3762c6ac0504481e5c80948f7e807", + "sha256:c3c200cf9757edd785051dc699c7ecbec22110dbfcb3fefc7a9f9695eda8ea7a", + "sha256:c7d3a97c678d34fc5b59da671ee9cd630096ddc643e7b5a30d54a2a6f3574d3f", + "sha256:c8653fd547c93a61aadc612007790f5555cdd18946fa48cf45e26d8ea4ea473d", + "sha256:cc7cb243a68167172f48c1fd43cee91ec4b1d40cefd190edd43369d1a6bc9c82", + "sha256:ccd4893707b3e2a13e39c90d43cf80edf2e4d0457935bcc103bf2346214c3f15", + "sha256:cd817772b2fcf2b8c0905795318485f9ec16eae60b29feb7f4c77085311637f0", + "sha256:cda5fd5c95ad7a125a2e8464acc78b98b94c475a3780d6aa0aa157c93f470f4d", + "sha256:cef89a58e628c4efcac3275c2d68083f82426dcdc89c1492a6f654f9f7ea6ab9", + "sha256:d1558173930a5a8d3069cee5c92fc91c87c4dbcb099debbb3622053717145a19", + "sha256:d6088ec9894113802bddb3c09e974929aed2c7b3a8c456219b8aab4481f1a239", + "sha256:d6218d92e450824e9b4881f44e8c09f1853b490f9a64130801024a4793b1b3b0", + "sha256:d77640cc618c1d99fc4f8589c0f24a730adfa54eb1e57ef7bf0c8dfb78da898c", + "sha256:d7d2deec16eeedf55f2c7cf75b521ea3856a5177e123844f8fd0f114ce252cb5", + "sha256:db332af25642007330fca8be5c4d194caf2bea7a7fc84415aff3497af5dfee6b", + "sha256:dd54d0e8717de95939766febac482ac0474d8ac3b048115f9f2b1d23a16e7db4", + "sha256:ddcac3c6b382e81f1dd0499199d4136b877beb4cb5ef770bbbfba56c4b8f55d2", + "sha256:df82f3787c940c94986b34222d59c9e38843fba85139f36e85255a82ad5355a9", + "sha256:dfa68deb2a443bdaa3ea5297b0699c1464f08aef3812b486d1348eee61b07dc0", + "sha256:dff9461ec275f22135650d5ba4b4931a11f3958df7dfbb8db630000d4dee0883", + "sha256:e1e74298bab6ee0d6e749ed4fd1901c7e604bdda32c03d787a2cc71c46d0433d", + "sha256:e2667f0bbe7eb6c74eae5e9691441ad186e5845ca3cff63230fc09c4e7514f5d", + "sha256:e3be98a7c30b8c25d573dafba7171d66dfb05ee6a9070fc46535464ff97700a6", + "sha256:e568e14940c09955aa51f4e645b6daa18a581c5dcfcd73744dcc86a856e3ced3", + "sha256:e72ee89e28d907a18f46959b4eb0bb06701cc7f8cf4366e00029e2ccfaaf5924", + "sha256:e92eb8acc45eb6a9f4935071a77edf5b85cc6f8dfad5cd99e97653c26593cdde", + "sha256:ea05e1f97ceea523942d9b2a7d7c0359d781d683d6b043f5943a602b14da4787", + "sha256:eac645b09bcfdf73df7536331f0678c1086ea250981118ddb5199e17ccef72bb", + "sha256:eb0495d778817619273c108784292be161a924b9f5ae5cbbc70a2caa6838250b", + "sha256:ebe8e504f058fe91223351cecd2d9d6946c9d241bb0250d898ffbdf584cc72b0", + "sha256:ed099d105449c4f9e84f24af203cd131349d4761d8813fa7e02c32e7128cd910", + "sha256:f0f177d1b195b9e06376cfd7d308d8a1b920909a609d03ac82a8c73bbb16d3b9", + "sha256:f3d2669fe7dec7fc359ecdb5984b29b50d85d5d00f8c1cb61de4f4a24ee42627", + "sha256:f4e05329faa0ea1a404b37de4f034fd2c2defcca06a68dc6745e4e56c88e8a48", + "sha256:f53bcd52f585e1ac3e590d61434eb61f9a88c38df041b4ea126d97144344a77b", + "sha256:f55119f7bf25f49ed210f6096090715da24f2943c62102448915fde3c62877ce", + "sha256:f631fe87a6f30df5fbe6d79640b25e4cffb38c31c7fb6f10871517b84b0f8c1a", + "sha256:f8fb78a83c9e5f741ca3a68cfb455c1f5bb83b4e7249a3848b3cd78d0a8563b0", + "sha256:fa9467a8113aa69d3d7c55a70ef0b7c636010a40993f3df9d9d0d73b3eb7ef24", + "sha256:fd51ebf9d3a00c074df4ede271023f4d2dba289bcc740b88191872716014e3c5" + ], + "markers": "python_version >= '3.10'", + "version": "==3.14.3" + }, + "aiosignal": { + "hashes": [ + "sha256:053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e", + "sha256:f47eecd9468083c2029cc99945502cb7708b082c232f9aca65da147157b251c7" + ], + "markers": "python_version >= '3.9'", + "version": "==1.4.0" + }, + "alibabacloud-actiontrail20200706": { + "hashes": [ + "sha256:5dee0009db9b7cba182fbac742820f6a949287a8faafb843b5107f7dc89136da", + "sha256:b65c6b37a96443fbe625dd5a4dd1be52a7476006a411db75206908b11588ffa8" + ], + "markers": "python_version >= '3.6'", + "version": "==2.4.1" + }, + "alibabacloud-credentials": { + "hashes": [ + "sha256:30c8302f204b663c655d97e1c283ee9f9f84a6257d7901b931477d6cf34445a8", + "sha256:9d8707e96afc6f348e23f5677ed15a21c2dfce7cfe6669776548ee4c80e1dfaf" + ], + "markers": "python_version >= '3.7'", + "version": "==1.0.3" + }, + "alibabacloud-credentials-api": { + "hashes": [ + "sha256:5f27889113214fc53493b3e918eb26d73dfab2022e22bdaac262849b8e58cbc0", + "sha256:8ea0668a6558f6956b8d20b2e561d19a80ea29c22cf56a3004d434b24a981b36" + ], + "markers": "python_version >= '3.7'", + "version": "==1.0.1" + }, + "alibabacloud-cs20151215": { + "hashes": [ + "sha256:5b3d99306701bf499ddd57cd9f2905b7721cb1bb4bb38ffe4d051f7b4e80e355", + "sha256:75e90b1bb9acca2236244bb0e44234ca4805d456ea4303ba4225ac15152a458e" + ], + "markers": "python_version >= '3.6'", + "version": "==6.1.0" + }, + "alibabacloud-darabonba-array": { + "hashes": [ + "sha256:7f9a7c632518ff4f0cebb0d4e825a48c12e7cf0b9016ea25054dd73732e155aa" + ], + "markers": "python_version >= '3.6'", + "version": "==0.1.0" + }, + "alibabacloud-darabonba-encode-util": { + "hashes": [ + "sha256:6a91c82f6cc4227091be39b65d1f6921d7330119bac7b911e5a26daf895cc9dc", + "sha256:f293ed5f5933e97061a51d80aeb4bdc4d38bc67f6e0aca6eda7c5d7814b21c46" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.3" + }, + "alibabacloud-darabonba-map": { + "hashes": [ + "sha256:adb17384658a1a8f72418f1838d4b6a5fd2566bfd392a3ef06d9dbb0a595a23f" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.1" + }, + "alibabacloud-darabonba-signature-util": { + "hashes": [ + "sha256:71d79b2ae65957bcfbf699ced894fda782b32f9635f1616635533e5a90d5feb0" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.4" + }, + "alibabacloud-darabonba-string": { + "hashes": [ + "sha256:ec6614c0448dadcbc5e466485838a1f8cfdd911135bea739e20b14511270c6f7" + ], + "version": "==0.0.4" + }, + "alibabacloud-darabonba-time": { + "hashes": [ + "sha256:0ad9c7b0696570d1a3f40106cc7777f755fd92baa0d1dcab5b7df78dde5b922d" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.1" + }, + "alibabacloud-ecs20140526": { + "hashes": [ + "sha256:10bda5e185f6ba899e7d51477373595c629d66db7530a8a37433fb4e9034a96f", + "sha256:2abbe630ce42d69061821f38950b938c5982cc31902ccd7132d05be328765a55" + ], + "markers": "python_version >= '3.6'", + "version": "==7.2.5" + }, + "alibabacloud-endpoint-util": { + "hashes": [ + "sha256:a593eb8ddd8168d5dc2216cd33111b144f9189fcd6e9ca20e48f358a739bbf90" + ], + "version": "==0.0.4" + }, + "alibabacloud-gateway-oss": { + "hashes": [ + "sha256:7ec8ea2f7f83bc7201326d6c2360c78fd092bc1931c5824d368b46d4d8779bee", + "sha256:ae952c48332622cd78552b943c854df7e6deea197266c2837176687416ae48a9" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.29" + }, + "alibabacloud-gateway-oss-util": { + "hashes": [ + "sha256:5eb7fa450dc7350d5c71577974b9d7f489479e5c5ec7efc1c5376385e8c1c0a5" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.3" + }, + "alibabacloud-gateway-sls": { + "hashes": [ + "sha256:106685a23b49ab2f0682ee2c3e160da9b50ea466de531b4e9259bc8c0583d61e", + "sha256:77bf66f136cdee9127e9070e43db574b3dc53166687498e2b95c6c61305c7baa" + ], + "markers": "python_version >= '3.7'", + "version": "==0.4.2" + }, + "alibabacloud-gateway-sls-util": { + "hashes": [ + "sha256:289f302e0e07456be5f811be9b9b526445576ae3b91f125f15870d335a211234", + "sha256:c03dcf894343c085da580b3b90c6788e38da00eceee77bacd4e6fded823877d9" + ], + "markers": "python_version >= '3.7'", + "version": "==0.4.1" + }, + "alibabacloud-gateway-spi": { + "hashes": [ + "sha256:0d5256e95d8719da8ec9611b7ffbb12c2d26fdf7ce52c8f64e4e06350731e893", + "sha256:73d6e20d65b54eed26d89c19640d3a7572e18c45ecada627f806f5dbe8ed2130" + ], + "markers": "python_version >= '3.6'", + "version": "==0.0.4" + }, + "alibabacloud-openapi-util": { + "hashes": [ + "sha256:87022b9dcb7593a601f7a40ca698227ac3ccb776b58cb7b06b8dc7f510995c34", + "sha256:a2474f230b5965ae9a8c286e0dc86132a887928d02d20b8182656cf6b1b6c5bd" + ], + "version": "==0.2.4" + }, + "alibabacloud-oss-util": { + "hashes": [ + "sha256:d3ecec36632434bd509a113e8cf327dc23e830ac8d9dd6949926f4e334c8b5d6" + ], + "version": "==0.0.6" + }, + "alibabacloud-oss20190517": { + "hashes": [ + "sha256:365fda353de6658a1a289f4d70dcd0394e2a8e2921b6b5834ba6d9772121d2f6", + "sha256:7cd0fb16af613ceb38d2e0e529aa1f58038c7cf59eb67c8c8775ae44ea717852" + ], + "markers": "python_version >= '3.6'", + "version": "==1.0.6" + }, + "alibabacloud-ram20150501": { + "hashes": [ + "sha256:03a0f2a0259848787c1f74e802b486184a88e04183486bd9398766971e5eb00a", + "sha256:6253513c8880769f4fd5b36fedddb362a9ca628ad9ae9c05c0eeacf5fbc95b42" + ], + "markers": "python_version >= '3.6'", + "version": "==1.2.0" + }, + "alibabacloud-rds20140815": { + "hashes": [ + "sha256:0bd7e2018a428d86b1b0681087336e74665b48fc3eb0a13c4f4377ed5eab2b08", + "sha256:e7421d94f18a914c0a06b0e7fad0daff557713f1c97d415d463a78c1270e9b98" + ], + "markers": "python_version >= '3.6'", + "version": "==12.0.0" + }, + "alibabacloud-sas20181203": { + "hashes": [ + "sha256:1ad735332c50c7961be036b17420d56b5ec3b5557e3aea1daa19491e8b75da20", + "sha256:e49ffd53e630274a8bf5a8299ca753023ad118510c80f6d9c6fb018b7479bf37" + ], + "markers": "python_version >= '3.6'", + "version": "==6.1.0" + }, + "alibabacloud-sls20201230": { + "hashes": [ + "sha256:bea830b64fbc7ed1719ba386ceeefb120f08d705f03eb0e02409dc6f12a291da", + "sha256:c4ae14096817a9686af5a0ae2389f1f6a8781e60b9edb8643445250cf15c26f1" + ], + "markers": "python_version >= '3.6'", + "version": "==5.9.0" + }, + "alibabacloud-sts20150401": { + "hashes": [ + "sha256:627f5ca1f86e19b0bf8ce0e99071a36fb65579fad9256fbee38fdc8d500598e9", + "sha256:c2529b41e0e4531e21cb393e4df346e19fd6d54cc6337d1138dbcd2191438d4c" + ], + "markers": "python_version >= '3.6'", + "version": "==1.1.6" + }, + "alibabacloud-tea": { + "hashes": [ + "sha256:ec8053d0aa8d43ebe1deb632d5c5404339b39ec9a18a0707d57765838418504a" + ], + "markers": "python_version >= '3.7'", + "version": "==0.4.3" + }, + "alibabacloud-tea-openapi": { + "hashes": [ + "sha256:c9e1727b9fb2936f487d050fc3590c99f9f2065256dc3a927e5b61f414674ed6", + "sha256:dafc32401712f5b21c12dc3d05ba887a91ad156d9b49a7662279f9fd90526fb2" + ], + "markers": "python_version >= '3.7'", + "version": "==0.4.6" + }, + "alibabacloud-tea-util": { + "hashes": [ + "sha256:79f78e596f6be03fb9565e34ac45420f3730e52888376cc9713bd07432a4c6cc", + "sha256:afb3dd8ad5cd2f93804258fbbac4360c050462100499269795ea055c1644e193" + ], + "markers": "python_version >= '3.6'", + "version": "==0.3.15" + }, + "alibabacloud-tea-xml": { + "hashes": [ + "sha256:979cb51fadf43de77f41c69fc69c12529728919f849723eb0cd24eb7b048a90c" + ], + "version": "==0.0.3" + }, + "alibabacloud-vpc20160428": { + "hashes": [ + "sha256:933cf1e74322a20a2df27ca6323760d857744a4246eeadc9fb3eae01322fb1c6", + "sha256:daf00679a83d422799f9fcf263739fe1f360641675843cbfbe623833fc8b1681" + ], + "markers": "python_version >= '3.6'", + "version": "==6.13.0" + }, + "alive-progress": { + "hashes": [ + "sha256:457dd2428b48dacd49854022a46448d236a48f1b7277874071c39395307e830c", + "sha256:63dd33bb94cde15ad9e5b666dbba8fedf71b72a4935d6fb9a92931e69402c9ff" + ], + "markers": "python_version >= '3.9' and python_version < '4'", + "version": "==3.3.0" + }, + "aliyun-log-fastpb": { + "hashes": [ + "sha256:3a85ccc868a9012461216f6a098e0833b64b7f890c18f95d26c101e58de195af", + "sha256:522b734e17eca7797235f297ff6a607137d2be92034778bb041ea061cd9cd9ba", + "sha256:746e3fb55c7e6eb9715e852a75cac5724e998778c09ad17e022b28eb76b1a741", + "sha256:78f244616536c1d2090c62acae7ac091ae38730377588c9bc21c5862a7fbab8d", + "sha256:817103ed97d7ba2f110d20e7ba449d631c61809f26bd0a12bcd2a37bffca2b00", + "sha256:8b3aa009a4216ad17fb0c7078da7fe06fdcaccc14ba0b29cf36e631740f71aa5", + "sha256:913cf6174f1e728299c841a5d7f622fedd6c72d6c597ea4266e1c96591c92d3e", + "sha256:c21036970e55a708003c78276857d36f864af2c209872c8e5047a167d37fd1f3", + "sha256:c2d4dfc638925a08aa9b32be2d9e51b6753736a69b2ed543c7d2f1c7189570ab", + "sha256:d27e31dabb47508a0458e7e6f1d3de154bb2b92d741d43ce8ee5961fe7e64f69", + "sha256:e2063938fdcb2536a61dcf4dc117be563c0ffa9accd438f8ad8abc163c509a1e", + "sha256:e29eba0690e325da53cf53e8e4481c4187a06d6b1b89de6edb05aabfec484e45", + "sha256:e44423983fff8ba08fced91f586f665813a700b2fdbd0d2f177271e41eaeb471", + "sha256:ed773cb7b6983d4bc69e9dd9a3437a070e08c07bd6312ff16a11e13c80c8a293", + "sha256:f283eb07866250943cf34c98c62b5780bdcdb144740857dd5210102fbf5dc75a", + "sha256:f44ac38904af17d5e327477076b47016e803072f1d01ccada4e1dd99c6b1be8d" + ], + "markers": "python_version >= '3.7'", + "version": "==0.3.0" + }, + "annotated-types": { + "hashes": [ + "sha256:13b2beaad985e05e2d6407ee4c4f35590b11f8d693a258a561055cac8f64cab7", + "sha256:f072f4d804ea359e4eaf198b1af7a8b0943881a87f31bb764f8bf219bb9419e0" + ], + "markers": "python_version >= '3.10'", + "version": "==0.8.0" + }, + "anyio": { + "hashes": [ + "sha256:9f505dda5ac9f0c8309b5e8bd445a8c2bf7246f3ce950121e45ea15bc41d1494", + "sha256:cfa139f3ed1a23ee8f88a145ddb5ac7605b8bbfd8592baacd7ce3d8bb4313c7f" + ], + "markers": "python_version >= '3.10'", + "version": "==4.14.2" + }, + "apscheduler": { + "hashes": [ + "sha256:bbeb2ec02d23d3c06a6c07ed7f0f3939ada6680eb121fae809a69bb42c537a30", + "sha256:cd2fcc9330039a81a5893472ad49facf23a6d5604cbe1d918c835c6de7834d5a" + ], + "markers": "python_version >= '3.8'", + "version": "==3.11.3" + }, + "attrs": { + "hashes": [ + "sha256:c647aa4a12dfbad9333ca4e71fe62ddc36f4e63b2d260a37a8b83d2f043ac309", + "sha256:d03ceb89cb322a8fd706d4fb91940737b6642aa36998fe130a9bc96c985eff32" + ], + "markers": "python_version >= '3.9'", + "version": "==26.1.0" + }, + "azure-common": { + "hashes": [ + "sha256:4ac0cd3214e36b6a1b6a442686722a5d8cc449603aa833f3f0f40bda836704a3", + "sha256:5c12d3dcf4ec20599ca6b0d3e09e86e146353d443e7fcc050c9a19c1f9df20ad" + ], + "version": "==1.1.28" + }, + "azure-core": { + "hashes": [ + "sha256:522b4011e8180b1a3dcd2024396a4e7fe9ac37fb8597db47163d230b5efe892d", + "sha256:f46ff5dfcd230f25cf1c19e8a34b8dc08a337b2503e268bb600a16c00db8ad5a" + ], + "markers": "python_version >= '3.10'", + "version": "==1.41.0" + }, + "azure-identity": { + "hashes": [ + "sha256:258ea6325537352440f71b35c3dffe9d240eae4a5126c1b7ce5efd5766bd9fd9", + "sha256:ea22ce6e6b0f429bc1b8d9212d5b9f9877bd4c82f1724bfa910760612c07a9a6" + ], + "markers": "python_version >= '3.8'", + "version": "==1.21.0" + }, + "azure-keyvault-keys": { + "hashes": [ + "sha256:210227e0061f641a79755f0e0bcbcf27bbfb4df630a933c43a99a29962283d0d", + "sha256:511206ae90aec1726a4d6ff5a92d754bd0c0f1e8751891368d30fb70b62955f1" + ], + "markers": "python_version >= '3.8'", + "version": "==4.10.0" + }, + "azure-mgmt-apimanagement": { + "hashes": [ + "sha256:0ab7fe17e70fe3154cd840ff47d19d7a4610217003eaa7c21acf3511a6e57999", + "sha256:b88c42a392333b60722fb86f15d092dfc19a8d67510dccd15c217381dff4e6ec" + ], + "markers": "python_version >= '3.8'", + "version": "==5.0.0" + }, + "azure-mgmt-applicationinsights": { + "hashes": [ + "sha256:15531390f12ce3d767cd3f1949af36aa39077c145c952fec4d80303c86ec7b6c", + "sha256:9e71f29b01e505a773501451d12fd6a10482cf4b13e9ac2bff72f5380496d979" + ], + "markers": "python_version >= '3.8'", + "version": "==4.1.0" + }, + "azure-mgmt-authorization": { + "hashes": [ + "sha256:69b85abc09ae64fc72975bd43431170d8c7eb5d166754b98aac5f3845de57dc4", + "sha256:d8feeb3842e6ddf1a370963ca4f61fb6edc124e8997b807dd025bc9b2379cd1a" + ], + "markers": "python_version >= '3.7'", + "version": "==4.0.0" + }, + "azure-mgmt-compute": { + "hashes": [ + "sha256:58cd01d025efa02870b84dbfb69834a3b23501a135658c03854d2434e8dfee1e", + "sha256:f8f7b1c5c187a26fae4d1f099adf93561244242f28899484d9a42747bf0d5af4" + ], + "markers": "python_version >= '3.8'", + "version": "==34.0.0" + }, + "azure-mgmt-containerregistry": { + "hashes": [ + "sha256:464abd4d3d9ecc0456ed8f63a6b9b93afc2e3e194f2d34f26a758afb67ad3b5c", + "sha256:f19f8faa7881deaf2b5015c0eb050a92e2380cd9d18dee33cdb5f27d44a06c03" + ], + "markers": "python_version >= '3.8'", + "version": "==12.0.0" + }, + "azure-mgmt-containerservice": { + "hashes": [ + "sha256:1faa1714e0100c6ee4cfb8d2eadb1c270b548a84b0070c74e9fe646056a5cb12", + "sha256:637a6cf8f06636c016ad151d76f9c7ba75bd05d4334b3dd7837eb8b517f30dbe" + ], + "markers": "python_version >= '3.8'", + "version": "==34.1.0" + }, + "azure-mgmt-core": { + "hashes": [ + "sha256:0460d11e85c408b71c727ee1981f74432bc641bb25dfcf1bb4e90a49e776dbc4", + "sha256:b26232af857b021e61d813d9f4ae530465255cb10b3dde945ad3743f7a58e79c" + ], + "markers": "python_version >= '3.9'", + "version": "==1.6.0" + }, + "azure-mgmt-cosmosdb": { + "hashes": [ + "sha256:b5072d319f11953d8f12e22459aded1912d5f27e442e1d8b49596a85005410a1", + "sha256:be735a554d16995c8cefe413e62119985f8fabae1cb45a6f6ad2c3958bed14da" + ], + "markers": "python_version >= '3.8'", + "version": "==9.7.0" + }, + "azure-mgmt-databricks": { + "hashes": [ + "sha256:0c29434a7339e74231bd171a6c08dcdf8153abaebd332658d7f66b8ea143fa17", + "sha256:70d11362dc2d17f5fb1db0cfe65c1af55b8f136f1a0db9a5b51e7acf760cf5b9" + ], + "markers": "python_version >= '3.7'", + "version": "==2.0.0" + }, + "azure-mgmt-keyvault": { + "hashes": [ + "sha256:34b92956aefbdd571cae5a03f7078e037d8087b2c00cfa6748835dc73abb5a30", + "sha256:a18a27a06551482d31f92bc43ac8b0846af02cd69511f80090865b4c5caa3c21" + ], + "markers": "python_version >= '3.8'", + "version": "==10.3.1" + }, + "azure-mgmt-loganalytics": { + "hashes": [ + "sha256:75ac1d47dd81179905c40765be8834643d8994acff31056ddc1863017f3faa02", + "sha256:da128a7e0291be7fa2063848df92a9180cf5c16d42adc09d2bc2efd711536bfb" + ], + "version": "==12.0.0" + }, + "azure-mgmt-monitor": { + "hashes": [ + "sha256:5ffbf500e499ab7912b1ba6d26cef26480d9ae411532019bb78d72562196e07b", + "sha256:fe4cf41e6680b74a228f81451dc5522656d599c6f343ecf702fc790fda9a357b" + ], + "markers": "python_version >= '3.7'", + "version": "==6.0.2" + }, + "azure-mgmt-network": { + "hashes": [ + "sha256:8c84bffb5ec75c6e0244e58ecf07c00d5fc421d616b0cb369c6fe585af33cf87", + "sha256:8ddb0e9ec8f10c9c152d60fc945908d113e4591f397ea3e40b92290ec2b01658" + ], + "markers": "python_version >= '3.8'", + "version": "==28.1.0" + }, + "azure-mgmt-postgresqlflexibleservers": { + "hashes": [ + "sha256:87ddb5a5e6d12c45769485d234cfe0322140e3a0a7636d0e61fb00ac544b5d20", + "sha256:9ede9d8ba63e9d2879cb74adc903c649af3bc5460a02787287b0cd18d754af14" + ], + "markers": "python_version >= '3.8'", + "version": "==1.1.0" + }, + "azure-mgmt-rdbms": { + "hashes": [ + "sha256:8eac17d1341a91d7ed914435941ba917b5ef1568acabc3e65653603966a7cc88", + "sha256:a87d401c876c84734cdd4888af551e4a1461b4b328d9816af60cb8ac5979f035" + ], + "markers": "python_version >= '3.6'", + "version": "==10.1.0" + }, + "azure-mgmt-recoveryservices": { + "hashes": [ + "sha256:21c58afdf4ae66806783e95f8cd17e3bec31be7178c48784db21f0b05de7fa66", + "sha256:7f2db98401708cf145322f50bc491caf7967bec4af3bf7b0984b9f07d3092687" + ], + "markers": "python_version >= '3.9'", + "version": "==3.1.0" + }, + "azure-mgmt-recoveryservicesbackup": { + "hashes": [ + "sha256:c0002858d0166b6a10189a1fd580a49c83dc31b111e98010a5b2ea0f767dfff1", + "sha256:c402b3e22a6c3879df56bc37e0063142c3352c5102599ff102d19824f1b32b29" + ], + "markers": "python_version >= '3.8'", + "version": "==9.2.0" + }, + "azure-mgmt-resource": { + "hashes": [ + "sha256:27b32cd223e2784269f5a0db3c282042886ee4072d79cedc638438ece7cd0df4", + "sha256:cf6b8995fcdd407ac9ff1dd474087129429a1d90dbb1ac77f97c19b96237b265" + ], + "markers": "python_version >= '3.9'", + "version": "==24.0.0" + }, + "azure-mgmt-search": { + "hashes": [ + "sha256:488ff81477e980e2b7abf0b857387c74ebbad419e6f6126044e3e6fad2da72b6", + "sha256:53bc6eeadb0974d21f120bb21bb5e6827df6d650e17347460fd83e2d68883599" + ], + "markers": "python_version >= '3.7'", + "version": "==9.1.0" + }, + "azure-mgmt-security": { + "hashes": [ + "sha256:5912eed7e9d3758fdca8d26e1dc26b41943dc4703208a1184266e2c252e1ad66", + "sha256:85a6d8b7a5cd74884a548ed53fed034449f54a9989edd64e9020c5837db96933" + ], + "markers": "python_version >= '3.8'", + "version": "==7.0.0" + }, + "azure-mgmt-sql": { + "hashes": [ + "sha256:129042cc011225e27aee6ef2697d585fa5722e5d1aeb0038af6ad2451a285457", + "sha256:1d1dd940d4d41be4ee319aad626341251572a5bf4a2addec71779432d9a1381f" + ], + "version": "==3.0.1" + }, + "azure-mgmt-storage": { + "hashes": [ + "sha256:25aaa5ae8c40c30e2f91f8aae6f52906b0557e947d5c1b9817d4ff9decc11340", + "sha256:a4a4064918dcfa4f1cbebada5bf064935d66f2a3647a2f46a1f1c9348736f5d9" + ], + "markers": "python_version >= '3.8'", + "version": "==22.1.1" + }, + "azure-mgmt-subscription": { + "hashes": [ + "sha256:38d4574a8d47fa17e3587d756e296cb63b82ad8fb21cd8543bcee443a502bf48", + "sha256:4e255b4ce9b924357bb8c5009b3c88a2014d3203b2495e2256fa027bf84e800e" + ], + "markers": "python_version >= '3.7'", + "version": "==3.1.1" + }, + "azure-mgmt-web": { + "hashes": [ + "sha256:0536aac05bfc673b56ed930f2966b77856e84df675d376e782a7af6bb92449af", + "sha256:c8d9c042c09db7aacb20270a9effed4d4e651e365af32d80897b84dc7bf35098" + ], + "markers": "python_version >= '3.8'", + "version": "==8.0.0" + }, + "azure-monitor-query": { + "hashes": [ + "sha256:7b05f2fcac4fb67fc9f77a7d4c5d98a0f3099fb73b57c69ec1b080773994671b", + "sha256:8f52d581271d785e12f49cd5aaa144b8910fb843db2373855a7ef94c7fc462ea" + ], + "markers": "python_version >= '3.9'", + "version": "==2.0.0" + }, + "azure-storage-blob": { + "hashes": [ + "sha256:052b2a1ea41725ba12e2f4f17be85a54df1129e13ea0321f5a2fcc851cbf47d4", + "sha256:77fb823fdbac7f3c11f7d86a5892e2f85e161e8440a7489babe2195bf248f09e" + ], + "markers": "python_version >= '3.8'", + "version": "==12.24.1" + }, + "blinker": { + "hashes": [ + "sha256:b4ce2265a7abece45e7cc896e98dbebe6cead56bcf805a3d23136d145f5445bf", + "sha256:ba0efaa9080b619ff2f3459d1d500c57bddea4a6b424b60a91141db6fd2f08bc" + ], + "markers": "python_version >= '3.9'", + "version": "==1.9.0" + }, + "boto3": { + "hashes": [ + "sha256:6b9c57b2a922b5d8c17766e29ed792586a818098efe84def27c8f582b33f898c", + "sha256:d6c56277251adf6c2bdd25249feae625abe4966831676689ff23b4694dea5b12" + ], + "index": "pypi", + "markers": "python_version >= '3.9'", + "version": "==1.40.61" + }, + "botocore": { + "hashes": [ + "sha256:17ebae412692fd4824f99cde0f08d50126dc97954008e5ba2b522eb049238aa7", + "sha256:a2487ad69b090f9cccd64cf07c7021cd80ee9c0655ad974f87045b02f3ef52cd" + ], + "markers": "python_version >= '3.9'", + "version": "==1.40.61" + }, + "certifi": { + "hashes": [ + "sha256:62f22742b58a1a33014a2b6b706588a8d7e2a88ae7bd1a6ebe8c992928483775", + "sha256:741e2c3b351ddf169a738da9f2c048608ff7f2c5cc02f1ebc6b118bb090d5d55" + ], + "markers": "python_version >= '3.7'", + "version": "==2026.7.22" + }, + "cffi": { + "hashes": [ + "sha256:046bfc24911b37851ee1b51aab8bffe713d89c68c6a057b09484ce9fd5f69b4e", + "sha256:06c72bb76605a4b0cd0aad6930b69d4baf7dd5d806cfc409b824191099700e66", + "sha256:0beceaabe56af686895136a2de78db54ecd8e4046b236b8fd6d6cb61389e9bf2", + "sha256:154852545011f779917b11c78db2358d095da62a9a172b78ad0a583ee5adc0d0", + "sha256:194cffa889098ced9976c3fc6340305e43f6303657d298da55366907c05c22d6", + "sha256:19ee6127ee34de7d83ce3d371ebc5ed91addbdcc39f9ab15ce4eb35a4e534971", + "sha256:1a18a57b58cfb21fc28d72e876acf10eaed67a1ed96226f92af4df681d571c4c", + "sha256:1aa5645c30469b09530c4ebca77ebf8f17618293c58f8549cb1a543a50236e7d", + "sha256:1dea0e4d7d4f11f619fe8c1d76caf49e24405b4b5743c0e3be16a500ecd930c9", + "sha256:208f941bb9d18e768138677f0a6d2ce01f590df56043dda1df1535ac57c88517", + "sha256:210019b6c7cf07f081b4c54635c8cf744377001350e29cc0f81c4377b4797735", + "sha256:246fa40ce8645a614ff682e0b70f37134e460eaf93a775e0cbe3cca585a67a80", + "sha256:25792eac27877609e7bb06d42ff88278a6624fff2ba9bbb523c09616b117e80f", + "sha256:27350daa11d4f10c540e6e89dada4c54feb7256ad03e9a4dc075ebad7ba360d1", + "sha256:28907ab9bfb6aa13184cfc17c6b8e1023c5ab6fd7076d8c20a35e59fe04f8f29", + "sha256:2ae64be792b8966f2c69538199728b290e34726562896df1e5dc8ffd8d8188e8", + "sha256:31348097ff5bbe827ccc41795d4dd099d9f0625e7def00ee653c137a490c2a6c", + "sha256:3143d81e29e1e20a9ce10901ec369012947876596f75a222235965f2b7ae832e", + "sha256:3222ba5d678f80a030e6afbcc33dc1ae5cb45facabb61cee2c7016b8432fde48", + "sha256:3311ed60d36f83378794e1009ac6258bafbf81f7888b4caa7b35a521e3f95813", + "sha256:334644fbac4eff73d985a17a91226df55d0f394160c4cfb880e084c8f7161cac", + "sha256:34e261f78cb6ceaaa36f42f2613f4380d94d9c759a9c73c769ee6e0247364632", + "sha256:363e05fa78e15116c3c32c210ee36884fd6b9afa6d440e47112c3bd511d64cb6", + "sha256:398aff33cee2767e3e781d2554c54bd0dff386bb437581e0d8011fde1a942ec1", + "sha256:3d22a20b1fb1632cc72c22f95f7b0d2961c3e1c235f245ba4c606c4771035659", + "sha256:42a494cee34437f05546455144f2b5d9ac09b1face62bcfce597d2e521066688", + "sha256:42e2f76b9455f5a9a844f770bf3e200ed3da0e15f5df3db9c31fe80b04b3d004", + "sha256:42f6930c31dc7f50732c9ae793c2786c7b6b044195967bbdde40bb9be81c4cc0", + "sha256:456a61fa52d579ebf9df2e9552ead5129855dbaff6c1e5a9b1bc408809bdc062", + "sha256:471cee653ae88de62096552e6d24ccb4a5adb8c8c9f10b5054d0122c15bf2779", + "sha256:49cbc70e6542d4ccccb936558d1064a8012541e78f821f955cff24e357776c94", + "sha256:4a7c934f7360e8cd64fe9efadcbd10c7c6364f531e432b9a4bf5ccbc9e0e8b50", + "sha256:4be96343e422f2dfcd12ab5c9f5aebe03f82f737c6bffeca6830b3875cb44aab", + "sha256:4f42141fc14250de6dde5ee7ea4432be017252d91f19c5ad043c084cea629cac", + "sha256:507a24c282e0f42f8ed737cf048572cbf580468da5555764a8331735e9c736b6", + "sha256:51b31d1c98274844cfd7838ce00bfc27c7423a4dc00fc0772fc3331c2cc90676", + "sha256:58acb8ab8e295e6c5ea12f888cbb13cf21511ef2a3303a23f4325c29d17fe5c1", + "sha256:5a59cc1c4442bc3d5c703bf720b51138d0bfc173618807c9ee2490a7541dd3d9", + "sha256:5bb4e7ea95dcd6a014a6fef62e62467d67d8e582326443f3d68e71d6320a9fcf", + "sha256:5c58fe613dc5e5336357eff555824a314d8e43282600435c8d1cb6a7a2fedd13", + "sha256:5e7cecbaadb83884793e05828cee59b210b24583b9c7425d0ba6a754fe22eb4e", + "sha256:616f097f2fe415bc92a247f02e11f634e1f9e9a83d327e3c915c15089c87869e", + "sha256:63bbfd5ded17c4840ac07cd8f1c21ba9d9708141f840b324f422f41b207e3973", + "sha256:64faea20f4e2613363a1a9b9c7dd73058f3ecd00133a511e72ad7c511658f527", + "sha256:661c298b4821edebead0c91edd2b00374d67ad7c5a1f7a91d4442633b79d6a72", + "sha256:68e62fe11f30d5ca8289242866f0a5291402d8529ca2178ab8afc5c9694ae890", + "sha256:6a8dddef476fab96d066d578fc88526767b836ab5ab21754e1d5bf3879c31c7c", + "sha256:6e192623c49c94421616a5778fba35cf0d5a8d000650c1967ef4448ee5cdd990", + "sha256:7225e4514edb64eb6740324353e0da0711954fd8d7da4576755b1c6e09b697cd", + "sha256:75f80557d1389eddbd0de2681f6a390a0c5338c31ddaa821381c203fc3fd50d9", + "sha256:770de9db11e84213beec501cfcaa013b019820ca881e03344dea5844f7876d94", + "sha256:7750c6449dff7864bb9bb27ddfb0267756189201a3afc911d82b3caacd70dfc3", + "sha256:7bde5e4cc5c10140859842b9d383af292b22639a4dffb725314baf45968cef80", + "sha256:7ce713ace7c0e4520535b42b77eaa742c16dab813978064913e5a3cf82973b41", + "sha256:7da0c5eff80f0197f3b3d1232ec5a682a9325f4ae9016a78f5f5ca35f9ced1f5", + "sha256:7dbb61fe3a7699468030f71bbe5f8a0e326a151daa91beb11a6fc1f980c55e1c", + "sha256:811bd1e21d32de12efca32393a0ab3f5133b54fce9bd44b8bd77ab07da14bf6a", + "sha256:8ef53b2de9bcb9197d31854256575d59dbac0cba72ac627bb291ef5eceb74be4", + "sha256:937c0052c05a31ca1daf18de3158eed4dbfcb9cc107adbea227728d647be701e", + "sha256:9d2055050ea716bd38b7f7f1579c275386646b4894c155a3e2f3cd62ed41b7c6", + "sha256:9f8d177621de5cb38ee3e731eda45d421db093ec0739f46a5594babda7987a98", + "sha256:a2d7755bef5a12ed488f4ef1f1b69ee9191d7396083b755a5d2295f6edb4768b", + "sha256:a48d62ab9d6f4f98c983223a547af44be6ca3691074c31cecced6facd3ba2dc1", + "sha256:a4f00aa42f75d6e4595e8866e748cc1705adc0cddfeb2ca86d0d03993d63ba03", + "sha256:a6e721d4b0e45d5b65e87534470e67b18dcd092c83f68fba09f152b9cbc061af", + "sha256:a730a083190634c65cca36ba5f489531576ebd79bcd5c8e172130f6453127231", + "sha256:a931079504ecc49efed7744c476a5c343a92fabf66dec2db95edb1b2fdc770e2", + "sha256:aa9511c62d14da7aacc9b4bf51f3f697a621e83b2d6919008243c3aad168eea3", + "sha256:ab36d55f9ed2d067327667c2fea18dda018eb628dd6347aa01dda6cf1f5d3836", + "sha256:ad2c86c495b899d862ea0f4b42891b8713a3bd45dd4105c7fd51c2a72f39f3a5", + "sha256:aeae0e330c9f6acd681f647d46cefd30c29f93e3392882e792e82080c9691399", + "sha256:b0431303acaea1089ad4b3e9ce4e6518193def1118d4073ca848635ee4ea2e96", + "sha256:b5bdfd1c873d4e093aabc0ca84c4ca6dbc4f752afb5c86f146d9742580c9da2e", + "sha256:baed1e86cc735622097354b9d1281406caf42ff42a886d29faa8e8d1630333be", + "sha256:c1453022f490d2459a11819d83ad1d586e9ff65a12ac3e705ffebd46d3685dcf", + "sha256:c26608d2222fb1e94487e4a387d85f13eb55d5ed725cb25a0c589ac4ee60e7bc", + "sha256:c7659f22557c5a0bc4855cd635f55edec690cc008a40768527762cb9fb263455", + "sha256:c8c69575568085ba0b1b10c0249d779a214aea6f6522e949a0fc9fb0fcb449d0", + "sha256:c8d2c9fd1f2d16f780d15127abb050d13d1a76c03a4bd87d7e4980e45e511e12", + "sha256:ca82be1a1d406ecfe1d25dc16cb33488e5a16bf4438c9fb590484ea29d92478b", + "sha256:cc572dace3f60ef98d7b12ff411d20f5362feb31a0439eab0085bbfd349982d7", + "sha256:d18e5ac0f2f03f4f518d3e23db0f0cad7faa1da8620e9c09461d443bbf6e6692", + "sha256:d28630f5854ab07ab1fd4aba756de52326c82e6be15d414b12793f1975048b54", + "sha256:d9c275eaacd24aa73f94ffd6de08fc3f932424d8b6c376f4bed7cde376fe7bc3", + "sha256:da0e573f9f97159390c89d9f1a9e41908b66d408cc5b58d08cf3847d844c531b", + "sha256:dd31f52ea1086513bb9df30f8fcee9b8918323ae067a3d5b78bc826a000712be", + "sha256:dddad92b554513a31f272570678ba307fb9f618f05e3d4a5eacafff9eae03e1d", + "sha256:df423d40ee8654634421812bc3b196da3f9bd7d32929da813f8394c4348a5358", + "sha256:df913725b79db7bcf03448f36b7bf8815363417d5b58deecf9305e3e30f0f21a", + "sha256:e0bcb7e0f677f543555d2adff3bf19c05f66cdb4796e5ff602442ab2fe3c4ef7", + "sha256:e2d65b31f36619cda3999b78b2aa9632e76b78448e7a56fc4240824200e7c4fc", + "sha256:e6e8cff14d6fb0be70a09c0bdc58096f501952d04624ebf867e0e56da2df8960", + "sha256:f16c709686a78c727bbbf059f92b0bf41c6fc60deec706d2dc19f529175a6125", + "sha256:f24fb43132a4c6b4cb4eb029492919b2db645be6808d738f244fd146c03c32cb", + "sha256:f53e442b08449d42821fa4a4fba000095af9f62742a500f978a9f557ec44339a", + "sha256:f5cfbc5fe74540d335175b656c725d74d90e3730c626d92575eea35029d9afaa", + "sha256:f81b3b8f3d4e343550fa4baa0e479bba9f2d29ce9c2e9b51d1ce1718d7442fcf", + "sha256:f8ec5e643a9a937f64e1999eb9f75d072263751912dc5cd06d3c85f8f44be7c3", + "sha256:fb92203a88b3d3053034db775110081c49d28be6551923805e039924093761e4", + "sha256:fcd22650c908d7b7da162bbfaab594a1227a15d1643a98c68b122ac642fa2264" + ], + "markers": "python_version >= '3.10'", + "version": "==2.1.1" + }, + "charset-normalizer": { + "hashes": [ + "sha256:00668ebb0609751758682eb0b5857e7c35b9f00e84dfdef062e103244ec94d45", + "sha256:012a22b88a77ca2e59b98ac5889b0deb604147666032f45e6d6e217634d2550d", + "sha256:01e93745f7f219b703b60ba7afead36cfc4242782be5af484673fc500df12da5", + "sha256:04368edf83514385ffc3e1cfd4546e595f4f1272dd23ba437a93a9cc3741d47b", + "sha256:0722590aabf9dc6a6c0343d523c05458fa2b5047dbe6302fd526bb570600753f", + "sha256:07ffd07412fc5d5e84cd8952acf9ff7e4ed7a708e69d1bada19d8ba91711353f", + "sha256:09a7bba9f739468c8e78c36a75c33768e53cb1959fc638f510454c14683f00d5", + "sha256:0b2b1b3fa5670c127b246df1d0c059defd41f689a868a3b9d79df9b1cac42d22", + "sha256:0c6dfb5ca6723eeed15aa8e564a014d69fcb8812f94eef11fe3631e0508199f5", + "sha256:0d929fc574b4d6fd9e7c0f5c2ede8716a41911923aa7fa5fce38e0818aa4a1ac", + "sha256:13e3afe97712e8887cd516e960c63f0b93122971e5b5e4b2622fe7701771e838", + "sha256:15f024313246a4ed976c60f440bb8d257815513a681d212ff74fd46f7d715a90", + "sha256:195ce897c6153c0700078142cf8efe3e6454ca4cf4357499e4078dfd83396626", + "sha256:19a3dd5aa73cef1c99687c4fc57db016a9c17104ae1185da88ba566a5d3bebe4", + "sha256:1d1c7a53a6c2103925cdd6d7229f8c567379f211c869793df679f2e9f738c369", + "sha256:1f5883d77fd409a261abb5dc8ccbe335720d798b1de4abb3b1d47ccbbc76b53b", + "sha256:21b82d8082f6f5e7f456ef0bd16323d08de1266efbfeb476e64b2a91d1471a4e", + "sha256:252d099029bcbea642f2a06c4ed5046bdf8b5a8150b64afa5e027e88b106e5ee", + "sha256:256dd4d85d9e4dc595e2bc983c980e73f62ddeb3165c58b4c3dfe78c5c8548c1", + "sha256:26422d45fd13551cf564c58932f7d72b4f58b93b0fcf18c35ba6be12b46bb102", + "sha256:2679de311c7946dde5d3b6f44941844133ff5c7cb86099c0061ab1e8901c20a8", + "sha256:29880d17a8eb0b5cfdfd8944b468322928059aa35f1f5fa8ff22b149ec0b42f8", + "sha256:2bced4061f000f7187254a02ad3433ae17eaf991747ceea2f478422590a5bba9", + "sha256:2e9cf9253119d8e5d111f05d71626786fd3d6193817316eab1ca088cdb8593cf", + "sha256:2f06b7eae9dbe77fe1d644ca244dad508de8d302870a43f3c559b521270938a0", + "sha256:2f293479cce755c75f1697e87c409b7ae4c555c7dfecb6e988ad13abba943031", + "sha256:329fc3ccb63ad22d867d84c2adea759a64079a37ba4a343433b02c7a2816871e", + "sha256:343fb4f2821043bd87095f7b08a1a181febc8e36ac64212143bbfd0a0e1bc235", + "sha256:3588e376b3ea2eea84976f67273d679f229e24c66dce7b82ae45aef04ff6e072", + "sha256:35aea775dc2bd5f54cd84a1cd2696cc3207c479cb9cf0bd346f0d343e4300ddb", + "sha256:35fe081843b35aad20ffeccec3eeffbe637b15d14f3fb22cc1b59cd8ec17e93c", + "sha256:36047af20e17097c3bb9476c2b7655f2f7aa51322c0ba58c07695bedf755a950", + "sha256:3617ac3cfd8b9888f145ad89dd6e692285834b0201c6074a5eeaad3fd4d668c2", + "sha256:366ec70f5547c640d3ce1985722490f23faf4eb5216a7eeba78277490e78dacb", + "sha256:394fea06235c8543390050ed5f529187074b029fb027213f6c46ac11ab5d950e", + "sha256:3d27167433c0d5f18dc850f07d0b3816221984fecdc405d6c157a6f0b8f8e9e6", + "sha256:3e5e1224c0a6a90e05843e07adfec669edebec17801c67072f51e59561d63c0b", + "sha256:41876ee62a3dddf48ff1121ad8f0798032aa03f2fd35f21f34a4cab14f18d8d2", + "sha256:433c5a81eade63b47e522303bad236f59dba55ea6951746f5558355eeed8c75d", + "sha256:4582c27e8c889d64811987b5967fbd3ae0c823fe1fd933b543d55ac20bb475fa", + "sha256:485a0d363cafefcd2538a73c7c838daa2035f09b2c9f9b5e3133f80c6aeb84c2", + "sha256:494b70049a4d69aec6e8137c13af4cf8db8c9f9820a1392ac293b0dd2987a818", + "sha256:496846868fea80e479324862fa877f02411f2fd0f83b79ccee2607aa68b2a032", + "sha256:4abdc5f9ad448c1ecbfae2974b820535d6bc6e7eef63babbab3d81cf46968c71", + "sha256:4b599739b93b2cbeded49645ae3c8d1405c29ddfbceac1545c87a3f9580a9e96", + "sha256:4bea7f8ebe90bbd7f0e4a2de42ca6924ba23e3e76418c408ff82f1d46fabd687", + "sha256:4c4fb141a727957c93edfe5c32a26ceb6b5f6461d67146e2d39f51e16170bea8", + "sha256:4c9548dc78002099910abaebc0a72ac58b7d30931869e0351c09b507dff4ece3", + "sha256:4d26f14f041e83dd8edfd61f4cd4fa7285d31798b5bf1f28e70c367ba6c41d61", + "sha256:4f298bdadb8f0b9e5672877f647d1be9373ef5320c9e2f049795e26cad28b6a9", + "sha256:52ec005752a56ae79547a05c0139ca2501a0c866390b6115008456b9f0e7cde1", + "sha256:55261ac0d2941c42f196dd576f543d87a8ee03cd6f5e30dfb4d807b2e3b9121a", + "sha256:56490c595a28b1bb27dfc583e816152a9767721ef58b2c03b13f954d2f707420", + "sha256:58d3e12c88e0950bca850ae1f7c256055c097639c2edb9eb123af9807d8b15e4", + "sha256:58d4aa13a59c969dbfdf9e6a9560e242cbfd9e8a8f50c2747714df1a423adf65", + "sha256:59171c6e45bf07d0d5cab3b0bf81d945035530f6873398b3b531c31184d46663", + "sha256:5b6d1386bf0096d26d3a863dc0a487a5b4eb9aa93cf5ba69683d29dde6b9d60f", + "sha256:5c0ea61a470e070686aa30892fed79e297d2c8d0ab46b8bcdf027d38c51da591", + "sha256:5c84bec0ab5ae0c64bfe73a7d2adcb5ce73b467523fc27fd6a28ab2aa6cbe35a", + "sha256:5ca0555312ae2fe82715cada7fac375530c2f3349e1eaa1bcb33d0283ac79a18", + "sha256:5d8531a6569d025f68e2321e7638fb7978f23db58e5f69f56913837aae03816e", + "sha256:5e2d0e146dcb57034f8b97dc58d2d512cb90aba253960ce449f695fec6a82c6f", + "sha256:5fc45d653ea8c9a20479167e11d4a0f8cb2fa3470737ab6f9c827532313187b7", + "sha256:6117b84ea48435e5356dc737f5121485c30920ba43375fa7b434fd753df0eac3", + "sha256:6199d5606e2bbf2b096cf64d03f8b6790c91081d5ac866b8e7bb6422738cc60c", + "sha256:62b55f6722735a6c472f88361cde6640608773d9443cebdbb51abf436a1fcdd3", + "sha256:687c9ca3035544b113bea2055e180af96fb63c0c476e22a9180f51925186e7b7", + "sha256:6b7430cf5728e68f6c462254009a6ef4086e1bea43cf2f57aa9c55fb4f50ff96", + "sha256:6ba32c4d2abf1d2fe7cf27d280f4cca5664233b0f885549c7761719eb977f486", + "sha256:6c9cdde8becb25a7fde49924511aa2644d6f8081cc8df8e9452724303348d8e3", + "sha256:6df0ec430f9a831772c23ca5a224cba36517a58a84bb32c32bb59a9fa67c47f6", + "sha256:6e2912d4babbc65196ac13c2f53468dc57fb8b9c25ef913e8c59ddf7c6dc0e1b", + "sha256:6e5e4d73d588ca5ed09df1b7dcd1b203d1df3c542e3f50d126c947d432b10731", + "sha256:70055ff39b97c99e7ae40ea3e393fb62aa2e44dbd9b29f8d14f42fb0025c3959", + "sha256:706bfd38730a5ac7a365793269a00f4e988178cec121391f4248d84ad8c972e9", + "sha256:7235dc28fc6dd9d832ac7c7bce95367dedb85929f17368a0c2bee1e080b9acbf", + "sha256:774d157f112367ff4abd29019f38f023c24e00e56edc7829c20e358a5a913ad8", + "sha256:77efcff2b23071c349402ac1066667a3d011f62398d81408c9b88ad991747c9e", + "sha256:789b8982559ae28dad2356519f841655756cdcd96616410590ae0b17454ee64f", + "sha256:7ac76cf9afd34929d76eb7fcb63be476a4853d8a96f0dcf2d0db68a0cbdf9885", + "sha256:7c0c10730342b0c9b35dd1d619beb8214e520bd96a1f870f452680b238aab3e0", + "sha256:823f82903d189af463d7df250ef1f7f696f3cee08cc8d91deb565e8d425f6506", + "sha256:838648accb3a7fd9803fd45c87bce8509648eb0c11bc34e216141300977244f2", + "sha256:854066be00447fa8de2ccbbe893e2ffc4b123ef16d897af794c1e18bd4a714b0", + "sha256:85d5855daafc240cc045c026d7a15fd198a09b0fc8ff6f5ecbb5297b509cb11e", + "sha256:85de3134b5379856e323ba37c19c9256d39425f7b76a63af52b09fb4664c2e8f", + "sha256:87e4f41d375c0b9be2fb5251aee4b8a689169e134535aed81bf085c3b647451e", + "sha256:88ca277405c2d3b71c4e1c2ee0e7966e807bcba86a69d11e19ba199d18ae4491", + "sha256:88e85ab89cb822c1e635f51d6d32e488f94e002e70e2f492bdb8b945543f345a", + "sha256:8ac8c94b6539074e0f40899301273ac8402b9b3e01c7b7ba269ff30340aaaf20", + "sha256:8fe532b3c966d1fb794e0698e4589d0444017ae77fc0b31edea13c0e35bcc449", + "sha256:9085f87b0e38a2b92b8923059b4e8789fe40d9279712d15dcc670048d77079af", + "sha256:90b7481fb62fbe172c558bc6fd1c4c98d82004a54a7551f20e11ac9bf0b8708c", + "sha256:92caef967d287a407085d61176fce4012b1dd62daed4eb6d5ceb26d3d2538712", + "sha256:9362dd90aa7dab48c0054a21187791ccf05473f7dba5d92b8033ae62164675e7", + "sha256:94d78ecec2605a8d0398b0f365d5f12a63248438516f5dac536a5eff7337df4a", + "sha256:94fbf1c0c6cc0d3d5e50f9a9313a8cdca90dd696d34b381cd1704f8c9e939f20", + "sha256:950f23cb393f85543777b0433f082cddd25b51ab398eac7971146495679efe5f", + "sha256:96eefc178f8636b9c760c5829345307fd81cfae9ab1e80997dbddeb0f54ee9a3", + "sha256:96fef3e886d6a9874b14f27fc193fbdc69d5d8035783d86aa4e1cea594e695f9", + "sha256:977cdbd483a9cff38179bea4fd754289a6f2195c7abd414aba85410b3e66cc5e", + "sha256:978eab16f55b4ab2c2a745be9a0a840bf8f09a7f227d9c76eb30214d078865a5", + "sha256:994e883d17c559cdfd38c84003c8b27d25424a1077272a17e7cd27bfe0bf57b2", + "sha256:9ac4444d8d4fd4c4bd08bf451ed3167aa9e7ec6cdb41b648794f1d1103652e36", + "sha256:9b5db6052055d34d41230fb78d7c439c23dc536a9896f6cb039e8dd92cfc1263", + "sha256:9d9a0dc7cbe9bec24c3f767c9122c41fe5a1bc43f47cd099d00d393e09769de4", + "sha256:9dbdd9205662134957cf0c324f639bdc5031c0ca056e2369e238db75187c0f11", + "sha256:9eea3ab2597a5e65fe65296e2d6a84570845a6b55532d90333d740d48bbc850a", + "sha256:a2028475ba855475b8b4d3cfeb4994269c967aea8b9892dfba907f4263a863a3", + "sha256:a3a370082ce34d0612f421e15fe011c53bb1feff21a26d06ad4fb244dab5a375", + "sha256:a545775cfe815855ea32d7c27731d79da358ef2055b4a25830231b1622dd18aa", + "sha256:a5cbd90ecf0fc62e64726917ad083b73001f0563657a87ec3c0b504e277dc90d", + "sha256:a6d095662e73e74f0a49988e0593373e243e3a52e27bfeea0a859e88acf4a0f5", + "sha256:a6dac12ff6b846103483683f60c5f8fee205121adc58ffd87e90a90a3af69e99", + "sha256:a951ad59cad9145664a730d3036b40b844e74d2d3683da40111463cd3a83845d", + "sha256:aa1099b956fb795e686d073568f6dc002a0bb89765ea6d5b055dd7d9bf1b116c", + "sha256:aa2bb0b37202dca27175591f761108b5d34096ade1191ffe4808bdf6b1571488", + "sha256:aae2ee51122d3ae968a3837d97dc24a0aeebb0dea23694422cd172bd30017cd6", + "sha256:ab743e9bc90c1f73552ec33e10e3331315acd2c397b36065b591b0181de533cc", + "sha256:ac00177c4831ffa650f8609e4bdddd5fe09c03b1c0c47acece7e6ea20421598b", + "sha256:ac13b004224fb341e1e25a1ed5e19d32f57cdb2a403e01f003b46f051a550f6f", + "sha256:acaf604462bf330b0d07e7a07c1d6e4adac79e5fb13e9c5140590542cafacc00", + "sha256:ae31a1a1db2ee6cc2942fccaf695c934bc7f3db9f2133a3fef1f367cf1a4ab10", + "sha256:ae4a097991662cd4fff0ddc74e0fe7874f82e00042fa0ea00855645ed0c79598", + "sha256:aea996a6aba25260827c9ea511d1addfde2da9eb686ac961838509086188b7e6", + "sha256:b39b69b347e5e47a3b5b8cfc005c68c1ba347474e3960236c4944a8ecd174962", + "sha256:b54e7e13267d49ffbfe68e25b3cbd774dab38fa37238f71265e91b36146eb21c", + "sha256:b9af956078716df40d985fb0dfeb2c2120c5ca92ba4ff4b388acfd01cdc14d08", + "sha256:ba2f37ee79e6338845261a3c5b1784e5d1acdff2c0785b284f1b633033d136ab", + "sha256:ba501e667c17d8411f98e67a022d9604ef179aff0e459b7e292c796837c13573", + "sha256:baf3775a2635e5a11fbd5e4e64ee69c7e86875d224a5c72aca4c141064589a90", + "sha256:bb57753e36e4855b8ca375069482250a6246372331a3e4f3407eaebb007443f5", + "sha256:bd6c173f04743d483881bffa1478d5a4624475b8cd1d2194956a75548e191c18", + "sha256:be47f99644b208bff7766314013f9acf57b056b04191d570d68ad14022cf5b1d", + "sha256:c010f5581d9c612804cc59fcf7b524b707fbcb72828551237ab545bb5c7034af", + "sha256:c1dcc36dcb96abc02236e182d17e0f71430152a6c2c7447421da2d2dc144edea", + "sha256:c428c6c31eb5f4277d7f8eccaf767fbd548ddd5ce3c8b4f4cbbfab3d96b5904c", + "sha256:c658c50ac0c98cd755a2dd50b7977d3bca7df401dcc47fbdfa87db53ef7d4e8b", + "sha256:c71fb0d56c920c269cd3e2e3fe7c610e3f1fdb21a6ce60efa6430ff63676cea6", + "sha256:c7b742bf31c88566b4bb6335a7f393bb322e580b6bb98df7bd0c25e6e3519ce8", + "sha256:cc0329df4caaceb950d2f580b5ac716a377f7059624a0bafaeaf8a218c6ed774", + "sha256:cc5d36d96478aa9c60654bd932525bf32964c62a7281eafdf16d85003a8d6004", + "sha256:ce854f5f478050ade5a238731c4ca985a7d3b3cb53ff600a9b5c3b689b5f0a7a", + "sha256:ced3fdd71aaa83ce593746c2edb42b7a59cb4c19c8b5c407781c72e493aae55a", + "sha256:cee5dd7c6fb5dd52a0fe2a740f9bc6e3593f5f8b1788bde49de02086f30182b2", + "sha256:cfa1c0cc3a8f9f53f1243a5a99ac36fd003880199383b37672e86ddda9cb07e2", + "sha256:d1ee1e296209fdce05b81b663250eefa02213a2da7b41bf26f7829b8ba3545aa", + "sha256:d59b75732e9b6f27388e10c14b0259cc5f2e48c78627d185e6a177b58ad3cffe", + "sha256:d63600d620ad0064c3a748b950ac5ea38a80190e5498532efefa4b7b3f1da1f3", + "sha256:dd732602a7009217f658d5863d12d79d373a4de0eebc111094bcdd3bb8e0a6cc", + "sha256:e06efa066f7dbadbc84ebc126a97c452a6451dfcf589d89d788484949e1cf795", + "sha256:e199fb99720074809a7720f1c0b4d919eea8b87e88713e0f8f602f7bef543d9d", + "sha256:e4b018dc5a0eee4676e38fe84a47a427816c590b93b55d9025274ec4d6ffc2dc", + "sha256:e6621fb2a4988d6e53eedc455e5903e2679f3967b8acb3d639f1b63c14a2e893", + "sha256:e71c909f353863b2b89c83de2ebed71ea6d0df8a6ef65a128193c5e650766bef", + "sha256:e90251c0c7bdd54a100a0dce3c07b7e637278c93af29dbf78ebb89a58c4bac7d", + "sha256:e9fbdce1e47394b09bc9f26ab117dfc8d6491977a11d86f592bb42c779db2fda", + "sha256:eb12fb2ba69ffa05f8695f61c69e591dc4b4a12ac3757ac8af8adb259bf56d17", + "sha256:eda059b6bc8bc0812d626fd91a7ce01bf583df0a61296eff390fd94141a34e30", + "sha256:f03ac127268b43ef4fe9e6ab6794a6794b49485a0cc0c1db79876d2f33f75bc7", + "sha256:f298e218441525d3794428b4c8b8fb8662c6d3ea79925d4807ee6b9a96a3bca5", + "sha256:f5542f9b941279d82d41eb0aa9f98eba36fe4df5c7086c651df7944935b37182", + "sha256:f6f7deae3feb4edfa2efaf7c574fe88cbf055038a6abdb40188e4fff66d5699f", + "sha256:f9b1e28d0e8dbfa858abdba91d6b547beaf2df1a59bec6da6faae7b96a4991a9", + "sha256:f9f8405c2c758532c74fed975dbee57be1f31a6e865c031870c79a6ed3212ada", + "sha256:fa48b1b63d639f9483e0633e092f5851e2348c352f1f9bb6c8182f87884ef876", + "sha256:fb78f6e7fcd8ad785d28cd577168bc1aaee827b25bb8755638f694794ea98f0a", + "sha256:fbc597639158fd7c14d55e808718848319540f51b0e6746e3eefa59723a4a348", + "sha256:fce8cbd4997efeb450bd298b54f755dcdff18d496f7a5ddbb4867c6d7c88fdc3", + "sha256:fd0350afdc3aabd5576f60ea109228bd5538139713c7b094c5cd27c73a98bc6f", + "sha256:fd0a274c0e5f9a21565cd9d3dd749b61f96b7aa1e20a93aa1ba4029518f2e5c0", + "sha256:fdb8a068947befafba9952162645dc2fecaeb400e64584829ed5e9b2fbe21a7f" + ], + "markers": "python_version >= '3.7'", + "version": "==3.5.1" + }, + "circuitbreaker": { + "hashes": [ + "sha256:1a4baee510f7bea3c91b194dcce7c07805fe96c4423ed5594b75af438531d084", + "sha256:87ba6a3ed03fdc7032bc175561c2b04d52ade9d5faf94ca2b035fbdc5e6b1dd1" + ], + "markers": "python_version >= '3.7'", + "version": "==2.1.3" + }, + "click": { + "hashes": [ + "sha256:9a6cea6e60b17ebe0a44c5cc636d94f09bd66142c1cd7d8b4cd731c4917a15f6", + "sha256:e6f9f66136c816745b9d65817da91d61d957fb16e02e4dcd0552553c5a197b76" + ], + "markers": "python_version >= '3.10'", + "version": "==8.4.2" + }, + "click-plugins": { + "hashes": [ + "sha256:008d65743833ffc1f5417bf0e78e8d2c23aab04d9745ba817bd3e71b0feb6aa6", + "sha256:d7af3984a99d243c131aa1a828331e7630f4a88a9741fd05c927b204bcf92261" + ], + "version": "==1.1.1.2" + }, + "cloudflare": { + "hashes": [ + "sha256:6927135a5ee5633d6e2e1952ca0484745e933727aeeb189996d2ad9d292071c6", + "sha256:b1e1c6beeb8d98f63bfe0a1cba874fc4e22e000bcc490544f956c689b3b5b258" + ], + "markers": "python_version >= '3.8'", + "version": "==4.3.1" + }, + "colorama": { + "hashes": [ + "sha256:08695f5cb7ed6e0531a20572697297273c47b8cae5a63ffc6d6ed5c201be6e44", + "sha256:4f1d9991f5acc0ca119f9d443620b77f9d6b33703e51011c16baf57afb285fc6" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6'", + "version": "==0.4.6" + }, + "contextlib2": { + "hashes": [ + "sha256:3fbdb64466afd23abaf6c977627b75b6139a5a3e8ce38405c5b413aed7a0471f", + "sha256:ab1e2bfe1d01d968e1b7e8d9023bc51ef3509bba217bb730cee3827e1ee82869" + ], + "markers": "python_version >= '3.6'", + "version": "==21.6.0" + }, + "crc32c": { + "hashes": [ + "sha256:0184369aad562d801f91f454c81f56b9ecb966f6b96684c4d6cf82fc8741d2ad", + "sha256:0450bb845b3c3c7b9bdc0b4e95620ec9a40824abdc8c86d6285c919a90743c1a", + "sha256:050475897cef1b5f51982bfaeef19d4f9e1a6691348fa47c5c83a95f12325fee", + "sha256:07f65f30a7c3e7eda933da7e22f3c4d2c266b63afd77f7048e82a6e9f2d7760d", + "sha256:086f64793c5ec856d1ab31a026d52ad2b895ac83d7a38fce557d74eb857f0a82", + "sha256:106fbd79013e06fa92bc3b51031694fcc1249811ed4364ef1554ee3dd2c7f5a2", + "sha256:14511d7cfc5d9f5e1a6c6b64caa6225c2bdc1ed00d725e9a374a3e84073ce180", + "sha256:15905fa78344654e241371c47e6ed2411f9eeb2b8095311c68c88eccf541e8b4", + "sha256:171ff0260d112c62abcce29332986950a57bddee514e0a2418bfde493ea06bb3", + "sha256:1895fbfafbe204a8127f46a252b9ae5ff18a8c6c6c7925acc8bbbce184fa5c23", + "sha256:1a16f7ffa4c242a909558565567cbba95148603717b53538ea299c98da68e7a9", + "sha256:1c529ee886eaf1c250b950e6b1636edbded39019b734ca9961c4a82f77feb55f", + "sha256:1dc4da036126ac07b39dd9d03e93e585ec615a2ad28ff12757aef7de175295a8", + "sha256:1e3dde2ec59a8a830511d72a086ead95c0b0b7f0d418f93ea106244c5e77e350", + "sha256:20a9cfb897693eb6da19e52e2a7be2026fd4d9fc8ae318f086c0d71d5dd2d8e0", + "sha256:2600f4614bd2efe1713218560503a1f5b548e23569628b7236c2c72cdc60f25f", + "sha256:2c0f4eb01fe7c0a3e3f973a418e04d52101bb077dd77626fd80c658ec60aaf95", + "sha256:2c80c3b25560df5a57345e19779e0e8710b7ba17f2439a7499fc4cd7a0a0bca5", + "sha256:2e68264555fab19bab08331550dab58573e351a63ed79c869d455edd3b0aa417", + "sha256:2e8fe863fbbd8bdb6b414a2090f1b0f52106e76e9a9c96a413495dbe5ebe492a", + "sha256:36f1e03ee9e9c6938e67d3bcb60e36f260170aa5f37da1185e04ef37b56af395", + "sha256:38f915336715d1f1353ab07d7d786f8a789b119e273aea106ba55355dfc9101d", + "sha256:3a3b2e4bcf7b3ee333050e7d3ff38e2ba46ea205f1d73d8949b248aaffe937ac", + "sha256:3cb30c019bc7856cbbb598f00ed63676d9655002351ac2ebdc01165c23c0e1b1", + "sha256:4374b3ecfdfd387c4dd53863348cc69a2c353ca8998f0a7dfd3193d108b80629", + "sha256:4379f73f9cdad31958a673d11a332ec725ca71572401ca865867229f5f15e853", + "sha256:445e559e66dff16be54f8a4ef95aa6b01db799a639956d995c5498ba513fccc2", + "sha256:4bb18e4bd98fb266596523ffc6be9c5b2387b2fa4e505ec56ca36336f49cb639", + "sha256:4c0e11e3826668121fa53e0745635baf5e4f0ded437e8ff63ea56f38fc4f970a", + "sha256:509e10035106df66770fe24b9eb8d9e32b6fb967df17744402fb67772d8b2bc7", + "sha256:51da61904a9e753780a2e6011885677d601db1fa840be4b68799643a113e6f08", + "sha256:5607ab8221e1ffd411f64aa40dbb6850cf06dd2908c9debd05d371e1acf62ff3", + "sha256:56b3b7d015247962cf58186e06d18c3d75a1a63d709d3233509e1c50a2d36aa2", + "sha256:572ffb1b78cce3d88e8d4143e154d31044a44be42cb3f6fbbf77f1e7a941c5ab", + "sha256:578728964e59c47c356aeeedee6220e021e124b9d3e8631d95d9a5e5f06e261c", + "sha256:5833f4071da7ea182c514ba17d1eee8aec3c5be927d798222fbfbbd0f5eea02c", + "sha256:59eee5f3a69ad0793d5fa9cdc9b9d743b0cd50edf7fccc0a3988a821fef0208c", + "sha256:5a7f1a0c0233f98ac96aa58edb036e53e3585b85816eea090a11763c6ee7b3b0", + "sha256:5c8933531442042438753755a5c8a9034e4d88b01da9eb796f7e151b31a7256c", + "sha256:5eb4094a2054774f13b26f21bf56792bb44fa1fcee6c6ad099387a43ffbfb4fa", + "sha256:60670569f5ede91e39f48fb0cb4060e05b8d8704dd9e17ede930bf441b2f73ef", + "sha256:60e0a765b1caab8d31b2ea80840639253906a9351d4b861551c8c8625ea20f86", + "sha256:61d51681a08b6a2a2e771b7f0cd1947fb87cb28f38ed55a01cb7c40b2ac4cdd8", + "sha256:670feb4279719f3cbfdac39f82201d28bc16ae2dc1930a6d662cc36ec4ecb9cb", + "sha256:6762d276d90331a490ef7e71ffee53b9c0eb053bd75a272d786f3b08d3fe3671", + "sha256:67c0716c3b1a02d5235be649487b637eed21f2d070f2b3f63f709dcd2fefb4c7", + "sha256:6baefcfbca82b1a9678455416da24f18629769a76920c640d5a538620a7d12bb", + "sha256:6dde035f91ffbfe23163e68605ee5a4bb8ceebd71ed54bb1fb1d0526cdd125a2", + "sha256:6e08628bc72d5b6bc8e0730e8f142194b610e780a98c58cb6698e665cb885a5b", + "sha256:6e7af94d59294d36db17032efc8e4817a589aa0720ade545484396b99ecb5496", + "sha256:6fb6590a225761d7d7b4d3a9550681550a7fc1b8b1e2fb4d1add1d10084a1320", + "sha256:70b0153c4d418b673309d3529334d117e1074c4a3b2d7f676e430d72c14de67b", + "sha256:711743da6ccc70b3c6718c328947b0b6f34a1fe6a6c27cc6c1d69cc226bf70e9", + "sha256:7399b01db4adaf41da2fb36fe2408e75a8d82a179a9564ed7619412e427b26d6", + "sha256:765d220bfcbcffa6598ac11eb1e10af0ee4802b49fe126aa6bf79f8ddb9931d1", + "sha256:7885c02d2edc17323de21a33978cdc6dbc7d4845172d2fc7563eae6e749958f5", + "sha256:864359a39777a07b09b28eb31337c0cc603d5c1bf0fc328c3af736a8da624ec0", + "sha256:86d2eeb5f0189bd803720abe7387019328ea34c4acde62999e5723f789bc316b", + "sha256:8a717dd9c3fd777d9bc6603717eae172887d402c4ab589d124ebd0184a83f89e", + "sha256:8bd317beeb59fef039debe33f139c6464c6c1801b369275f433c754cb366c438", + "sha256:8d23c4fe01b3844cb6e091044bc1cebdef7d16472e058ce12d9fadf10d2614af", + "sha256:8dd4a19505e0253892e1b2f1425cc3bd47f79ae5a04cb8800315d00aad7197f2", + "sha256:918b7999b52b5dcbcea34081e9a02d46917d571921a3f209956a9a429b2e06e5", + "sha256:9bb678507a4e4cf3f0506607b046ecc4ed1c58a19e08a3fb3c2d25441c480bf1", + "sha256:a1512640c6684805419e57ee060e50d6f33af2c0f2d1fa2ab3c2e38d7536cc32", + "sha256:a5f23f17fc25fe49d7334ce73e67568e4120b7aa43d8ad78b06bd22ebf8e45a9", + "sha256:a73d03ce3604aa5d7a2698e9057a0eef69f529c46497b27ee1c38158e90ceb76", + "sha256:b2d6a1f2500daaf2e4b08f97ad0349aa2eff5faaaa5fd3350314a26eade334cd", + "sha256:b2f3226b94b85a8dd9b3533601d7a63e9e3e8edf03a8a169830ee8303a199aeb", + "sha256:b48f2486727b8d0e7ccbae4a34cb0300498433d2a9d6b49cb13cb57c2e3f19cb", + "sha256:b977a32a3708d6f51703c8557008f190aaa434d7347431efb0e86fcbe78c2a50", + "sha256:b9829f2ab5524cd9fcba367603dbaf038e6f3280102c6dc1d3e09b4ef0e3270a", + "sha256:bcf72ee7e0135b3d941c34bb2c26c3fc6bc207106b49fd89aaafaeae223ae209", + "sha256:bf3040919e17afa5782e01b1875d6a05f44b8f19c05f211d8b9f8a1deb8bbd9c", + "sha256:c47f17195ef686545226a5a37402d0c054fdbe2b7fc3f571c28fbb6ac91a2ffb", + "sha256:c596f918688821f796434e89b431b1698396c38bf0b56de873621528fe3ecb1e", + "sha256:c7f5db4f16816926986d3c94253314920689706ae13a9bf4888b47336c6735ce", + "sha256:cc445da03fc012a5a03b71da1df1b40139729e6a5571fd4215ab40bfb39689c7", + "sha256:cdc83a3fe6c4e5df9457294cfd643de7d95bd4e9382c1dd6ed1e0f0f9169172c", + "sha256:cf827b3758ee0c4aacd21ceca0e2da83681f10295c38a10bfeb105f7d98f7a68", + "sha256:d7f959fcf6c5aad1c4a653ee1a50f05760dab1d1c35d98ec4d7f0f68643f7612", + "sha256:e41ebe7c2f0fdcd9f3a3fd206989a36b460b4d3f24816d53e5be6c7dba72c5e1", + "sha256:e560a97fbb96c9897cb1d9b5076ef12fc12e2e25622530a1afd0de4240f17e1f", + "sha256:e636ac60f76de538f7a2c0d0f3abf43104ee83a8f5e516f6345dc283ed1a4df7", + "sha256:ecf123348934a086df8c8fde7f9f2d716d523ca0707c5a1367b8bb00d8134823", + "sha256:ecf66cf90266d9c15cea597d5cc86c01917cd1a238dc3c51420c7886fa750d7e", + "sha256:fff15bf2bd3e95780516baae935ed12be88deaa5ebe6143c53eb0d26a7bdc7b7" + ], + "markers": "python_version >= '3.7'", + "version": "==2.8" + }, + "cryptography": { + "hashes": [ + "sha256:031e2d5dd4bb9caa3ca9c82e5a197fd8ae680232cee62603d1a813f3f07e3d03", + "sha256:06a32a980526a6ab9a4b9bf8f7385800791e2bb960903cb6b530e4817509a3b7", + "sha256:07479a1cb08219ab719147e742e76090c9c773321959bb94946fffdd397a6437", + "sha256:07949c449a1abcf60d1ee6e88956d89404c7df3c8258f46589e912988e551987", + "sha256:105110f43a471dbd0060b9c9516cb8a6a79233631a04cc2ba16f28323ac6e025", + "sha256:11b74db56cdbe3cdee6e3f6982ecb70334fa10dce99ed58bf7894aaaa3b2a037", + "sha256:12b9c6996425c76ea6c457ace4f3073e715b8c545add07cd1a8f3a4f90691269", + "sha256:1489e263a8048bb8b6a8bac662eb2d402ea5d2b7b4699b72f385f1e2772db105", + "sha256:19736989797678c6af1e55cd49055cdbcb55d8f6b5583ac5335f933aba9101dc", + "sha256:1b4a266766514614f8aa60416e71f2fc6e575d36e7bdc90f644fadb2f4b75b95", + "sha256:2a8183b489dc1f7f80f135780fadc1108f14b31b8a40411c7a5b17425f65f28b", + "sha256:37fdb0d0111f1e2ff07139dfb79f1b49531f8e213c46f1163dd7642979b58c47", + "sha256:3f5735ffe4996d28b809371756219f5354864902a3b9e7c0b9ee87041209fc9c", + "sha256:49e7d93abdbd2990caced757e5fade25302f719c3c8fb6e6fff2dde98999fc41", + "sha256:5e34edd123674534acd70147f0ca331eaa2c74e6325fb2028c886aa26ba0b68c", + "sha256:62598a8a57f815db4c6259a4e97d857dab56697e7de8e8ab02352ab74da1995d", + "sha256:65c2c3add92b45fd0709db8594536aea39c2a67af0e27ffcf049c498501140b7", + "sha256:6ba6a53445bd3cfa809ef3ef5f1589aa6ba08784a1d962bf47d0940e871dab1c", + "sha256:6e7d61120573a7f2cd94cc095f9e81f6967c61ccdf194285aa143ecec8e0b708", + "sha256:7cec5b856506da6defb290f30c9ee687d5f5e8cb0bd3f6459dde43b0b4fa40ef", + "sha256:80b63928fa35083b33966ce1efb70e5b9607181e49dcd1c22c8c005e319f667f", + "sha256:82148ec5bddac30b51a5b3c1945075f896fa022cb93f8e4a01e9f6ee95292c5f", + "sha256:828743d939e9629bc267b8e2d08d8bb67cd4319c771a33d4b18b22dd8fb7440a", + "sha256:8d89f3976b10b4ce31118de72329025f70d2c6ead14a8217c5514dd2c6d5a78f", + "sha256:8eb5e1172eb569ea8a872796576e6a67c276351728b6455d5beb01242b027c6a", + "sha256:900131fafd8aead39ac7dd3a7e833be754c17a95cfd91221636949fe4eb0aa8a", + "sha256:910d11e1a385c654bf738bf3e6b8e6ed5de0f5610fcae2be9e5b398d8081d20e", + "sha256:910e1d2668e7de9648f2bcee30e180db2a6b15c30f887d7c4c93ddf96e3992e3", + "sha256:9aa87839c383bdbab6ef865787a1fb877af8dd03464c4400322726feaaadfc6d", + "sha256:a1b30560f2acc95aa8b2e06e716a13dbfc97314747b80d9707e307f77b40d6b3", + "sha256:a91296cb61e8df6f86d0c19cc4068228da256bf59bf86049fbd821084565327f", + "sha256:b42a28c1844fd9de8f3f7d540e36b66f3a9c83fceac7170ebc7a6a19edd9dcae", + "sha256:bd1c592e4d5974f0d08d4888e432157adba757c66da0246918e43677fafa2d30", + "sha256:c87f62a3d3b9888ed0fdde100ec06aa61ca9cd44bad9057d1dff9a516b5f5bb9", + "sha256:c99c003e088647b8a5b7c145d6f78c335f6348332b62e142d411c4b63d1460b9", + "sha256:ccdc4a71a4dabae05de219404f9f4abc38e3b58422177ff93d0da05967dafa07", + "sha256:d24fead1d4d076e1bfb006dcec392074a3cd8d7b4fc8a595aa64073b2b7a96ba", + "sha256:d58c3db7cd6eed54e6c06744db55456b65ebd7492ddeae9c1e93cfca7aa857d3", + "sha256:d764dcf130c428ef66786f866dd750f53182bc608813489915e9fc106bb0c82f", + "sha256:df2a58a472f332225671c35b0a830208b86d004f82baa8530fa3782c85646533", + "sha256:e722f16708d854fe924790e051061f6704a472c3bac347b6fd88033ea8dd0dc5", + "sha256:ecfed7367f965a0328cfbdd70da860f15441f002f613185668c6e6ebf5a0ac11", + "sha256:eeac2acb5a20ed25e0ad6d1df9891a520b78b404266b6d11778f25d5d691a6c9", + "sha256:f59e38625469987d7ef6d495323c55e7db6c212eaf6112267e0d3b565a2e9c9f", + "sha256:f89831ef99dd7dd169ab06d63a831adb9e20a87aac6d380266bbda5823349169", + "sha256:fd9192b7b70c573d7f214eb1ae35e00d359f6f5e4b27c7e21e30de1fc6204645" + ], + "markers": "python_version >= '3.9' and python_full_version not in '3.9.0, 3.9.1'", + "version": "==50.0.0" + }, + "darabonba-core": { + "hashes": [ + "sha256:ac093fdd40f88f2f9dfbbbfd7bc143495a3cb031f35b397c98d24edfa6b69483", + "sha256:f1661960b368e342d3d36434be82d264b70a01c49e843921d8a4dacd217376ae" + ], + "markers": "python_version >= '3.7'", + "version": "==1.0.8" + }, + "dash": { + "hashes": [ + "sha256:66fff37e79c6aa114cd55aea13683d1e9afe0e3f96b35388baca95ff6cfdad23", + "sha256:916b31cec46da0a3339da0e9df9f446126aa7f293c0544e07adf9fe4ba060b18" + ], + "markers": "python_version >= '3.8'", + "version": "==3.1.1" + }, + "dash-bootstrap-components": { + "hashes": [ + "sha256:5c161b04a6e7ed19a7d54e42f070c29fd6c385d5a7797e7a82999aa2fc15b1de", + "sha256:82754d3d001ad5482b8a82b496c7bf98a1c68d2669d607a89dda7ec627304af5" + ], + "markers": "python_version >= '3.9'", + "version": "==2.0.3" + }, + "decorator": { + "hashes": [ + "sha256:4cbcdd55a6efadb9dbea26b858f4fb3264567b52d69ca0d25b721b553f60ea82", + "sha256:f47fe6fdbd2edd623ecfe36875d37aba411624e2670dd395dddae1358689bb3c" + ], + "markers": "python_version >= '3.8'", + "version": "==5.3.1" + }, + "defusedxml": { + "hashes": [ + "sha256:1bb3032db185915b62d7c6209c5a8792be6a32ab2fedacc84e01b52c51aa3e69", + "sha256:a352e7e428770286cc899e2542b6cdaedb2b4953ff269a210103ec58f6198a61" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4'", + "version": "==0.7.1" + }, + "deprecated": { + "hashes": [ + "sha256:597bfef186b6f60181535a29fbe44865ce137a5079f295b479886c82729d5f3f", + "sha256:b1b50e0ff0c1fddaa5708a2c6b0a6588bb09b892825ab2b214ac9ea9d92a5223" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'", + "version": "==1.3.1" + }, + "distro": { + "hashes": [ + "sha256:2fa77c6fd8940f116ee1d6b94a2f90b13b5ea8d019b98bc8bafdcabcdd9bdbed", + "sha256:7bffd925d65168f85027d8da9af6bddab658135b840670a223589bc0c8ef02b2" + ], + "markers": "python_version >= '3.6'", + "version": "==1.9.0" + }, + "dnspython": { + "hashes": [ + "sha256:01d9bbc4a2d76bf0db7c1f729812ded6d912bd318d3b1cf81d30c0f845dbf3af", + "sha256:181d3c6996452cb1189c4046c61599b84a5a86e099562ffde77d26984ff26d0f" + ], + "markers": "python_version >= '3.10'", + "version": "==2.8.0" + }, + "dogpile.cache": { + "hashes": [ + "sha256:849c5573c9a38f155cd4173103c702b637ede0361c12e864876877d0cd125eec", + "sha256:dc7b47d37844db15e8fdc0243c1b58857a2ddc52a5118237a97127bac200e18d" + ], + "markers": "python_version >= '3.10'", + "version": "==1.5.0" + }, + "dulwich": { + "hashes": [ + "sha256:00b54a1d56ddbacdd8eadd6d4787a51b3a05fefa30eadbf9165fd283a00b90ed", + "sha256:0395b2c8924c3424bafe2d9c1edd5348cc4b21ce9c1d6655bf01f9a5c47164c8", + "sha256:07cb75b58216440e2c170fff4f3d55a5f387358d9489863af8cb11f24ee37121", + "sha256:1679b376433a0fc7f36586afda1d4ed7427afa7a79d4bf17e5014474eea69fa4", + "sha256:1699a4cf8d44c174408325a9594a1498d05786cea34e3004c8732420ee1b8182", + "sha256:1ba83ec3cfb4c506c277400357a51523c8258fa07b841ee06e8e1071da4cfed1", + "sha256:1c151a7f3995ccf9d433a603b747e76141a7ebe7c385c8909e9f7e7a6422c28f", + "sha256:2f10dafa1ef5660b1331364bc8d68446448608a8d8f493ed0e260eaf5133e71c", + "sha256:2f90d68bfa97c4ca71de7507984365aefe27b6d248cb28dc99644d0f3ae8c60b", + "sha256:41ccffb0521f3f9ad73fac78772f321d731607336cee48911e7c26963459481c", + "sha256:46db47394ba8a95748ae739f5d3a5a3e1724a2f857bf2437bc71bfc0baaed91d", + "sha256:5108acead814d1de8b6262d6d8fb90af7e82f5a4d83788b6b48e39d01800a92f", + "sha256:517fb7e20f91d2bd48dc5de9edc90ff8974a5512ce7f243284b191f8be6344c3", + "sha256:53599909d54a2fae49fcd50047f1daf4b8b9eda6a5500a08b71da689f5431c24", + "sha256:556593fd11637f80f6018bee1916b1a84f5b420423b470ebb3f1a782ad6ef081", + "sha256:5e067b7feceb7034bc99e7c7143a704f1d97d4be7027d9a0aa5a83c0657ff091", + "sha256:66aded7d364341b55941973a1562323f25bd205f0809692b687ec36ccd31242c", + "sha256:6c683c0f4a062894b6826c61102d415dae86ade61a10003c82ccc2b91858d5fb", + "sha256:701a9ecf7a8a44f5e2459e46befa93530cf36a8b1ae3140aefc007db1d7d0207", + "sha256:77d2d2e43ad975459491de1ebf47990c74ff17f12586c8561e9890239bc422db", + "sha256:827366331603150de5976d72dd456a3fd5fc91e856471dc1d10fd64758c05f02", + "sha256:8929134acf4ff967203df7600b38535f9b5b590462067a7e30dbce01acb97af9", + "sha256:8e55f36a7f52ba0976dd72100273523908b16fb9dda6ce96d9aa9df9cceed4cc", + "sha256:9008ef25cabd379cda4fa86000fc38ca14b72afe17db798a8c85c0b2b7ce4d1e", + "sha256:93d2d87acf75d60c5a2b8c5c8a45aff17bbbd00c17bdccb4ba013d3ab590a65f", + "sha256:9693d2c9e226b2ea855c1dc3a87e2f4d972f7523fc0f7924e5997e9f4c23d97f", + "sha256:9b6d234f1f91335e9f01d9daac42ddc2d2e5c2fdbe285d8eeef50353b283648a", + "sha256:9f3c98f5fa90a842c1f545463834f712aa2eed785fc3d5e42836c0df2d691bb6", + "sha256:9fc113c1348c7eb22c4e8790f68b562bb4f42a721fafb813e89a57e9cd632040", + "sha256:a5549f4afc973e0a15ea6b0244d57f848d3f3ee13dac557eb311024aebebf128", + "sha256:a6620963196c49212c511cd909f367dacf771f199a27d116f357cc671ea956c7", + "sha256:a70477c991e96cfe8fdd7c866e7251faf71b38bfeb51d6f27554c9cce1caabf3", + "sha256:ade416833214f3ee13af9b0199fff4de00fa6e0fde3deced776532fd91df5515", + "sha256:c65230abaa52c72093b70d3b499d5689d1d8f9627e88ad3c3b4f8154e86ac0c8", + "sha256:ccc58f26a1b94bef255316311678b03854f7192069bdf11cf501a6c85f61b83c", + "sha256:d33bae2b3292ed0235522682316251658187f43b1ebad6cd2b127069b94afb3b", + "sha256:d46e35c473646efb3b2ff8032f37ac5b6d48da52a669577187d3796a6d5987a3", + "sha256:d8f7ea8f47e38e5b0de3fab97e07e9c9161ffddc90b3964512cab2b7749df4e6", + "sha256:dd9569bc26174a3437d749114d36c81fc6c7478b55370ae50125e34e9629e4fe", + "sha256:df4ac3746099562c8160d78d55bb2fa10c9ada7ef970af3e2536bd133cb7830e", + "sha256:e128cddeccae4146b556684a0d5426454fff5bfe7306862e5a8ce6b471568af4", + "sha256:fa37da7ad16c47391016b5f984fb60e175e1ab0b478f04920fd6d1f61123ce4d" + ], + "markers": "python_version >= '3.10'", + "version": "==1.2.5" + }, + "durationpy": { + "hashes": [ + "sha256:1fa6893409a6e739c9c72334fc65cca1f355dbdd93405d30f726deb5bde42fba", + "sha256:3b41e1b601234296b4fb368338fdcd3e13e0b4fb5b67345948f4f2bf9868b286" + ], + "version": "==0.10" + }, + "email-validator": { + "hashes": [ + "sha256:561977c2d73ce3611850a06fa56b414621e0c8faa9d66f2611407d87465da631", + "sha256:cb690f344c617a714f22e66ae771445a1ceb46821152df8e165c5f9a364582b7" + ], + "markers": "python_version >= '3.8'", + "version": "==2.2.0" + }, + "filelock": { + "hashes": [ + "sha256:0ffa185a3540854c95caa7fa76b76cb219d907415e2c5dc9af25fd970563487f", + "sha256:7f0ca4bcc0e181c60dbbd8aa9ab5b120ebb99e4e064e83636340056f833a1f09" + ], + "markers": "python_version >= '3.10'", + "version": "==3.32.3" + }, + "flask": { + "hashes": [ + "sha256:0ef0e52b8a9cd932855379197dd8f94047b359ca0a78695144304cb45f87c9eb", + "sha256:f4bcbefc124291925f1a26446da31a5178f9483862233b23c0c96a20701f670c" + ], + "markers": "python_version >= '3.9'", + "version": "==3.1.3" + }, + "frozenlist": { + "hashes": [ + "sha256:0325024fe97f94c41c08872db482cf8ac4800d80e79222c6b0b7b162d5b13686", + "sha256:032efa2674356903cd0261c4317a561a6850f3ac864a63fc1583147fb05a79b0", + "sha256:03ae967b4e297f58f8c774c7eabcce57fe3c2434817d4385c50661845a058121", + "sha256:06be8f67f39c8b1dc671f5d83aaefd3358ae5cdcf8314552c57e7ed3e6475bdd", + "sha256:073f8bf8becba60aa931eb3bc420b217bb7d5b8f4750e6f8b3be7f3da85d38b7", + "sha256:07cdca25a91a4386d2e76ad992916a85038a9b97561bf7a3fd12d5d9ce31870c", + "sha256:09474e9831bc2b2199fad6da3c14c7b0fbdd377cce9d3d77131be28906cb7d84", + "sha256:0c18a16eab41e82c295618a77502e17b195883241c563b00f0aa5106fc4eaa0d", + "sha256:0f96534f8bfebc1a394209427d0f8a63d343c9779cda6fc25e8e121b5fd8555b", + "sha256:102e6314ca4da683dca92e3b1355490fed5f313b768500084fbe6371fddfdb79", + "sha256:11847b53d722050808926e785df837353bd4d75f1d494377e59b23594d834967", + "sha256:119fb2a1bd47307e899c2fac7f28e85b9a543864df47aa7ec9d3c1b4545f096f", + "sha256:13d23a45c4cebade99340c4165bd90eeb4a56c6d8a9d8aa49568cac19a6d0dc4", + "sha256:154e55ec0655291b5dd1b8731c637ecdb50975a2ae70c606d100750a540082f7", + "sha256:168c0969a329b416119507ba30b9ea13688fafffac1b7822802537569a1cb0ef", + "sha256:17c883ab0ab67200b5f964d2b9ed6b00971917d5d8a92df149dc2c9779208ee9", + "sha256:1a7607e17ad33361677adcd1443edf6f5da0ce5e5377b798fba20fae194825f3", + "sha256:1a7fa382a4a223773ed64242dbe1c9c326ec09457e6b8428efb4118c685c3dfd", + "sha256:1aa77cb5697069af47472e39612976ed05343ff2e84a3dcf15437b232cbfd087", + "sha256:1b9290cf81e95e93fdf90548ce9d3c1211cf574b8e3f4b3b7cb0537cf2227068", + "sha256:20e63c9493d33ee48536600d1a5c95eefc870cd71e7ab037763d1fbb89cc51e7", + "sha256:21900c48ae04d13d416f0e1e0c4d81f7931f73a9dfa0b7a8746fb2fe7dd970ed", + "sha256:229bf37d2e4acdaf808fd3f06e854a4a7a3661e871b10dc1f8f1896a3b05f18b", + "sha256:2552f44204b744fba866e573be4c1f9048d6a324dfe14475103fd51613eb1d1f", + "sha256:27c6e8077956cf73eadd514be8fb04d77fc946a7fe9f7fe167648b0b9085cc25", + "sha256:28bd570e8e189d7f7b001966435f9dac6718324b5be2990ac496cf1ea9ddb7fe", + "sha256:294e487f9ec720bd8ffcebc99d575f7eff3568a08a253d1ee1a0378754b74143", + "sha256:29548f9b5b5e3460ce7378144c3010363d8035cea44bc0bf02d57f5a685e084e", + "sha256:2c5dcbbc55383e5883246d11fd179782a9d07a986c40f49abe89ddf865913930", + "sha256:2dc43a022e555de94c3b68a4ef0b11c4f747d12c024a520c7101709a2144fb37", + "sha256:2f05983daecab868a31e1da44462873306d3cbfd76d1f0b5b69c473d21dbb128", + "sha256:33139dc858c580ea50e7e60a1b0ea003efa1fd42e6ec7fdbad78fff65fad2fd2", + "sha256:332db6b2563333c5671fecacd085141b5800cb866be16d5e3eb15a2086476675", + "sha256:33f48f51a446114bc5d251fb2954ab0164d5be02ad3382abcbfe07e2531d650f", + "sha256:34187385b08f866104f0c0617404c8eb08165ab1272e884abc89c112e9c00746", + "sha256:342c97bf697ac5480c0a7ec73cd700ecfa5a8a40ac923bd035484616efecc2df", + "sha256:3462dd9475af2025c31cc61be6652dfa25cbfb56cbbf52f4ccfe029f38decaf8", + "sha256:39ecbc32f1390387d2aa4f5a995e465e9e2f79ba3adcac92d68e3e0afae6657c", + "sha256:3e0761f4d1a44f1d1a47996511752cf3dcec5bbdd9cc2b4fe595caf97754b7a0", + "sha256:3ede829ed8d842f6cd48fc7081d7a41001a56f1f38603f9d49bf3020d59a31ad", + "sha256:3ef2d026f16a2b1866e1d86fc4e1291e1ed8a387b2c333809419a2f8b3a77b82", + "sha256:405e8fe955c2280ce66428b3ca55e12b3c4e9c336fb2103a4937e891c69a4a29", + "sha256:42145cd2748ca39f32801dad54aeea10039da6f86e303659db90db1c4b614c8c", + "sha256:4314debad13beb564b708b4a496020e5306c7333fa9a3ab90374169a20ffab30", + "sha256:433403ae80709741ce34038da08511d4a77062aa924baf411ef73d1146e74faf", + "sha256:44389d135b3ff43ba8cc89ff7f51f5a0bb6b63d829c8300f79a2fe4fe61bcc62", + "sha256:48e6d3f4ec5c7273dfe83ff27c91083c6c9065af655dc2684d2c200c94308bb5", + "sha256:494a5952b1c597ba44e0e78113a7266e656b9794eec897b19ead706bd7074383", + "sha256:4970ece02dbc8c3a92fcc5228e36a3e933a01a999f7094ff7c23fbd2beeaa67c", + "sha256:4e0c11f2cc6717e0a741f84a527c52616140741cd812a50422f83dc31749fb52", + "sha256:50066c3997d0091c411a66e710f4e11752251e6d2d73d70d8d5d4c76442a199d", + "sha256:517279f58009d0b1f2e7c1b130b377a349405da3f7621ed6bfae50b10adf20c1", + "sha256:54b2077180eb7f83dd52c40b2750d0a9f175e06a42e3213ce047219de902717a", + "sha256:5500ef82073f599ac84d888e3a8c1f77ac831183244bfd7f11eaa0289fb30714", + "sha256:581ef5194c48035a7de2aefc72ac6539823bb71508189e5de01d60c9dcd5fa65", + "sha256:59a6a5876ca59d1b63af8cd5e7ffffb024c3dc1e9cf9301b21a2e76286505c95", + "sha256:5a3a935c3a4e89c733303a2d5a7c257ea44af3a56c8202df486b7f5de40f37e1", + "sha256:5c1c8e78426e59b3f8005e9b19f6ff46e5845895adbde20ece9218319eca6506", + "sha256:5d63a068f978fc69421fb0e6eb91a9603187527c86b7cd3f534a5b77a592b888", + "sha256:667c3777ca571e5dbeb76f331562ff98b957431df140b54c85fd4d52eea8d8f6", + "sha256:6da155091429aeba16851ecb10a9104a108bcd32f6c1642867eadaee401c1c41", + "sha256:6dc4126390929823e2d2d9dc79ab4046ed74680360fc5f38b585c12c66cdf459", + "sha256:7398c222d1d405e796970320036b1b563892b65809d9e5261487bb2c7f7b5c6a", + "sha256:74c51543498289c0c43656701be6b077f4b265868fa7f8a8859c197006efb608", + "sha256:776f352e8329135506a1d6bf16ac3f87bc25b28e765949282dcc627af36123aa", + "sha256:778a11b15673f6f1df23d9586f83c4846c471a8af693a22e066508b77d201ec8", + "sha256:78f7b9e5d6f2fdb88cdde9440dc147259b62b9d3b019924def9f6478be254ac1", + "sha256:799345ab092bee59f01a915620b5d014698547afd011e691a208637312db9186", + "sha256:7bf6cdf8e07c8151fba6fe85735441240ec7f619f935a5205953d58009aef8c6", + "sha256:8009897cdef112072f93a0efdce29cd819e717fd2f649ee3016efd3cd885a7ed", + "sha256:80f85f0a7cc86e7a54c46d99c9e1318ff01f4687c172ede30fd52d19d1da1c8e", + "sha256:8585e3bb2cdea02fc88ffa245069c36555557ad3609e83be0ec71f54fd4abb52", + "sha256:878be833caa6a3821caf85eb39c5ba92d28e85df26d57afb06b35b2efd937231", + "sha256:8a76ea0f0b9dfa06f254ee06053d93a600865b3274358ca48a352ce4f0798450", + "sha256:8b7b94a067d1c504ee0b16def57ad5738701e4ba10cec90529f13fa03c833496", + "sha256:8d92f1a84bb12d9e56f818b3a746f3efba93c1b63c8387a73dde655e1e42282a", + "sha256:908bd3f6439f2fef9e85031b59fd4f1297af54415fb60e4254a95f75b3cab3f3", + "sha256:92db2bf818d5cc8d9c1f1fc56b897662e24ea5adb36ad1f1d82875bd64e03c24", + "sha256:940d4a017dbfed9daf46a3b086e1d2167e7012ee297fef9e1c545c4d022f5178", + "sha256:957e7c38f250991e48a9a73e6423db1bb9dd14e722a10f6b8bb8e16a0f55f695", + "sha256:96153e77a591c8adc2ee805756c61f59fef4cf4073a9275ee86fe8cba41241f7", + "sha256:96f423a119f4777a4a056b66ce11527366a8bb92f54e541ade21f2374433f6d4", + "sha256:97260ff46b207a82a7567b581ab4190bd4dfa09f4db8a8b49d1a958f6aa4940e", + "sha256:974b28cf63cc99dfb2188d8d222bc6843656188164848c4f679e63dae4b0708e", + "sha256:9ff15928d62a0b80bb875655c39bf517938c7d589554cbd2669be42d97c2cb61", + "sha256:a6483e309ca809f1efd154b4d37dc6d9f61037d6c6a81c2dc7a15cb22c8c5dca", + "sha256:a88f062f072d1589b7b46e951698950e7da00442fc1cacbe17e19e025dc327ad", + "sha256:ac913f8403b36a2c8610bbfd25b8013488533e71e62b4b4adce9c86c8cea905b", + "sha256:adbeebaebae3526afc3c96fad434367cafbfd1b25d72369a9e5858453b1bb71a", + "sha256:b2a095d45c5d46e5e79ba1e5b9cb787f541a8dee0433836cea4b96a2c439dcd8", + "sha256:b3210649ee28062ea6099cfda39e147fa1bc039583c8ee4481cb7811e2448c51", + "sha256:b37f6d31b3dcea7deb5e9696e529a6aa4a898adc33db82da12e4c60a7c4d2011", + "sha256:b4dec9482a65c54a5044486847b8a66bf10c9cb4926d42927ec4e8fd5db7fed8", + "sha256:b4f3b365f31c6cd4af24545ca0a244a53688cad8834e32f56831c4923b50a103", + "sha256:b6db2185db9be0a04fecf2f241c70b63b1a242e2805be291855078f2b404dd6b", + "sha256:b9be22a69a014bc47e78072d0ecae716f5eb56c15238acca0f43d6eb8e4a5bda", + "sha256:bac9c42ba2ac65ddc115d930c78d24ab8d4f465fd3fc473cdedfccadb9429806", + "sha256:bf0a7e10b077bf5fb9380ad3ae8ce20ef919a6ad93b4552896419ac7e1d8e042", + "sha256:c23c3ff005322a6e16f71bf8692fcf4d5a304aaafe1e262c98c6d4adc7be863e", + "sha256:c4c800524c9cd9bac5166cd6f55285957fcfc907db323e193f2afcd4d9abd69b", + "sha256:c7366fe1418a6133d5aa824ee53d406550110984de7637d65a178010f759c6ef", + "sha256:c8d1634419f39ea6f5c427ea2f90ca85126b54b50837f31497f3bf38266e853d", + "sha256:c9a63152fe95756b85f31186bddf42e4c02c6321207fd6601a1c89ebac4fe567", + "sha256:cb89a7f2de3602cfed448095bab3f178399646ab7c61454315089787df07733a", + "sha256:cba69cb73723c3f329622e34bdbf5ce1f80c21c290ff04256cff1cd3c2036ed2", + "sha256:cee686f1f4cadeb2136007ddedd0aaf928ab95216e7691c63e50a8ec066336d0", + "sha256:cf253e0e1c3ceb4aaff6df637ce033ff6535fb8c70a764a8f46aafd3d6ab798e", + "sha256:d1eaff1d00c7751b7c6662e9c5ba6eb2c17a2306ba5e2a37f24ddf3cc953402b", + "sha256:d3bb933317c52d7ea5004a1c442eef86f426886fba134ef8cf4226ea6ee1821d", + "sha256:d4d3214a0f8394edfa3e303136d0575eece0745ff2b47bd2cb2e66dd92d4351a", + "sha256:d6a5df73acd3399d893dafc71663ad22534b5aa4f94e8a2fabfe856c3c1b6a52", + "sha256:d8b7138e5cd0647e4523d6685b0eac5d4be9a184ae9634492f25c6eb38c12a47", + "sha256:db1e72ede2d0d7ccb213f218df6a078a9c09a7de257c2fe8fcef16d5925230b1", + "sha256:e25ac20a2ef37e91c1b39938b591457666a0fa835c7783c3a8f33ea42870db94", + "sha256:e2de870d16a7a53901e41b64ffdf26f2fbb8917b3e6ebf398098d72c5b20bd7f", + "sha256:e4a3408834f65da56c83528fb52ce7911484f0d1eaf7b761fc66001db1646eff", + "sha256:eaa352d7047a31d87dafcacbabe89df0aa506abb5b1b85a2fb91bc3faa02d822", + "sha256:eab8145831a0d56ec9c4139b6c3e594c7a83c2c8be25d5bcf2d86136a532287a", + "sha256:ec3cc8c5d4084591b4237c0a272cc4f50a5b03396a47d9caaf76f5d7b38a4f11", + "sha256:edee74874ce20a373d62dc28b0b18b93f645633c2943fd90ee9d898550770581", + "sha256:eefdba20de0d938cec6a89bd4d70f346a03108a19b9df4248d3cf0d88f1b0f51", + "sha256:ef2b7b394f208233e471abc541cc6991f907ffd47dc72584acee3147899d6565", + "sha256:f21f00a91358803399890ab167098c131ec2ddd5f8f5fd5fe9c9f2c6fcd91e40", + "sha256:f4be2e3d8bc8aabd566f8d5b8ba7ecc09249d74ba3c9ed52e54dc23a293f0b92", + "sha256:f57fb59d9f385710aa7060e89410aeb5058b99e62f4d16b08b91986b9a2140c2", + "sha256:f6292f1de555ffcc675941d65fffffb0a5bcd992905015f85d0592201793e0e5", + "sha256:f833670942247a14eafbb675458b4e61c82e002a148f49e68257b79296e865c4", + "sha256:fa47e444b8ba08fffd1c18e8cdb9a75db1b6a27f17507522834ad13ed5922b93", + "sha256:fb30f9626572a76dfe4293c7194a09fb1fe93ba94c7d4f720dfae3b646b45027", + "sha256:fe3c58d2f5db5fbd18c2987cba06d51b0529f52bc3a6cdc33d3f4eab725104bd" + ], + "markers": "python_version >= '3.9'", + "version": "==1.8.0" + }, + "google-api-core": { + "hashes": [ + "sha256:98a779fe72de956eb1c9c2f47ff4c4432a668ece1a002ec38bed07ec2698ae59", + "sha256:cdf9c67e7ca2402d86ccbfde5f2503fc83e3cc3f58cc78456ae96cad24a6d2de" + ], + "markers": "python_version >= '3.10'", + "version": "==2.34.0" + }, + "google-api-python-client": { + "hashes": [ + "sha256:080e8bc0669cb4c1fb8efb8da2f5b91a2625d8f0e7796cfad978f33f7016c6c4", + "sha256:88dee87553a2d82176e2224648bf89272d536c8f04dcdda37ef0a71473886dd7" + ], + "markers": "python_version >= '3.7'", + "version": "==2.163.0" + }, + "google-auth": { + "hashes": [ + "sha256:40e229fc901f0a305b553050e5fce562d509bee0435be053abfa91582b51b90c", + "sha256:8ec438808f813ad034535000261eed1067475d229d05bbf4216e78c3f2362e53" + ], + "markers": "python_version >= '3.10'", + "version": "==2.56.3" + }, + "google-auth-httplib2": { + "hashes": [ + "sha256:38aa7badf48f974f1eb9861794e9c0cb2a0511a4ec0679b1f886d108f5640e05", + "sha256:b65a0a2123300dd71281a7bf6e64d65a0759287df52729bdd1ae2e47dc311a3d" + ], + "version": "==0.2.0" + }, + "googleapis-common-protos": { + "hashes": [ + "sha256:28a1934bcd33b9c9da66ac301a0a4227e3367f095a17d0375cb98f0a09d93b79", + "sha256:d3042c6c5a2d4e67113104d6b6818b59b6bd92a197f2a91508e801fe815cf071" + ], + "markers": "python_version >= '3.10'", + "version": "==1.75.1" + }, + "graphemeu": { + "hashes": [ + "sha256:1444520f6899fd30114fc2a39f297d86d10fa0f23bf7579f772f8bc7efaa2542", + "sha256:42bbe373d7c146160f286cd5f76b1a8ad29172d7333ce10705c5cc282462a4f8" + ], + "markers": "python_version >= '3.7'", + "version": "==0.7.2" + }, + "h11": { + "hashes": [ + "sha256:4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208ee5ff1", + "sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86" + ], + "markers": "python_version >= '3.8'", + "version": "==0.16.0" + }, + "h2": { + "hashes": [ + "sha256:6c59efe4323fa18b47a632221a1888bd7fde6249819beda254aeca909f221bf1", + "sha256:c438f029a25f7945c69e0ccf0fb951dc3f73a5f6412981daee861431b70e2bdd" + ], + "markers": "python_version >= '3.9'", + "version": "==4.3.0" + }, + "hpack": { + "hashes": [ + "sha256:0895cfa3b5531fc65fe439c05eb65144f123bf7a394fcaa56aa423548d8e45c0", + "sha256:858ac0b02280fa582b5080d68db0899c62a80375e0e5413a74970c5e518b6986" + ], + "markers": "python_version >= '3.10'", + "version": "==4.2.0" + }, + "httpcore": { + "hashes": [ + "sha256:2d400746a40668fc9dec9810239072b40b4484b640a8c38fd654a024c7a1bf55", + "sha256:6e34463af53fd2ab5d807f399a9b45ea31c3dfa2276f15a2c3f00afff6e176e8" + ], + "markers": "python_version >= '3.8'", + "version": "==1.0.9" + }, + "httplib2": { + "hashes": [ + "sha256:48a0ef30a42db65d8f3399045e1d09ab0ba66e3b9efc360d07f80ea55d286025", + "sha256:dc6705cacdf3fb0a2aba7629fa33c90fd93e30035db0c157325826be177e4816" + ], + "markers": "python_version >= '3.8'", + "version": "==0.32.0" + }, + "httpx": { + "extras": [ + "http2" + ], + "hashes": [ + "sha256:75e98c5f16b0f35b567856f597f06ff2270a374470a5c2392242528e3e3e42fc", + "sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad" + ], + "markers": "python_version >= '3.8'", + "version": "==0.28.1" + }, + "huaweicloudsdkcore": { + "hashes": [ + "sha256:9ae17744795ebdc8ce9291373a3a27bf72e90aa98677cfce0ea9394376875a95" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkcts": { + "hashes": [ + "sha256:9def561aa784a6ee13b46bfc96888cd1df5bfc42f8a89e60b42c91c608bf6d60" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkecs": { + "hashes": [ + "sha256:dc5715d782c0260b901c793d009d5e632257acb04257b6f2c6631e415c589343" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkelb": { + "hashes": [ + "sha256:620247c2b2a7f20e7da8b18fe9c64e29972055f015bc35270fb5b43243dc4830" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkevs": { + "hashes": [ + "sha256:9118ac4c576e54aa7eaa926949e2b6824c5f038a2274b51d9a304d37fc0d7e2f" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkiam": { + "hashes": [ + "sha256:0021e204f81ceef2640017e517adb72ba56c9ced03f071a0265b10bc9759badf" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkkms": { + "hashes": [ + "sha256:378986f33113ce99f445ef318d1c7dda89e361d16c008e5ef9793981d8385376" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkobs": { + "hashes": [ + "sha256:8c5830fa30293185964d98e524887fc510c8e17ca2fadb4563dad10910f37b13" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkrds": { + "hashes": [ + "sha256:a790b5b3c457a608e5679c101f463b4d037dd9a8a66f6e46144a9e5a4b37780f" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkvpc": { + "hashes": [ + "sha256:c57d6b6d2f70deca91e86f7956b33fc9ac4991b431f0d608c3632231119f8970" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "huaweicloudsdkwaf": { + "hashes": [ + "sha256:b2355276e0029808f45e2d1bd3eb14b37d2da9417e61e642ffe0e2b748ca8283" + ], + "markers": "python_version >= '3.6'", + "version": "==3.1.204" + }, + "hyperframe": { + "hashes": [ + "sha256:b03380493a519fce58ea5af42e4a42317bf9bd425596f7a0835ffce80f1a42e5", + "sha256:f630908a00854a7adeabd6382b43923a4c4cd4b821fcb527e6ab9e15382a3b08" + ], + "markers": "python_version >= '3.9'", + "version": "==6.1.0" + }, + "iamdata": { + "hashes": [ + "sha256:27809af7c5fc822ff656fee329a761f9350a082b21601d5a51c497634baf61c7", + "sha256:f6b75261120314dd18010d9b86863068e0bca4acfb66d45c1472d5544c43bc12" + ], + "markers": "python_version >= '3.7'", + "version": "==0.1.202608191" + }, + "idna": { + "hashes": [ + "sha256:5e0811a4383b21dc5838069f801c4fb62113b7447663d2530d2bd6e77b49bf15", + "sha256:815e7be7a7806d54abb586dc943addc79e8b2ee16915059658cbeff4b1b43bf4" + ], + "markers": "python_version >= '3.9'", + "version": "==3.19" + }, + "importlib-metadata": { + "hashes": [ + "sha256:2d21d1cc5a017bd0559e36150c21c830ab1dc304dedd1b7ea85d20f45ef3edd7", + "sha256:a4f57ab599e6a2e3016d7595cfd72eb4661a5106e787a95bcc90c7105b831efc" + ], + "markers": "python_version >= '3.10'", + "version": "==9.0.0" + }, + "iso8601": { + "hashes": [ + "sha256:6b1d3829ee8921c4301998c909f7829fa9ed3cbdac0d3b16af2d743aed1ba8df", + "sha256:aac4145c4dcb66ad8b648a02830f5e2ff6c24af20f4f482689be402db2429242" + ], + "markers": "python_version >= '3.7' and python_version < '4.0'", + "version": "==2.1.0" + }, + "isodate": { + "hashes": [ + "sha256:28009937d8031054830160fce6d409ed342816b543597cece116d966c6d99e15", + "sha256:4cd1aa0f43ca76f4a6c6c0292a85f40b35ec2e43e315b59f06e6d32171a953e6" + ], + "markers": "python_version >= '3.7'", + "version": "==0.7.2" + }, + "itsdangerous": { + "hashes": [ + "sha256:c6242fc49e35958c8b15141343aa660db5fc54d4f13a1db01a3f5891b98700ef", + "sha256:e0050c0b7da1eea53ffaf149c0cfbb5c6e2e2b69c4bef22c81fa6eb73e5f6173" + ], + "markers": "python_version >= '3.8'", + "version": "==2.2.0" + }, + "jinja2": { + "hashes": [ + "sha256:0137fb05990d35f1275a587e9aee6d56da821fc83491a0fb838183be43f66d6d", + "sha256:85ece4451f492d0c13c5dd7c13a64681a86afae63a5f347908daf103ce6d2f67" + ], + "markers": "python_version >= '3.7'", + "version": "==3.1.6" + }, + "jmespath": { + "hashes": [ + "sha256:472c87d80f36026ae83c6ddd0f1d05d4e510134ed462851fd5f754c8c3cbb88d", + "sha256:a5663118de4908c91729bea0acadca56526eb2698e83de10cd116ae0f4e97c64" + ], + "markers": "python_version >= '3.9'", + "version": "==1.1.0" + }, + "jsonpatch": { + "hashes": [ + "sha256:0ae28c0cd062bbd8b8ecc26d7d164fbbea9652a1a3693f3b956c1eae5145dade", + "sha256:9fcd4009c41e6d12348b4a0ff2563ba56a2923a7dfee731d004e212e1ee5030c" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6'", + "version": "==1.33" + }, + "jsonpointer": { + "hashes": [ + "sha256:0b801c7db33a904024f6004d526dcc53bbb8a4a0f4e32bfd10beadf60adf1900", + "sha256:8ff8b95779d071ba472cf5bc913028df06031797532f08a7d5b602d8b2a488ca" + ], + "markers": "python_version >= '3.10'", + "version": "==3.1.1" + }, + "jsonschema": { + "hashes": [ + "sha256:d71497fef26351a33265337fa77ffeb82423f3ea21283cd9467bb03999266bc4", + "sha256:fbadb6f8b144a8f8cf9f0b89ba94501d143e50411a1278633f56a7acf7fd5566" + ], + "markers": "python_version >= '3.8'", + "version": "==4.23.0" + }, + "jsonschema-specifications": { + "hashes": [ + "sha256:98802fee3a11ee76ecaca44429fda8a41bff98b00a0f2838151b113f210cc6fe", + "sha256:b540987f239e745613c7a9176f3edb72b832a4ac465cf02712288397832b5e8d" + ], + "markers": "python_version >= '3.9'", + "version": "==2025.9.1" + }, + "jwcrypto": { + "hashes": [ + "sha256:85aeb475f808d56bbc2f2ed1f6f73e6a317c4011a4321505f02f0aed695a3742", + "sha256:c3d7114b6f6e65b52f6b7da817eb8cb8423e1da31e1ef13508447c81ecbdcc34" + ], + "markers": "python_version >= '3.8'", + "version": "==1.5.8" + }, + "keystoneauth1": { + "hashes": [ + "sha256:9e2a4cf45cc2e2164093157091bc073eda1f334f755e8fab9fd25420c6f6acef", + "sha256:ce2cacdfd028e65bd23ff403d6572ebfab3b006d6d2dde3aa85c263675a9fbb5" + ], + "markers": "python_version >= '3.11'", + "version": "==5.15.0" + }, + "kingfisher-bin": { + "hashes": [ + "sha256:0a94abbf2154ef8a3b4845cc0240e2321cdc19e0f5c7f585ea5252e76b242f68", + "sha256:8e3840e67004a971fef80aba240ee5c3c5f7a3a343a6d1083a2751aaf866d5d3", + "sha256:a7774d9d11815ca946bd80b8c9df0f1d39c36cb5a21def3323b99d148dc63065", + "sha256:b838313411fa2166a318a45aec2cfcc238e2f30f5292e309ca1129a73180c851", + "sha256:f228d0dd61a738673b1c536e965a5661a83b1ee6ca64186a46ba6ea81ab4fd0b", + "sha256:f381274b946f7f68ed72911770fff72024f2192c6e2e2158f2a7fbfda8c482fb" + ], + "markers": "python_version >= '3.8'", + "version": "==1.104.0" + }, + "kubernetes": { + "hashes": [ + "sha256:35282ab8493b938b08ab5526c7ce66588232df00ef5e1dbe88a419107dc10998", + "sha256:42f43d49abd437ada79a79a16bd48a604d3471a117a8347e87db693f2ba0ba28" + ], + "markers": "python_version >= '3.6'", + "version": "==32.0.1" + }, + "linode-api4": { + "hashes": [ + "sha256:3cc2650b13d8d3bc7735fa8e92a639669618f320471dc8e519db778c6020eacd", + "sha256:af8a0a5638345ad467447112dcf5d58ec47e7dd192b89ce0c8537a1e5c435d04" + ], + "markers": "python_version >= '3.10'", + "version": "==5.45.0" + }, + "lz4": { + "hashes": [ + "sha256:0846e6e78f374156ccf21c631de80967e03cc3c01c373c665789dc0c5431e7fc", + "sha256:0bba042ec5a61fa77c7e380351a61cb768277801240249841defd2ff0a10742f", + "sha256:12233624f1bc2cebc414f9efb3113a03e89acce3ab6f72035577bc61b270d24d", + "sha256:13254bd78fef50105872989a2dc3418ff09aefc7d0765528adc21646a7288294", + "sha256:15551280f5656d2206b9b43262799c89b25a25460416ec554075a8dc568e4397", + "sha256:1dd4d91d25937c2441b9fc0f4af01704a2d09f30a38c5798bc1d1b5a15ec9581", + "sha256:214e37cfe270948ea7eb777229e211c601a3e0875541c1035ab408fbceaddf50", + "sha256:216ca0c6c90719731c64f41cfbd6f27a736d7e50a10b70fad2a9c9b262ec923d", + "sha256:24092635f47538b392c4eaeff14c7270d2c8e806bf4be2a6446a378591c5e69e", + "sha256:28ccaeb7c5222454cd5f60fcd152564205bcb801bd80e125949d2dfbadc76bbd", + "sha256:2a2b7504d2dffed3fd19d4085fe1cc30cf221263fd01030819bdd8d2bb101cf1", + "sha256:2c3ea562c3af274264444819ae9b14dbbf1ab070aff214a05e97db6896c7597e", + "sha256:33dd86cea8375d8e5dd001e41f321d0a4b1eb7985f39be1b6a4f466cd480b8a7", + "sha256:3b84a42da86e8ad8537aabef062e7f661f4a877d1c74d65606c49d835d36d668", + "sha256:451039b609b9a88a934800b5fc6ee401c89ad9c175abf2f4d9f8b2e4ef1afc64", + "sha256:533298d208b58b651662dd972f52d807d48915176e5b032fb4f8c3b6f5fe535c", + "sha256:5f0b9e53c1e82e88c10d7c180069363980136b9d7a8306c4dca4f760d60c39f0", + "sha256:609a69c68e7cfcfa9d894dc06be13f2e00761485b62df4e2472f1b66f7b405fb", + "sha256:61d0ee03e6c616f4a8b69987d03d514e8896c8b1b7cc7598ad029e5c6aedfd43", + "sha256:66c5de72bf4988e1b284ebdd6524c4bead2c507a2d7f172201572bac6f593901", + "sha256:67531da3b62f49c939e09d56492baf397175ff39926d0bd5bd2d191ac2bff95f", + "sha256:6bb05416444fafea170b07181bc70640975ecc2a8c92b3b658c554119519716c", + "sha256:6d0bf51e7745484d2092b3a51ae6eb58c3bd3ce0300cf2b2c14f76c536d5697a", + "sha256:713a777de88a73425cf08eb11f742cd2c98628e79a8673d6a52e3c5f0c116f33", + "sha256:75419bb1a559af00250b8f1360d508444e80ed4b26d9d40ec5b09fe7875cb989", + "sha256:7b62f94b523c251cf32aa4ab555f14d39bd1a9df385b72443fd76d7c7fb051f5", + "sha256:7c4e7c44b6a31de77d4dc9772b7d2561937c9588a734681f70ec547cfbc51ecd", + "sha256:7dc1e1e2dbd872f8fae529acd5e4839efd0b141eaa8ae7ce835a9fe80fbad89f", + "sha256:83bc23ef65b6ae44f3287c38cbf82c269e2e96a26e560aa551735883388dcc4b", + "sha256:8a842ead8ca7c0ee2f396ca5d878c4c40439a527ebad2b996b0444f0074ed004", + "sha256:92159782a4502858a21e0079d77cdcaade23e8a5d252ddf46b0652604300d7be", + "sha256:9b5e6abca8df9f9bdc5c3085f33ff32cdc86ed04c65e0355506d46a5ac19b6e9", + "sha256:a1acbbba9edbcbb982bc2cac5e7108f0f553aebac1040fbec67a011a45afa1ba", + "sha256:a2af2897333b421360fdcce895c6f6281dc3fab018d19d341cf64d043fc8d90d", + "sha256:a482eecc0b7829c89b498fda883dbd50e98153a116de612ee7c111c8bcf82d1d", + "sha256:a5f197ffa6fc0e93207b0af71b302e0a2f6f29982e5de0fbda61606dd3a55832", + "sha256:a88cbb729cc333334ccfb52f070463c21560fca63afcf636a9f160a55fac3301", + "sha256:b424df1076e40d4e884cfcc4c77d815368b7fb9ebcd7e634f937725cd9a8a72a", + "sha256:bd85d118316b53ed73956435bee1997bd06cc66dd2fa74073e3b1322bd520a67", + "sha256:c1cfa663468a189dab510ab231aad030970593f997746d7a324d40104db0d0a9", + "sha256:c216b6d5275fc060c6280936bb3bb0e0be6126afb08abccde27eed23dead135f", + "sha256:c8e71b14938082ebaf78144f3b3917ac715f72d14c076f384a4c062df96f9df6", + "sha256:cdd4bdcbaf35056086d910d219106f6a04e1ab0daa40ec0eeef1626c27d0fddb", + "sha256:d221fa421b389ab2345640a508db57da36947a437dfe31aeddb8d5c7b646c22d", + "sha256:d64141085864918392c3159cdad15b102a620a67975c786777874e1e90ef15ce", + "sha256:d6da84a26b3aa5da13a62e4b89ab36a396e9327de8cd48b436a3467077f8ccd4", + "sha256:d994b87abaa7a88ceb7a37c90f547b8284ff9da694e6afcfaa8568d739faf3f7", + "sha256:da68497f78953017deb20edff0dba95641cc86e7423dfadf7c0264e1ac60dc22", + "sha256:daffa4807ef54b927451208f5f85750c545a4abbff03d740835fc444cd97f758", + "sha256:df5aa4cead2044bab83e0ebae56e0944cc7fcc1505c7787e9e1057d6d549897e", + "sha256:e099ddfaa88f59dd8d36c8a3c66bd982b4984edf127eb18e30bb49bdba68ce67", + "sha256:e64e61f29cf95afb43549063d8433b46352baf0c8a70aa45e2585618fcf59d86", + "sha256:e928ec2d84dc8d13285b4a9288fd6246c5cde4f5f935b479f50d986911f085e3", + "sha256:f32b9e65d70f3684532358255dc053f143835c5f5991e28a5ac4c93ce94b9ea7", + "sha256:f6538aaaedd091d6e5abdaa19b99e6e82697d67518f114721b5248709b639fad", + "sha256:f9b8bde9909a010c75b3aea58ec3910393b758f3c219beed67063693df854db0", + "sha256:ff1b50aeeec64df5603f17984e4b5be6166058dcf8f1e26a3da40d7a0f6ab547" + ], + "markers": "python_version >= '3.9'", + "version": "==4.4.5" + }, + "markdown": { + "hashes": [ + "sha256:994d51325d25ad8aa7ce4ebaec003febcce822c3f8c911e3b17c52f7f589f950", + "sha256:e91464b71ae3ee7afd3017d9f358ef0baf158fd9a298db92f1d4761133824c36" + ], + "markers": "python_version >= '3.10'", + "version": "==3.10.2" + }, + "markupsafe": { + "hashes": [ + "sha256:0303439a41979d9e74d18ff5e2dd8c43ed6c6001fd40e5bf2e43f7bd9bbc523f", + "sha256:068f375c472b3e7acbe2d5318dea141359e6900156b5b2ba06a30b169086b91a", + "sha256:0bf2a864d67e76e5c9a34dc26ec616a66b9888e25e7b9460e1c76d3293bd9dbf", + "sha256:0db14f5dafddbb6d9208827849fad01f1a2609380add406671a26386cdf15a19", + "sha256:0eb9ff8191e8498cca014656ae6b8d61f39da5f95b488805da4bb029cccbfbaf", + "sha256:0f4b68347f8c5eab4a13419215bdfd7f8c9b19f2b25520968adfad23eb0ce60c", + "sha256:1085e7fbddd3be5f89cc898938f42c0b3c711fdcb37d75221de2666af647c175", + "sha256:116bb52f642a37c115f517494ea5feb03889e04df47eeff5b130b1808ce7c219", + "sha256:12c63dfb4a98206f045aa9563db46507995f7ef6d83b2f68eda65c307c6829eb", + "sha256:133a43e73a802c5562be9bbcd03d090aa5a1fe899db609c29e8c8d815c5f6de6", + "sha256:1353ef0c1b138e1907ae78e2f6c63ff67501122006b0f9abad68fda5f4ffc6ab", + "sha256:15d939a21d546304880945ca1ecb8a039db6b4dc49b2c5a400387cdae6a62e26", + "sha256:177b5253b2834fe3678cb4a5f0059808258584c559193998be2601324fdeafb1", + "sha256:1872df69a4de6aead3491198eaf13810b565bdbeec3ae2dc8780f14458ec73ce", + "sha256:1b4b79e8ebf6b55351f0d91fe80f893b4743f104bff22e90697db1590e47a218", + "sha256:1b52b4fb9df4eb9ae465f8d0c228a00624de2334f216f178a995ccdcf82c4634", + "sha256:1ba88449deb3de88bd40044603fafffb7bc2b055d626a330323a9ed736661695", + "sha256:1cc7ea17a6824959616c525620e387f6dd30fec8cb44f649e31712db02123dad", + "sha256:218551f6df4868a8d527e3062d0fb968682fe92054e89978594c28e642c43a73", + "sha256:26a5784ded40c9e318cfc2bdb30fe164bdb8665ded9cd64d500a34fb42067b1c", + "sha256:2713baf880df847f2bece4230d4d094280f4e67b1e813eec43b4c0e144a34ffe", + "sha256:2a15a08b17dd94c53a1da0438822d70ebcd13f8c3a95abe3a9ef9f11a94830aa", + "sha256:2f981d352f04553a7171b8e44369f2af4055f888dfb147d55e42d29e29e74559", + "sha256:32001d6a8fc98c8cb5c947787c5d08b0a50663d139f1305bac5885d98d9b40fa", + "sha256:3524b778fe5cfb3452a09d31e7b5adefeea8c5be1d43c4f810ba09f2ceb29d37", + "sha256:3537e01efc9d4dccdf77221fb1cb3b8e1a38d5428920e0657ce299b20324d758", + "sha256:35add3b638a5d900e807944a078b51922212fb3dedb01633a8defc4b01a3c85f", + "sha256:38664109c14ffc9e7437e86b4dceb442b0096dfe3541d7864d9cbe1da4cf36c8", + "sha256:3a7e8ae81ae39e62a41ec302f972ba6ae23a5c5396c8e60113e9066ef893da0d", + "sha256:3b562dd9e9ea93f13d53989d23a7e775fdfd1066c33494ff43f5418bc8c58a5c", + "sha256:457a69a9577064c05a97c41f4e65148652db078a3a509039e64d3467b9e7ef97", + "sha256:4bd4cd07944443f5a265608cc6aab442e4f74dff8088b0dfc8238647b8f6ae9a", + "sha256:4e885a3d1efa2eadc93c894a21770e4bc67899e3543680313b09f139e149ab19", + "sha256:4faffd047e07c38848ce017e8725090413cd80cbc23d86e55c587bf979e579c9", + "sha256:509fa21c6deb7a7a273d629cf5ec029bc209d1a51178615ddf718f5918992ab9", + "sha256:5678211cb9333a6468fb8d8be0305520aa073f50d17f089b5b4b477ea6e67fdc", + "sha256:591ae9f2a647529ca990bc681daebdd52c8791ff06c2bfa05b65163e28102ef2", + "sha256:5a7d5dc5140555cf21a6fefbdbf8723f06fcd2f63ef108f2854de715e4422cb4", + "sha256:69c0b73548bc525c8cb9a251cddf1931d1db4d2258e9599c28c07ef3580ef354", + "sha256:6b5420a1d9450023228968e7e6a9ce57f65d148ab56d2313fcd589eee96a7a50", + "sha256:722695808f4b6457b320fdc131280796bdceb04ab50fe1795cd540799ebe1698", + "sha256:729586769a26dbceff69f7a7dbbf59ab6572b99d94576a5592625d5b411576b9", + "sha256:77f0643abe7495da77fb436f50f8dab76dbc6e5fd25d39589a0f1fe6548bfa2b", + "sha256:795e7751525cae078558e679d646ae45574b47ed6e7771863fcc079a6171a0fc", + "sha256:7be7b61bb172e1ed687f1754f8e7484f1c8019780f6f6b0786e76bb01c2ae115", + "sha256:7c3fb7d25180895632e5d3148dbdc29ea38ccb7fd210aa27acbd1201a1902c6e", + "sha256:7e68f88e5b8799aa49c85cd116c932a1ac15caaa3f5db09087854d218359e485", + "sha256:83891d0e9fb81a825d9a6d61e3f07550ca70a076484292a70fde82c4b807286f", + "sha256:8485f406a96febb5140bfeca44a73e3ce5116b2501ac54fe953e488fb1d03b12", + "sha256:8709b08f4a89aa7586de0aadc8da56180242ee0ada3999749b183aa23df95025", + "sha256:8f71bc33915be5186016f675cd83a1e08523649b0e33efdb898db577ef5bb009", + "sha256:915c04ba3851909ce68ccc2b8e2cd691618c4dc4c4232fb7982bca3f41fd8c3d", + "sha256:949b8d66bc381ee8b007cd945914c721d9aba8e27f71959d750a46f7c282b20b", + "sha256:94c6f0bb423f739146aec64595853541634bde58b2135f27f61c1ffd1cd4d16a", + "sha256:9a1abfdc021a164803f4d485104931fb8f8c1efd55bc6b748d2f5774e78b62c5", + "sha256:9b79b7a16f7fedff2495d684f2b59b0457c3b493778c9eed31111be64d58279f", + "sha256:a320721ab5a1aba0a233739394eb907f8c8da5c98c9181d1161e77a0c8e36f2d", + "sha256:a4afe79fb3de0b7097d81da19090f4df4f8d3a2b3adaa8764138aac2e44f3af1", + "sha256:ad2cf8aa28b8c020ab2fc8287b0f823d0a7d8630784c31e9ee5edea20f406287", + "sha256:b8512a91625c9b3da6f127803b166b629725e68af71f8184ae7e7d54686a56d6", + "sha256:bc51efed119bc9cfdf792cdeaa4d67e8f6fcccab66ed4bfdd6bde3e59bfcbb2f", + "sha256:bdc919ead48f234740ad807933cdf545180bfbe9342c2bb451556db2ed958581", + "sha256:bdd37121970bfd8be76c5fb069c7751683bdf373db1ed6c010162b2a130248ed", + "sha256:be8813b57049a7dc738189df53d69395eba14fb99345e0a5994914a3864c8a4b", + "sha256:c0c0b3ade1c0b13b936d7970b1d37a57acde9199dc2aecc4c336773e1d86049c", + "sha256:c47a551199eb8eb2121d4f0f15ae0f923d31350ab9280078d1e5f12b249e0026", + "sha256:c4ffb7ebf07cfe8931028e3e4c85f0357459a3f9f9490886198848f4fa002ec8", + "sha256:ccfcd093f13f0f0b7fdd0f198b90053bf7b2f02a3927a30e63f3ccc9df56b676", + "sha256:d2ee202e79d8ed691ceebae8e0486bd9a2cd4794cec4824e1c99b6f5009502f6", + "sha256:d53197da72cc091b024dd97249dfc7794d6a56530370992a5e1a08983ad9230e", + "sha256:d6dd0be5b5b189d31db7cda48b91d7e0a9795f31430b7f271219ab30f1d3ac9d", + "sha256:d88b440e37a16e651bda4c7c2b930eb586fd15ca7406cb39e211fcff3bf3017d", + "sha256:de8a88e63464af587c950061a5e6a67d3632e36df62b986892331d4620a35c01", + "sha256:df2449253ef108a379b8b5d6b43f4b1a8e81a061d6537becd5582fba5f9196d7", + "sha256:e1c1493fb6e50ab01d20a22826e57520f1284df32f2d8601fdd90b6304601419", + "sha256:e1cf1972137e83c5d4c136c43ced9ac51d0e124706ee1c8aa8532c1287fa8795", + "sha256:e2103a929dfa2fcaf9bb4e7c091983a49c9ac3b19c9061b6d5427dd7d14d81a1", + "sha256:e56b7d45a839a697b5eb268c82a71bd8c7f6c94d6fd50c3d577fa39a9f1409f5", + "sha256:e8afc3f2ccfa24215f8cb28dcf43f0113ac3c37c2f0f0806d8c70e4228c5cf4d", + "sha256:e8fc20152abba6b83724d7ff268c249fa196d8259ff481f3b1476383f8f24e42", + "sha256:eaa9599de571d72e2daf60164784109f19978b327a3910d3e9de8c97b5b70cfe", + "sha256:ec15a59cf5af7be74194f7ab02d0f59a62bdcf1a537677ce67a2537c9b87fcda", + "sha256:f190daf01f13c72eac4efd5c430a8de82489d9cff23c364c3ea822545032993e", + "sha256:f34c41761022dd093b4b6896d4810782ffbabe30f2d443ff5f083e0cbbb8c737", + "sha256:f3e98bb3798ead92273dc0e5fd0f31ade220f59a266ffd8a4f6065e0a3ce0523", + "sha256:f42d0984e947b8adf7dd6dde396e720934d12c506ce84eea8476409563607591", + "sha256:f71a396b3bf33ecaa1626c255855702aca4d3d9fea5e051b41ac59a9c1c41edc", + "sha256:f9e130248f4462aaa8e2552d547f36ddadbeaa573879158d721bbd33dfe4743a", + "sha256:fed51ac40f757d41b7c48425901843666a6677e3e8eb0abcff09e4ba6e664f50" + ], + "markers": "python_version >= '3.9'", + "version": "==3.0.3" + }, + "microsoft-kiota-abstractions": { + "hashes": [ + "sha256:8eb62d64c35ad0eeb4e8bcdbb143c0b308dc4a494e757f8e44cb959d34f44ecf", + "sha256:cd169067ebe48e6feea1258630807034239e0c61c2abe5fd66896a58177e8f05" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-authentication-azure": { + "hashes": [ + "sha256:b5d98b0d17173c61c0c7ab4274ea4ca69253b3c13424137758034506694964e9", + "sha256:b9f10a9fa86e36114abfee448d2dab91a502d6a55d349a306e2e41a1218fe1ad" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-http": { + "hashes": [ + "sha256:6127032c8d94f8607e4d36d0822b88bc8689ab368b4c00d6c7beb7d2d0f2ab10", + "sha256:af1838d091f76426c974897357093ed977ce66f1d808cb161c190de873bb5833" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-serialization-form": { + "hashes": [ + "sha256:4c6655d8cd479d1ada63fdfe6a272e50d87d7c8369dbc8e13833ba4787fc798b", + "sha256:765d3f6408668f58bfdf892c32b45967c579d9131f3ba5a6b6868cb7ab956bfe" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-serialization-json": { + "hashes": [ + "sha256:0545ae910160b19caaa8c30c90c7416e1966294fbd6cc5af01f0e116a18f223a", + "sha256:6063028f30dd67afa2db20a72d9bde5e5d26d468f8bdedadd1445cf7c7630e17" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-serialization-multipart": { + "hashes": [ + "sha256:7cadc26483b567c738f926b044521569e0b797446053c9e8eab02269d4a81062", + "sha256:8f2da4f93e79b09f9738b6889685e47acfafcca870db94ab1d4cd233d69e4268" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "microsoft-kiota-serialization-text": { + "hashes": [ + "sha256:742890cfd4450d12f58d42da7cfa474fe1ee5d6442e016bf70ab76e5c876c0ea", + "sha256:cfc433c2a95ea3c3ec43c8b09002fbf65c998c5c0571205df161fe0e9d5d8de7" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.9.10" + }, + "msal": { + "hashes": [ + "sha256:1b1672a33ee467c1d70b341bb16cafd51bb3c817147a95b93263794b03971bec", + "sha256:dd17e95a7c71bce75e8108113438ba7c4a086b3bcad4f57a8c09b7af3d753c2d" + ], + "markers": "python_version >= '3.9'", + "version": "==1.37.0" + }, + "msal-extensions": { + "hashes": [ + "sha256:96d3de4d034504e969ac5e85bae8106c8373b5c6568e4c8fa7af2eca9dbe6bca", + "sha256:c5b0fd10f65ef62b5f1d62f4251d51cbcaf003fcedae8c91b040a488614be1a4" + ], + "markers": "python_version >= '3.9'", + "version": "==1.3.1" + }, + "msgraph-core": { + "hashes": [ + "sha256:6e883f9d4c4ad57501234749e07b010478c1a5f19550ef4cf005bbcac4a63ae7", + "sha256:86d83edcf62119946f201d13b7e857c947ef67addb088883940197081de85bea" + ], + "markers": "python_version >= '3.9'", + "version": "==1.3.8" + }, + "msgraph-sdk": { + "hashes": [ + "sha256:6df691a31954a050d26b8a678968017e157d940fb377f2a8a4e17a9741b98756", + "sha256:c8e68ebc4b88af5111de312e7fa910a4e76ddf48a4534feadb1fb8a411c48cfc" + ], + "markers": "python_version >= '3.9'", + "version": "==1.55.0" + }, + "msrest": { + "hashes": [ + "sha256:21120a810e1233e5e6cc7fe40b474eeb4ec6f757a15d7cf86702c369f9567c32", + "sha256:6e7661f46f3afd88b75667b7187a92829924446c7ea1d169be8c4bb7eeb788b9" + ], + "markers": "python_version >= '3.6'", + "version": "==0.7.1" + }, + "multidict": { + "hashes": [ + "sha256:026d264228bcd637d4e060844e39cdc60f86c479e463d49075dedc21b18fbbe0", + "sha256:03ede2a6ffbe8ef936b92cb4529f27f42be7f56afcdab5ab739cd5f27fb1cbf9", + "sha256:0458c978acd8e6ea53c81eefaddbbee9c6c5e591f41b3f5e8e194780fe026581", + "sha256:067343c68cd6612d375710f895337b3a98a033c94f14b9a99eff902f205424e2", + "sha256:08ccb2a6dc72009093ebe7f3f073e5ec5964cba9a706fa94b1a1484039b87941", + "sha256:0b38ebffd9be37c1170d33bc0f36f4f262e0a09bc1aac1c34c7aa51a7293f0b3", + "sha256:0b4c48648d7649c9335cf1927a8b87fa692de3dcb15faa676c6a6f1f1aabda43", + "sha256:0d17522c37d03e85c8098ec8431636309b2682cf12e58f4dbc76121fb50e4962", + "sha256:0e161ddf326db5577c3a4cc2d8648f81456e8a20d40415541587a71620d7a7d1", + "sha256:0e697826df7eb63418ee190fd06ce9f1803593bb4b9517d08c60d9b9a7f69d8f", + "sha256:10ae39c9cfe6adedcdb764f5e8411d4a92b055e35573a2eaa88d3323289ef93c", + "sha256:121a34e5bfa410cdf2c8c49716de160de3b1dbcd86b49656f5681e4543bcd1a8", + "sha256:128441d052254f42989ef98b7b6a6ecb1e6f708aa962c7984235316db59f50fa", + "sha256:12fad252f8b267cc75b66e8fc51b3079604e8d43a75428ffe193cd9e2195dfd6", + "sha256:14525a5f61d7d0c94b368a42cff4c9a4e7ba2d52e2672a7b23d84dc86fb02b0c", + "sha256:17207077e29342fdc2c9a82e4b306f1127bf1ea91f8b71e02d4798a70bb99991", + "sha256:17307b22c217b4cf05033dabefe68255a534d637c6c9b0cc8382718f87be4262", + "sha256:1b99af4d9eec0b49927b4402bcbb58dea89d3e0db8806a4086117019939ad3dd", + "sha256:1d540e51b7e8e170174555edecddbd5538105443754539193e3e1061864d444d", + "sha256:1e3a8bb24342a8201d178c3b4984c26ba81a577c80d4d525727427460a50c22d", + "sha256:1fa6609d0364f4f6f58351b4659a1f3e0e898ba2a8c5cac04cb2c7bc556b0bc5", + "sha256:21f830fe223215dffd51f538e78c172ed7c7f60c9b96a2bf05c4848ad49921c3", + "sha256:233b398c29d3f1b9676b4b6f75c518a06fcb2ea0b925119fb2c1bc35c05e1601", + "sha256:24c0cf81544ca5e17cfcb6e482e7a82cd475925242b308b890c9452a074d4505", + "sha256:25167cc263257660290fba06b9318d2026e3c910be240a146e1f66dd114af2b0", + "sha256:253282d70d67885a15c8a7716f3a73edf2d635793ceda8173b9ecc21f2fb8292", + "sha256:273d23f4b40f3dce4d6c8a821c741a86dec62cded82e1175ba3d99be128147ed", + "sha256:283ddac99f7ac25a4acadbf004cb5ae34480bbeb063520f70ce397b281859362", + "sha256:28ca5ce2fd9716631133d0e9a9b9a745ad7f60bac2bccafb56aa380fc0b6c511", + "sha256:2b41f5fed0ed563624f1c17630cb9941cf2309d4df00e494b551b5f3e3d67a23", + "sha256:2bbd113e0d4af5db41d5ebfe9ccaff89de2120578164f86a5d17d5a576d1e5b2", + "sha256:2e1425e2f99ec5bd36c15a01b690a1a2456209c5deed58f95469ffb46039ccbb", + "sha256:2e2d2ed645ea29f31c4c7ea1552fcfd7cb7ba656e1eafd4134a6620c9f5fdd9e", + "sha256:3758692429e4e32f1ba0df23219cd0b4fc0a52f476726fff9337d1a57676a582", + "sha256:38fb49540705369bab8484db0689d86c0a33a0a9f2c1b197f506b71b4b6c19b0", + "sha256:3943debf0fbb57bdde5901695c11094a9a36723e5c03875f87718ee15ca2f4d2", + "sha256:398c1478926eca669f2fd6a5856b6de9c0acf23a2cb59a14c0ba5844fa38077e", + "sha256:3ab8b9d8b75aef9df299595d5388b14530839f6422333357af1339443cff777d", + "sha256:3bd231490fa7217cc832528e1cd8752a96f0125ddd2b5749390f7c3ec8721b65", + "sha256:3d51ff4785d58d3f6c91bdbffcb5e1f7ddfda557727043aa20d20ec4f65e324a", + "sha256:3fccb473e87eaa1382689053e4a4618e7ba7b9b9b8d6adf2027ee474597128cd", + "sha256:401c5a650f3add2472d1d288c26deebc540f99e2fb83e9525007a74cd2116f1d", + "sha256:41f2952231456154ee479651491e94118229844dd7226541788be783be2b5108", + "sha256:432feb25a1cb67fe82a9680b4d65fb542e4635cb3166cd9c01560651ad60f177", + "sha256:439cbebd499f92e9aa6793016a8acaa161dfa749ae86d20960189f5398a19144", + "sha256:4885cb0e817aef5d00a2e8451d4665c1808378dc27c2705f1bf4ef8505c0d2e5", + "sha256:497394b3239fc6f0e13a78a3e1b61296e72bf1c5f94b4c4eb80b265c37a131cd", + "sha256:497bde6223c212ba11d462853cfa4f0ae6ef97465033e7dc9940cdb3ab5b48e5", + "sha256:4cfb48c6ea66c83bcaaf7e4dfa7ec1b6bbcf751b7db85a328902796dfde4c060", + "sha256:538cec1e18c067d0e6103aa9a74f9e832904c957adc260e61cd9d8cf0c3b3d37", + "sha256:55d97cc6dae627efa6a6e548885712d4864b81110ac76fa4e534c03819fa4a56", + "sha256:563fe25c678aaba333d5399408f5ec3c383ca5b663e7f774dd179a520b8144df", + "sha256:57b46b24b5d5ebcc978da4ec23a819a9402b4228b8a90d9c656422b4bdd8a963", + "sha256:5884a04f4ff56c6120f6ccf703bdeb8b5079d808ba604d4d53aec0d55dc33568", + "sha256:59bc83d3f66b41dac1e7460aac1d196edc70c9ba3094965c467715a70ecb46db", + "sha256:5a37ca18e360377cfda1d62f5f382ff41f2b8c4ccb329ed974cc2e1643440118", + "sha256:5c4b9bfc148f5a91be9244d6264c53035c8a0dcd2f51f1c3c6e30e30ebaa1c84", + "sha256:5e01429a929600e7dab7b166062d9bb54a5eed752384c7384c968c2afab8f50f", + "sha256:5fa6a95dfee63893d80a34758cd0e0c118a30b8dcb46372bf75106c591b77889", + "sha256:619e5a1ac57986dbfec9f0b301d865dddf763696435e2962f6d9cf2fdff2bb71", + "sha256:65573858d27cdeaca41893185677dc82395159aa28875a8867af66532d413a8f", + "sha256:6704fa2b7453b2fb121740555fa1ee20cd98c4d011120caf4d2b8d4e7c76eec0", + "sha256:6aac4f16b472d5b7dc6f66a0d49dd57b0e0902090be16594dc9ebfd3d17c47e7", + "sha256:6b10359683bd8806a200fd2909e7c8ca3a7b24ec1d8132e483d58e791d881048", + "sha256:6b83cabdc375ffaaa15edd97eb7c0c672ad788e2687004990074d7d6c9b140c8", + "sha256:6d3bc717b6fe763b8be3f2bee2701d3c8eb1b2a8ae9f60910f1b2860c82b6c49", + "sha256:6f77ce314a29263e67adadc7e7c1bc699fcb3a305059ab973d038f87caa42ed0", + "sha256:749aa54f578f2e5f439538706a475aa844bfa8ef75854b1401e6e528e4937cf9", + "sha256:7a7e590ff876a3eaf1c02a4dfe0724b6e69a9e9de6d8f556816f29c496046e59", + "sha256:7dfb78d966b2c906ae1d28ccf6e6712a3cd04407ee5088cd276fe8cb42186190", + "sha256:7eee46ccb30ff48a1e35bb818cc90846c6be2b68240e42a78599166722cea709", + "sha256:7ff981b266af91d7b4b3793ca3382e53229088d193a85dfad6f5f4c27fc73e5d", + "sha256:841189848ba629c3552035a6a7f5bf3b02eb304e9fea7492ca220a8eda6b0e5c", + "sha256:844c5bca0b5444adb44a623fb0a1310c2f4cd41f402126bb269cd44c9b3f3e1e", + "sha256:84e61e3af5463c19b67ced91f6c634effb89ef8bfc5ca0267f954451ed4bb6a2", + "sha256:8affcf1c98b82bc901702eb73b6947a1bfa170823c153fe8a47b5f5f02e48e40", + "sha256:8be1802715a8e892c784c0197c2ace276ea52702a0ede98b6310c8f255a5afb3", + "sha256:8f333ec9c5eb1b7105e3b84b53141e66ca05a19a605368c55450b6ba208cb9ee", + "sha256:9004d8386d133b7e6135679424c91b0b854d2d164af6ea3f289f8f2761064609", + "sha256:90efbcf47dbe33dcf643a1e400d67d59abeac5db07dc3f27d6bdeae497a2198c", + "sha256:935434b9853c7c112eee7ac891bc4cb86455aa631269ae35442cb316790c1445", + "sha256:93b1818e4a6e0930454f0f2af7dfce69307ca03cdcfb3739bf4d91241967b6c1", + "sha256:95922cee9a778659e91db6497596435777bd25ed116701a4c034f8e46544955a", + "sha256:960c83bf01a95b12b08fd54324a4eb1d5b52c88932b5cba5d6e712bb3ed12eb5", + "sha256:97231140a50f5d447d3164f994b86a0bed7cd016e2682f8650d6a9158e14fd31", + "sha256:974e72a2474600827abaeda71af0c53d9ebbc3c2eb7da37b37d7829ae31232d8", + "sha256:97891f3b1b3ffbded884e2916cacf3c6fc87b66bb0dde46f7357404750559f33", + "sha256:98655c737850c064a65e006a3df7c997cd3b220be4ec8fe26215760b9697d4d7", + "sha256:98bc624954ec4d2c7cb074b8eefc2b5d0ce7d482e410df446414355d158fe4ca", + "sha256:98c5787b0a0d9a41d9311eae44c3b76e6753def8d8870ab501320efe75a6a5f8", + "sha256:9b0d9b91d1aa44db9c1f1ecd0d9d2ae610b2f4f856448664e01a3b35899f3f92", + "sha256:9c90fed18bffc0189ba814749fdcc102b536e83a9f738a9003e569acd540a733", + "sha256:9d624335fd4fa1c08a53f8b4be7676ebde19cd092b3895c421045ca87895b429", + "sha256:9f9af11306994335398293f9958071019e3ab95e9a707dc1383a35613f6abcb9", + "sha256:a0543217a6a017692aa6ae5cc39adb75e587af0f3a82288b1492eb73dd6cc2a4", + "sha256:a088b62bd733e2ad12c50dad01b7d0166c30287c166e137433d3b410add807a6", + "sha256:a407f13c188f804c759fc6a9f88286a565c242a76b27626594c133b82883b5c2", + "sha256:a90f75c956e32891a4eda3639ce6dd86e87105271f43d43442a3aedf3cddf172", + "sha256:a9fc4caa29e2e6ae408d1c450ac8bf19892c5fca83ee634ecd88a53332c59981", + "sha256:aa23b001d968faef416ff70dc0f1ab045517b9b42a90edd3e9bcdb06479e31d5", + "sha256:ac1c665bad8b5d762f5f85ebe4d94130c26965f11de70c708c75671297c776de", + "sha256:af959b9beeb66c822380f222f0e0a1889331597e81f1ded7f374f3ecb0fd6c52", + "sha256:b0fa96985700739c4c7853a43c0b3e169360d6855780021bfc6d0f1ce7c123e7", + "sha256:b26684587228afed0d50cf804cc71062cc9c1cdf55051c4c6345d372947b268c", + "sha256:b4938326284c4f1224178a560987b6cf8b4d38458b113d9b8c1db1a836e640a2", + "sha256:b8c990b037d2fff2f4e33d3f21b9b531c5745b33a49a7d6dbe7a177266af44f6", + "sha256:ba0a9fb644d0c1a2194cf7ffb043bd852cea63a57f66fbd33959f7dae18517bf", + "sha256:bb08271280173720e9fea9ede98e5231defcbad90f1624bea26f32ec8a956e2f", + "sha256:bdbf9f3b332abd0cdb306e7c2113818ab1e922dc84b8f8fd06ec89ed2a19ab8b", + "sha256:bfde23ef6ed9db7eaee6c37dcec08524cb43903c60b285b172b6c094711b3961", + "sha256:c0abd12629b0af3cf590982c0b413b1e7395cd4ec026f30986818ab95bfaa94a", + "sha256:c102791b1c4f3ab36ce4101154549105a53dc828f016356b3e3bcae2e3a039d3", + "sha256:c3a32d23520ee37bf327d1e1a656fec76a2edd5c038bf43eddfa0572ec49c60b", + "sha256:c524c6fb8fc342793708ab111c4dbc90ff9abd568de220432500e47e990c0358", + "sha256:c5f0c21549ab432b57dcc82130f388d84ad8179824cc3f223d5e7cfbfd4143f6", + "sha256:c6b3228e1d80af737b72925ce5fb4daf5a335e49cd7ab77ed7b9fdfbf58c526e", + "sha256:c76c4bec1538375dad9d452d246ca5368ad6e1c9039dadcf007ae59c70619ea1", + "sha256:c9035dde0f916702850ef66460bc4239d89d08df4d02023a5926e7446724212c", + "sha256:c93c3db7ea657dd4637d57e74ab73de31bccefe144d3d4ce370052035bc85fb5", + "sha256:cb2a55f408c3043e42b40cc8eecd575afa27b7e0b956dfb190de0f8499a57a53", + "sha256:cdea2e7b2456cfb6694fb113066fd0ec7ea4d67e3a35e1f4cbeea0b448bf5872", + "sha256:ce1bbd7d780bb5a0da032e095c951f7014d6b0a205f8318308140f1a6aba159e", + "sha256:cf37cbe5ced48d417ba045aca1b21bafca67489452debcde94778a576666a1df", + "sha256:d4f49cb5661344764e4c7c7973e92a47a59b8fc19b6523649ec9dc4960e58a03", + "sha256:d54ecf9f301853f2c5e802da559604b3e95bb7a3b01a9c295c6ee591b9882de8", + "sha256:d62b7f64ffde3b99d06b707a280db04fb3855b55f5a06df387236051d0668f4a", + "sha256:d82dd730a95e6643802f4454b8fdecdf08667881a9c5670db85bc5a56693f122", + "sha256:da62917e6076f512daccfbbde27f46fed1c98fee202f0559adec8ee0de67f71a", + "sha256:dd96c01a9dcd4889dcfcf9eb5544ca0c77603f239e3ffab0524ec17aea9a93ee", + "sha256:df9f19c28adcb40b6aae30bbaa1478c389efd50c28d541d76760199fc1037c32", + "sha256:e1c5988359516095535c4301af38d8a8838534158f649c05dd1050222321bcb3", + "sha256:e628ef0e6859ffd8273c69412a2465c4be4a9517d07261b33334b5ec6f3c7489", + "sha256:e82d14e3c948952a1a85503817e038cba5905a3352de76b9a465075d072fba23", + "sha256:e954b24433c768ce78ab7929e84ccf3422e46deb45a4dc9f93438f8217fa2d34", + "sha256:eb0ce7b2a32d09892b3dd6cc44877a0d02a33241fafca5f25c8b6b62374f8b75", + "sha256:eb304767bca2bb92fb9c5bd33cedc95baee5bb5f6c88e63706533a1c06ad08c8", + "sha256:eb351f72c26dc9abe338ca7294661aa22969ad8ffe7ef7d5541d19f368dc854a", + "sha256:ec6652a1bee61c53a3e5776b6049172c53b6aaba34f18c9ad04f82712bac623d", + "sha256:f2a0a924d4c2e9afcd7ec64f9de35fcd96915149b2216e1cb2c10a56df483855", + "sha256:f33dc2a3abe9249ea5d8360f969ec7f4142e7ac45ee7014d8f8d5acddf178b7b", + "sha256:f537b55778cd3cbee430abe3131255d3a78202e0f9ea7ffc6ada893a4bcaeea4", + "sha256:f5dd81c45b05518b9aa4da4aa74e1c93d715efa234fd3e8a179df611cc85e5f4", + "sha256:f99fe611c312b3c1c0ace793f92464d8cd263cc3b26b5721950d977b006b6c4d", + "sha256:fa263a02f4f2dd2d11a7b1bb4362aa7cb1049f84a9235d31adf63f30143469a0", + "sha256:fc5907494fccf3e7d3f94f95c91d6336b092b5fc83811720fae5e2765890dfba", + "sha256:fcee94dfbd638784645b066074b338bc9cc155d4b4bffa4adce1615c5a426c19" + ], + "markers": "python_version >= '3.9'", + "version": "==6.7.1" + }, + "narwhals": { + "hashes": [ + "sha256:42fdedf44e5b2ca7505630d45b4ac3058f38d8485cba9fe1652ca23152df7489", + "sha256:b5c0f684ccd9d7475b564111e319a4964abcf2baf79d3cf6b1003d06ac9b828d" + ], + "markers": "python_version >= '3.10'", + "version": "==2.24.0" + }, + "nest-asyncio": { + "hashes": [ + "sha256:6f172d5449aca15afd6c646851f4e31e02c598d553a667e38cafa997cfec55fe", + "sha256:87af6efd6b5e897c81050477ef65c62e2b2f35d51703cae01aff2905b1852e1c" + ], + "markers": "python_version >= '3.5'", + "version": "==1.6.0" + }, + "numpy": { + "hashes": [ + "sha256:038613e9fb8c72b0a41f025a7e4c3f0b7a1b5d768ece4796b674c8f3fe13efff", + "sha256:0678000bb9ac1475cd454c6b8c799206af8107e310843532b04d49649c717a47", + "sha256:0811bb762109d9708cca4d0b13c4f67146e3c3b7cf8d34018c722adb2d957c84", + "sha256:0b605b275d7bd0c640cad4e5d30fa701a8d59302e127e5f79138ad62762c3e3d", + "sha256:0bca768cd85ae743b2affdc762d617eddf3bcf8724435498a1e80132d04879e6", + "sha256:1bc23a79bfabc5d056d106f9befb8d50c31ced2fbc70eedb8155aec74a45798f", + "sha256:287cc3162b6f01463ccd86be154f284d0893d2b3ed7292439ea97eafa8170e0b", + "sha256:37c0ca431f82cd5fa716eca9506aefcabc247fb27ba69c5062a6d3ade8cf8f49", + "sha256:37e990a01ae6ec7fe7fa1c26c55ecb672dd98b19c3d0e1d1f326fa13cb38d163", + "sha256:389d771b1623ec92636b0786bc4ae56abafad4a4c513d36a55dce14bd9ce8571", + "sha256:3d70692235e759f260c3d837193090014aebdf026dfd167834bcba43e30c2a42", + "sha256:41c5a21f4a04fa86436124d388f6ed60a9343a6f767fced1a8a71c3fbca038ff", + "sha256:481b49095335f8eed42e39e8041327c05b0f6f4780488f61286ed3c01368d491", + "sha256:4eeaae00d789f66c7a25ac5f34b71a7035bb474e679f410e5e1a94deb24cf2d4", + "sha256:55a4d33fa519660d69614a9fad433be87e5252f4b03850642f88993f7b2ca566", + "sha256:5a6429d4be8ca66d889b7cf70f536a397dc45ba6faeb5f8c5427935d9592e9cf", + "sha256:5bd4fc3ac8926b3819797a7c0e2631eb889b4118a9898c84f585a54d475b7e40", + "sha256:5beb72339d9d4fa36522fc63802f469b13cdbe4fdab4a288f0c441b74272ebfd", + "sha256:6031dd6dfecc0cf9f668681a37648373bddd6421fff6c66ec1624eed0180ee06", + "sha256:71594f7c51a18e728451bb50cc60a3ce4e6538822731b2933209a1f3614e9282", + "sha256:74d4531beb257d2c3f4b261bfb0fc09e0f9ebb8842d82a7b4209415896adc680", + "sha256:7befc596a7dc9da8a337f79802ee8adb30a552a94f792b9c9d18c840055907db", + "sha256:894b3a42502226a1cac872f840030665f33326fc3dac8e57c607905773cdcde3", + "sha256:8e41fd67c52b86603a91c1a505ebaef50b3314de0213461c7a6e99c9a3beff90", + "sha256:8e9ace4a37db23421249ed236fdcdd457d671e25146786dfc96835cd951aa7c1", + "sha256:8fc377d995680230e83241d8a96def29f204b5782f371c532579b4f20607a289", + "sha256:9551a499bf125c1d4f9e250377c1ee2eddd02e01eac6644c080162c0c51778ab", + "sha256:b0544343a702fa80c95ad5d3d608ea3599dd54d4632df855e4c8d24eb6ecfa1c", + "sha256:b093dd74e50a8cba3e873868d9e93a85b78e0daf2e98c6797566ad8044e8363d", + "sha256:b412caa66f72040e6d268491a59f2c43bf03eb6c96dd8f0307829feb7fa2b6fb", + "sha256:b4f13750ce79751586ae2eb824ba7e1e8dba64784086c98cdbbcc6a42112ce0d", + "sha256:b64d8d4d17135e00c8e346e0a738deb17e754230d7e0810ac5012750bbd85a5a", + "sha256:ba10f8411898fc418a521833e014a77d3ca01c15b0c6cdcce6a0d2897e6dbbdf", + "sha256:bd48227a919f1bafbdda0583705e547892342c26fb127219d60a5c36882609d1", + "sha256:c1f9540be57940698ed329904db803cf7a402f3fc200bfe599334c9bd84a40b2", + "sha256:c820a93b0255bc360f53eca31a0e676fd1101f673dda8da93454a12e23fc5f7a", + "sha256:ce47521a4754c8f4593837384bd3424880629f718d87c5d44f8ed763edd63543", + "sha256:d042d24c90c41b54fd506da306759e06e568864df8ec17ccc17e9e884634fd00", + "sha256:de749064336d37e340f640b05f24e9e3dd678c57318c7289d222a8a2f543e90c", + "sha256:e1dda9c7e08dc141e0247a5b8f49cf05984955246a327d4c48bda16821947b2f", + "sha256:e29554e2bef54a90aa5cc07da6ce955accb83f21ab5de01a62c8478897b264fd", + "sha256:e3143e4451880bed956e706a3220b4e5cf6172ef05fcc397f6f36a550b1dd868", + "sha256:e8213002e427c69c45a52bbd94163084025f533a55a59d6f9c5b820774ef3303", + "sha256:efd28d4e9cd7d7a8d39074a4d44c63eda73401580c5c76acda2ce969e0a38e83", + "sha256:f0fd6321b839904e15c46e0d257fdd101dd7f530fe03fd6359c1ea63738703f3", + "sha256:f1372f041402e37e5e633e586f62aa53de2eac8d98cbfb822806ce4bbefcb74d", + "sha256:f2618db89be1b4e05f7a1a847a9c1c0abd63e63a1607d892dd54668dd92faf87", + "sha256:f447e6acb680fd307f40d3da4852208af94afdfab89cf850986c3ca00562f4fa", + "sha256:f92729c95468a2f4f15e9bb94c432a9229d0d50de67304399627a943201baa2f", + "sha256:f9f1adb22318e121c5c69a09142811a201ef17ab257a1e66ca3025065b7f53ae", + "sha256:fc0c5673685c508a142ca65209b4e79ed6740a4ed6b2267dbba90f34b0b3cfda", + "sha256:fc7b73d02efb0e18c000e9ad8b83480dfcd5dfd11065997ed4c6747470ae8915", + "sha256:fd83c01228a688733f1ded5201c678f0c53ecc1006ffbc404db9f7a899ac6249", + "sha256:fe27749d33bb772c80dcd84ae7e8df2adc920ae8297400dabec45f0dedb3f6de", + "sha256:fee4236c876c4e8369388054d02d0e9bb84821feb1a64dd59e137e6511a551f8" + ], + "markers": "python_version >= '3.10'", + "version": "==2.2.6" + }, + "oauthlib": { + "hashes": [ + "sha256:0f0f8aa759826a193cf66c12ea1af1637f87b9b4622d46e866952bb022e538c9", + "sha256:88119c938d2b8fb88561af5f6ee0eec8cc8d552b7bb1f712743136eb7523b7a1" + ], + "markers": "python_version >= '3.8'", + "version": "==3.3.1" + }, + "oci": { + "hashes": [ + "sha256:617dad69caf8dd6e521d224dbc3e8a8bc289906943a0214fd2c3419094e26435", + "sha256:bd814e38a70da2190e721937455a08689ab13c0750bd2ef8dd0c98b2dc5a38ea" + ], + "version": "==2.184.1" + }, + "okta": { + "hashes": [ + "sha256:b05201056f3f028c5d2d16394f9b47024a689080f5a993c11d4d80f0e1b5ba1e", + "sha256:b67bcff31de65223c5848894a202153236d0c99e3a8541a54bf7065f81676637" + ], + "markers": "python_version >= '3.10'", + "version": "==3.4.2" + }, + "openstacksdk": { + "hashes": [ + "sha256:238be0fa5d9899872b00787ab38e84f92fd6dc87525fde0965dadcdc12196dc6", + "sha256:5cb9450dcce8054a2caf89d8be9e55057ddfa219a954e781032241eb29280445" + ], + "markers": "python_version >= '3.9'", + "version": "==4.2.0" + }, + "opentelemetry-api": { + "hashes": [ + "sha256:67647e5e9566edcf421166fdf022b3537f818635daa852b289e34604dc6fb33a", + "sha256:94b98c893a91b88657eaac1e3ba89618cdb85be6918196705354f34728b2cdef" + ], + "markers": "python_version >= '3.10'", + "version": "==1.44.0" + }, + "opentelemetry-sdk": { + "hashes": [ + "sha256:cebe7f65dc12f26ead75c6064de12fd2a9052e5060c0272d402cfa203aae123b", + "sha256:df081c4c6bcfdb1211e3e86140376792643128a25f8d72d1d27675936e7e96ad" + ], + "markers": "python_version >= '3.10'", + "version": "==1.44.0" + }, + "opentelemetry-semantic-conventions": { + "hashes": [ + "sha256:1cacde7b0ad306f84c5ef08c3dbe1bbaf20165bba6f8bff43b670e555a086bcb", + "sha256:f9b2b81e9d5b64f11bc952075e7e9c7fb0aab075c7fd1c46d597f1b919852d60" + ], + "markers": "python_version >= '3.10'", + "version": "==0.65b0" + }, + "os-service-types": { + "hashes": [ + "sha256:1f2e5fb71d1f6f4ff31d8992674f2368465bc2f25cd94018015c3ddbfc5c617f", + "sha256:f268545c896434177bf55c43f7d5129e65210d5d456df3f00a1c9832a71c3a4b" + ], + "markers": "python_version >= '3.11'", + "version": "==1.9.0" + }, + "packaging": { + "hashes": [ + "sha256:94edc256424af38762eb31306eed28beb9f0efc50a8837492c9d6fd6004aed79", + "sha256:d7193f7c8e4e93f444fde0262bf90af30e16fa0ad0ad44cb553c87339b23cd1c" + ], + "markers": "python_version >= '3.9'", + "version": "==26.3" + }, + "pandas": { + "hashes": [ + "sha256:062309c1b9ea12a50e8ce661145c6aab431b1e99530d3cd60640e255778bd43a", + "sha256:15c0e1e02e93116177d29ff83e8b1619c93ddc9c49083f237d4312337a61165d", + "sha256:1948ddde24197a0f7add2bdc4ca83bf2b1ef84a1bc8ccffd95eda17fd836ecb5", + "sha256:1db71525a1538b30142094edb9adc10be3f3e176748cd7acc2240c2f2e5aa3a4", + "sha256:22a9d949bfc9a502d320aa04e5d02feab689d61da4e7764b62c30b991c42c5f0", + "sha256:29401dbfa9ad77319367d36940cd8a0b3a11aba16063e39632d98b0e931ddf32", + "sha256:31d0ced62d4ea3e231a9f228366919a5ea0b07440d9d4dac345376fd8e1477ea", + "sha256:3508d914817e153ad359d7e069d752cdd736a247c322d932eb89e6bc84217f28", + "sha256:37e0aced3e8f539eccf2e099f65cdb9c8aa85109b0be6e93e2baff94264bdc6f", + "sha256:381175499d3802cde0eabbaf6324cce0c4f5d52ca6f8c377c29ad442f50f6348", + "sha256:38cf8125c40dae9d5acc10fa66af8ea6fdf760b2714ee482ca691fc66e6fcb18", + "sha256:3b71f27954685ee685317063bf13c7709a7ba74fc996b84fc6821c59b0f06468", + "sha256:3fc6873a41186404dad67245896a6e440baacc92f5b716ccd1bc9ed2995ab2c5", + "sha256:4850ba03528b6dd51d6c5d273c46f183f39a9baf3f0143e566b89450965b105e", + "sha256:4f18ba62b61d7e192368b84517265a99b4d7ee8912f8708660fb4a366cc82667", + "sha256:56534ce0746a58afaf7942ba4863e0ef81c9c50d3f0ae93e9497d6a41a057645", + "sha256:59ef3764d0fe818125a5097d2ae867ca3fa64df032331b7e0917cf5d7bf66b13", + "sha256:5dbca4c1acd72e8eeef4753eeca07de9b1db4f398669d5994086f788a5d7cc30", + "sha256:5de54125a92bb4d1c051c0659e6fcb75256bf799a732a87184e5ea503965bce3", + "sha256:61c5ad4043f791b61dd4752191d9f07f0ae412515d59ba8f005832a532f8736d", + "sha256:6374c452ff3ec675a8f46fd9ab25c4ad0ba590b71cf0656f8b6daa5202bca3fb", + "sha256:63cc132e40a2e084cf01adf0775b15ac515ba905d7dcca47e9a251819c575ef3", + "sha256:66108071e1b935240e74525006034333f98bcdb87ea116de573a6a0dccb6c039", + "sha256:6dfcb5ee8d4d50c06a51c2fffa6cff6272098ad6540aed1a76d15fb9318194d8", + "sha256:7c2875855b0ff77b2a64a0365e24455d9990730d6431b9e0ee18ad8acee13dbd", + "sha256:7eee9e7cea6adf3e3d24e304ac6b8300646e2a5d1cd3a3c2abed9101b0846761", + "sha256:800250ecdadb6d9c78eae4990da62743b857b470883fa27f652db8bdde7f6659", + "sha256:86976a1c5b25ae3f8ccae3a5306e443569ee3c3faf444dfd0f41cda24667ad57", + "sha256:8cd6d7cc958a3910f934ea8dbdf17b2364827bb4dafc38ce6eef6bb3d65ff09c", + "sha256:99df71520d25fade9db7c1076ac94eb994f4d2673ef2aa2e86ee039b6746d20c", + "sha256:a5a1595fe639f5988ba6a8e5bc9649af3baf26df3998a0abe56c02609392e0a4", + "sha256:ad5b65698ab28ed8d7f18790a0dc58005c7629f227be9ecc1072aa74c0c1d43a", + "sha256:b1d432e8d08679a40e2a6d8b2f9770a5c21793a6f9f47fdd52c5ce1948a5a8a9", + "sha256:b8661b0238a69d7aafe156b7fa86c44b881387509653fdf857bebc5e4008ad42", + "sha256:ba96630bc17c875161df3818780af30e43be9b166ce51c9a18c1feae342906c2", + "sha256:bc6b93f9b966093cb0fd62ff1a7e4c09e6d546ad7c1de191767baffc57628f39", + "sha256:c124333816c3a9b03fbeef3a9f230ba9a737e9e5bb4060aa2107a86cc0a497fc", + "sha256:cd8d0c3be0515c12fed0bdbae072551c8b54b7192c7b1fda0ba56059a0179698", + "sha256:d9c45366def9a3dd85a6454c0e7908f2b3b8e9c138f5dc38fed7ce720d8453ed", + "sha256:f00d1345d84d8c86a63e476bb4955e46458b304b9575dcf71102b5c705320015", + "sha256:f3a255b2c19987fbbe62a9dfd6cff7ff2aa9ccab3fc75218fd4b7530f01efa24", + "sha256:fffb8ae78d8af97f849404f21411c95062db1496aeb3e56f146f0355c9989319" + ], + "markers": "python_version >= '3.9'", + "version": "==2.2.3" + }, + "pbr": { + "hashes": [ + "sha256:b46004ec30a5324672683ec848aed9e8fc500b0d261d40a3229c2d2bbfcedc29", + "sha256:ff223894eb1cd271a98076b13d3badff3bb36c424074d26334cd25aebeecea6b" + ], + "markers": "python_version >= '2.6'", + "version": "==7.0.3" + }, + "platformdirs": { + "hashes": [ + "sha256:5ed065d443751de711da036041a7a214122efc4a4de393b3f4137ba5576540e7", + "sha256:66a73d38a849810252df809a3d8bcbda8e26f6c189920e7535ad608a48dbb5ab" + ], + "markers": "python_version >= '3.10'", + "version": "==4.11.3" + }, + "plotly": { + "hashes": [ + "sha256:36bebe2f1bb13884774fe61689c329071446f6ce4a8927fb1f0d6fb24f581236", + "sha256:967ad33e8c704fed051800d11d985eb206a9c795c14206b30a6f463ed9c67d0d" + ], + "markers": "python_version >= '3.8'", + "version": "==6.9.0" + }, + "polling": { + "hashes": [ + "sha256:3afd62320c99b725c70f379964bf548b302fc7f04d4604e6c315d9012309cc9a" + ], + "version": "==0.3.2" + }, + "propcache": { + "hashes": [ + "sha256:01c4fc7480cd0598bb4b57022df55b9ca296da7fc5a8760bd8451a7e63a7d427", + "sha256:04dc2390d9edbbaef7461f33322555976ffddf0b650a038649d026358714e6c5", + "sha256:06187263ddad280d05b4d8a8b3bb7d164cbebd469236544a42e6d9b28ac6a4fa", + "sha256:0958834041a0166d343b8d2cedcd8bcbaeb4fdbe0cf08320c5379f143c3be6e7", + "sha256:099aaf4b4d1a02265b92a977edf00b5c4f63b3b17ac6de39b0d637c9cac0188a", + "sha256:0d2c9bf8528f135dbb805ce027567e09164f7efa51a2be07458a2c0420f292d0", + "sha256:0fd59b5af35f74da48d905dcbad55449ba13be91823cb05a9bd590bbf5b61660", + "sha256:10734b5484ea113152ee25a91dccedf81631791805d2c9ccb054958e51842c94", + "sha256:13fef48778b5a2a756523fdb781326b028ca75e32858b04f2cdd19f394564917", + "sha256:178b4a2cdaac1818e2bf1c5a99b94383fa73ea5382e032a48dec07dc5668dc42", + "sha256:196913dea116aeb5a2ba95af4ddcb7ea85559ae07d8eee8751688310d09168c3", + "sha256:1b31822f4474c4036bae62de9402710051d431a606d6a0f907fec79935a071aa", + "sha256:1ca071adabaab6e9219924bbe00af821f1ee7de113a9eca1cdc292de3d120f4d", + "sha256:1d1ad32d9d4355e2be65574fd0bfd3677e7066b009cd5b9b2dee8aa6a6393b33", + "sha256:1dbcf7675229b35d31abb6547d8ebc8c27a830ac3f9a794edff6254873ec7c0a", + "sha256:2293949b855ce597f2826452d17c2d545fb5622379c4ea6fdf525e9b8e8a2511", + "sha256:26a4dca084132874e639895c3135dfad5eb20bae209f62d1aeb31b03e601c3c0", + "sha256:2800a4a8ead6b28cccd1ec54b59346f0def7922ee1c7598e8499c733cfbb7c84", + "sha256:29cbaac5ea0212663e6845e04b5e188d5a6ae6dd919810ac835bf1d3b42c3f4c", + "sha256:29f9309a2e42b0d273be006fdb4be2d6c39a47f6f57d8fb1cf9f81481df81b66", + "sha256:2d7aa89ebca5acc98cba9d1472d976e394782f587bad6661003602a619fd1821", + "sha256:2f22cbbac9e26a8e864c0985ff1268d5d939d53d9d9411a9824279097e03a2cb", + "sha256:2f8ea531c794b9d6274acd4e8d2c2ebcac590a4361d27482edd3010b79f1325e", + "sha256:3115559b8effafd63b142ea5ed53d63a16ea6469cbc63dce4ee194b42db5d853", + "sha256:32775082acd2d807ee3db715c7770d38767b817870acfa08c29e057f3c4d5b56", + "sha256:3430bb2bfe1331885c427745a751e774ee679fd4344f80b97bf879815fe8fa55", + "sha256:3b199b9b2b3d6a7edf3183ba8a9a137a22b97f7df525feb5ae1eccf026d2a9c6", + "sha256:40314bca9ac559716fe374094fc81c11dcc34b64fd6c585360f5775690505704", + "sha256:44e488ef40dbb452700b2b1f8188934121f6648f52c295055662d2191959ff82", + "sha256:452b5065457eb9991ec5eb38ff41d6cd4c991c9ac7c531c4d5849ae473a9a13f", + "sha256:45f11346f884bc47444f6e6647131055844134c3175b629f84952e2b5cd62b64", + "sha256:46088abff4cba581dea21ae0467a480526cb25aa5f3c269e909f800328bc3999", + "sha256:4621064bbf28fa77ff64dd5d94367c04684c67d3a5bf1dff25f0cd0d98a38f3b", + "sha256:4bc8ff1feffc6a61c7002ffe84634c41b822e104990ae009f44a0834430070bb", + "sha256:4db0ba63d693afd40d249bd93f842b5f144f8fcbb83de05660373bcf30517b1d", + "sha256:51f96d685ab16e88cab128cd37a52c5da540809c8b879fa047731bfcb4ad35a4", + "sha256:54adaa85a22078d1e306304a40984dc5be99d599bf3dc0a24dc98f7daeab89ab", + "sha256:552ffadf6ad409844bc5919c42a0a83d88314cedddaea0e41e80a8b8fffe881f", + "sha256:5538d2c13d93e4698af7e092b57bc7298fd35d1d58e656ae18f23ee0d0378e03", + "sha256:5570dbcc97571c15f68068e529c92715a12f8d54030e272d264b377e22bd17a5", + "sha256:5671d09a36b06d0fd4a3da0fccbcae360e9b1570924171a15e9e0997f0249fba", + "sha256:583c19759d9eec1e5b69e2fbef36a7d9c326041be9746cb822d335c8cedc2979", + "sha256:5aaa2b923c1944ac8febd6609cb373540a5563e7cbcb0fd770f75dace2eb817b", + "sha256:5dbc581d2814337da56222fab8dc5f161cd798a434e49bac27930aaef798e144", + "sha256:5fcb98e7598b1ee0addab320d90f65b530297a867dbfe9de52ea838077e16e3d", + "sha256:6041d31504dc1779d700e1edcfb08eea334b357620b06681a4eabb57a74e574e", + "sha256:66ea454f095ddf5b6b14f56c064c0941c4788be11e18d2464cf643bf7203ff67", + "sha256:68ce1c44c7a813a7f71ea04315a8c7b330b63db99d059a797a4651bb6f69f117", + "sha256:6a997d0489e9668a384fcfd5061b857aa5361de73191cac204d04b889cfbbafa", + "sha256:6bf3be92233808fcd338eba0fb4d0b59ec5772af4f4ecfcec450d1bfc0f8b5eb", + "sha256:6de8bd93ddde9b992cf2b2e0d796d501a19026b5b9fd87356d7d0779531a8d96", + "sha256:6e7b8719005dd1175be4ab1cd25e9b98659a5e0347331506ec6760d2773a7fb5", + "sha256:6f328175a2cde1f0ff2c4ed8ce968b9dcfb55f3a7153f39e2957ed994da13476", + "sha256:72d61e16dd78228b58c5d47be830ff3da7e5f139abdf0aef9d86cde1c5cf2191", + "sha256:74b70780220e2dd89175ca24b81b68b67c83db499ae611e7f2313cb329801c78", + "sha256:79aa3ff0a9b566633b642fa9caf7e21ed1c13d6feca718187873f199e1514078", + "sha256:7afa37062e6650640e932e4cc9297d81f9f42d9944029cc386b8247dea4da837", + "sha256:80168e2ebe4d3ec6599d10ad8f520304ae1cad9b6c5a95372aef1b66b7bfb53a", + "sha256:806719138ecd720339a12410fb9614ac9b2b2d3a5fdf8235d56981c36f4039ba", + "sha256:8114f28879e0904748e831c3a7774261bd9e75f49be089f389a76f959dcd13fe", + "sha256:81e3a30b0bb60caa22033dd0f8a3618d1d67356212514f62c57db75cb0ef410c", + "sha256:823581fd5cb08b12a48bfa11fe962a7916766b6170c17b028fbdf762b85eb9bf", + "sha256:85341b12b9d55bad0bded24cac341bb34289469e03a11f3f583ea1cc1db0326c", + "sha256:857187f381f88c8e2fa2fe56ab94879d011b883d5a2ee5a1b60a8cd2a06846d9", + "sha256:8a90efd5777e996e42d568db9ac740b944d691e565cbfd31b2f7832f9184b2b8", + "sha256:8b73ab70f1a3351fbc71f663b3e645af6dd0329100c353081cf69c37433fc6fe", + "sha256:8c7972d8f193740d9175f0998ab38717e6cd322d5935c5b0fef8c0d323fd9031", + "sha256:8e778ebd44ef4f66ed60a0416b06b489687db264a9c0b3620362f26489492913", + "sha256:9282fb1a3bccd038da9f768b927b24a0c753e466c086b7c4f3c6982851eefb2d", + "sha256:949c91d1a990cf3b2e8188dfcfb25005e0b834a06c63fa4ef9f360878ce21ecf", + "sha256:95f1e3f4760d404b13c9976c0229b2b49a3c8e2c62a9ce92efdd2b11ada75e3f", + "sha256:97797ebb098e670a2f92dd66f32897e30d7615b14e7f59711de23e30a9072539", + "sha256:a0e399a2eccb91ed18721f86aa85757727400b6865c89e88934781deb9c8498b", + "sha256:a473b3440261e0c60706e732b2ed2f517857344fc21bf48fdfe211e2d98eb285", + "sha256:a4840ab0ae0216d952f4b53dc6d0b992bfc2bedbfe360bdd9b548bc184c08959", + "sha256:a592f5f3da71c8691c788c13cb6734b6d17663d2e1cb8caddf0673d01ef8847d", + "sha256:a6ae2198be502c10f09b2516e7b5d019816924bc3183a43ce792a7bd6625e6f4", + "sha256:a6ddc6ac9e25de626c1f129c1b467d7ecd33ce2237d3fd0c4e429feef0a7ee1f", + "sha256:acd2c8edba48e31e58a363b8cf4e5c7db3b04b3f9e371f601df30d9b0d244836", + "sha256:b05d643f944a8c3c4bd86d65ffd87bf3264b617f87791940302bc474d2ff5274", + "sha256:b96db7141a592cbc968daf1feea83a118e6ab378af4abbc72b248c895414c22d", + "sha256:ba338430e87ceb9c8f0cf754de38a9860560261e56c00376debd628698a7364f", + "sha256:ba57fffe4ac99c5d30076161b5866336d97600769bad35cc68f7774b15298a4e", + "sha256:be1ddfcbb376e3de5d2e2db1d58d6d67463e6b4f9f040c000de8e300295465fe", + "sha256:c0cb9ed24c8964e172768d455a38254c2dd8a552905729ce006cad3d3dda59b1", + "sha256:c60462af8e6dc30c35407c7237ea908d777b22862bbee27bc4699c0d8bcdc45a", + "sha256:c66afea89b1e43725731d2004732a046fe6fe955d51f952c3e95a7314a284a39", + "sha256:c6844ba6364fb12f403928a82cfd295ab103a2b315c77c747b2dbe4a41894ea7", + "sha256:c80f4ba3e8f00189165999a742ee526ebeccedf6c3f7beb0c7df821e9772435a", + "sha256:cafca7e56c12bb02ae16d283742bef25a61122e9dab2b5b3f2ccbe589ce32164", + "sha256:cc1177027eda740fdb152706bd215a3f124e3eea15afc39f2cb9fe351b50619e", + "sha256:cc49723e2f60d6b32a0f0b08a3fd6d13203c07f1cd9566cfce0f12a917c967a2", + "sha256:cc6fc3cc62e8501d3ed62894425040d2728ecddb1ed072737a5c70bd537aa9f0", + "sha256:cd416c1de191973c52ff1a12a57446bfc7642797b282d7caf2162d7d1b8aa9a0", + "sha256:cd645f03898405cabe694fb8bc35241e3a9c332ec85627584fe3de201452b335", + "sha256:cef6cea3922890dd6c9654971001fa797b526c16ab5e1e46c05fd6f877be7568", + "sha256:cfa21e036ce1e1db2be04ba3b85d2df1bb1702fa01932d984c5464c665228ff4", + "sha256:d0326e2e5e1f3163fa306c834e48e8d490e5fae607a097a40c0648109b47ba80", + "sha256:d310c013aad2c72f1c3f2f8dd3279d460a858c551f97aeb8c63e4693cca7b4d2", + "sha256:d447bb0b3054be5818458fbb171208b1d9ff11eba14e18ca18b90cbb45767370", + "sha256:d4dc37dec6c6cdad0b57881a5658fd14fbf53e333b1a86cf86559f190e1d9ec4", + "sha256:d5a81be28596d6559f6131ef33e10200de6e17643b3c74ce03f9eb103be6ae8b", + "sha256:d9ee8826a7d47863a08ac44e1a5f611a462eefc3a194b492da242128bec75b42", + "sha256:db2b80ea58eab4f86b2beec3cc8b39e8ff9276ac20e96b7cce43c8ae84cd6b5a", + "sha256:decfca4c79dd53ebab484b00cc4b6717d8c369f86e74aa4ca395a64ac651495e", + "sha256:dfed59d0a5aeb01e242e66ff0300bc4a265a7c05f612d30016f0b60b1017d757", + "sha256:e00820e192c8dbebcafb383ebbf99030895f09905e7a0eb2e0340a0bcc2bc825", + "sha256:e4294d04a94dcab1b3bccd8b66d962dcad411a1d19414b2a41d1445f1de32ad0", + "sha256:e59bc9e66329185b93dab73f210f1a37f81cb40f321501db8017c9aea15dba27", + "sha256:e5cbfac9f61484f7e9f3597775500cd3ebe8274e9b050c38f9525c77c97520bf", + "sha256:f064f8d2b59177878b7615df1735cd8fe3462ed6be8c7b217d17a276489c2b7f", + "sha256:f156a3529f38063b6dbaf356e15602a7f95f8055b1295a438433a6386f10463d", + "sha256:f19bb891234d72535764d703bfed1153cc34f4214d5bd7150aee1eec9e8f4366", + "sha256:f7467da8a9822bf1a55336f877340c5bcbd3c482afc43a99771169f74a26dedc", + "sha256:f78abfa8dfc32376fd1aacf597b2f2fbbe0ea751419aee718af5d4f82537ef8c", + "sha256:f7eabc04151c78a9f4d5bbb5f1faf571e4defeb4b585e0fe95b60ff2dbe4d3d7", + "sha256:f814362777a9f841adddb200ecdf8f5cb1e5a3c4b7a86378edbd6ccb26edd702", + "sha256:fc299c129490f55f254cd90be0deca4764e36e9a7c08b4aa588479a3bbed3098", + "sha256:fc76378c62a0f04d0cd82fbb1a2cd2d7e28fcb40d5873f28a6c44e388aaa2751", + "sha256:fc88b26f08d634f7bc819a7852e5214f5802641ab8d9fd5326892292eee1993e", + "sha256:fe67a3d11cd9b4efabfa45c3d00ffba2b26811442a73a581a94b67c2b5faccf6" + ], + "markers": "python_version >= '3.10'", + "version": "==0.5.2" + }, + "proto-plus": { + "hashes": [ + "sha256:5f91b30dafa6bb38d432c5557a6ee1d35ffd40b4b1e0e3ca27260448560b91d9", + "sha256:dc76880b8ee951cca002098574376cf71e055f9f16d9ba6570fb8a06f726d281" + ], + "markers": "python_version >= '3.10'", + "version": "==1.28.3" + }, + "protobuf": { + "hashes": [ + "sha256:11d6b0ec246892d85215b0a13ca6e0233cf5284b68f0ac02646427f4ff88a799", + "sha256:230a75ddfc2de4806e56696ce9640c1cdfdb6543b7cfce98d42a4c0a0e7bdb87", + "sha256:24f857477359a85c0c235261b8ba905fd51b2562f4a64ca1df5473f29850cbf6", + "sha256:353652e4efd0bca5b5fc2656abf8307ef351f0cf938c9eba09f0e09c20a25c30", + "sha256:4bc97768d8fe4ad6743c8a19403e314511ed9f6d13205b687e52421c023ac1b9", + "sha256:74758715c53d7158fb76caf4f0cfdacc5329a4b1bb994f865d6cf302d413a1c4", + "sha256:b73f9489a4b8b1c9cb1f8ed951c736392592edb24b9d6819f36d2e10b171d5b4", + "sha256:ce115a26fe0c39a2c29973d914d327e516a6455464489fe3cd1e51a1b354f81a" + ], + "markers": "python_version >= '3.10'", + "version": "==7.35.1" + }, + "prowler": { + "hashes": [ + "sha256:2c47b325f5a8d8ddeef613d25ca9aaac531459db9c59a51ed78eb633bbe45144", + "sha256:35c9234569fc0652f0110b72d778519ce1f7064efb11fc1da1ef9846193c67f3" + ], + "index": "pypi", + "markers": "python_version >= '3.10' and python_version < '3.14'", + "version": "==5.39.1" + }, + "psutil": { + "hashes": [ + "sha256:0746f5f8d406af344fd547f1c8daa5f5c33dbc293bb8d6a16d80b4bb88f59372", + "sha256:076a2d2f923fd4821644f5ba89f059523da90dc9014e85f8e45a5774ca5bc6f9", + "sha256:11fe5a4f613759764e79c65cf11ebdf26e33d6dd34336f8a337aa2996d71c841", + "sha256:1a571f2330c966c62aeda00dd24620425d4b0cc86881c89861fbc04549e5dc63", + "sha256:1a7b04c10f32cc88ab39cbf606e117fd74721c831c98a27dc04578deb0c16979", + "sha256:1fa4ecf83bcdf6e6c8f4449aff98eefb5d0604bf88cb883d7da3d8d2d909546a", + "sha256:2edccc433cbfa046b980b0df0171cd25bcaeb3a68fe9022db0979e7aa74a826b", + "sha256:7b6d09433a10592ce39b13d7be5a54fbac1d1228ed29abc880fb23df7cb694c9", + "sha256:8c233660f575a5a89e6d4cb65d9f938126312bca76d8fe087b947b3a1aaac9ee", + "sha256:917e891983ca3c1887b4ef36447b1e0873e70c933afc831c6b6da078ba474312", + "sha256:ab486563df44c17f5173621c7b198955bd6b613fb87c71c161f827d3fb149a9b", + "sha256:ae0aefdd8796a7737eccea863f80f81e468a1e4cf14d926bd9b6f5f2d5f90ca9", + "sha256:b0726cecd84f9474419d67252add4ac0cd9811b04d61123054b9fb6f57df6e9e", + "sha256:b58fabe35e80b264a4e3bb23e6b96f9e45a3df7fb7eed419ac0e5947c61e47cc", + "sha256:c7663d4e37f13e884d13994247449e9f8f574bc4655d509c3b95e9ec9e2b9dc1", + "sha256:e452c464a02e7dc7822a05d25db4cde564444a67e58539a00f929c51eddda0cf", + "sha256:e78c8603dcd9a04c7364f1a3e670cea95d51ee865e4efb3556a3a63adef958ea", + "sha256:eb7e81434c8d223ec4a219b5fc1c47d0417b12be7ea866e24fb5ad6e84b3d988", + "sha256:ed0cace939114f62738d808fdcecd4c869222507e266e574799e9c0faa17d486", + "sha256:eed63d3b4d62449571547b60578c5b2c4bcccc5387148db46e0c2313dad0ee00", + "sha256:fd04ef36b4a6d599bbdb225dd1d3f51e00105f6d48a28f006da7f9822f2606d8" + ], + "markers": "python_version >= '3.6'", + "version": "==7.2.2" + }, + "py-iam-expand": { + "hashes": [ + "sha256:4ccfe25f40ba0633a152c4f86b49cde8972ee3d4b6009b017a4310cc4b9e64c7", + "sha256:94c0a1e9dd60316ce60ddc0cdc9a046119bde335b5bb9593ee29224857860d5a" + ], + "markers": "python_version >= '3.10' and python_version < '3.15'", + "version": "==0.3.0" + }, + "py-ocsf-models": { + "hashes": [ + "sha256:29abaa5a3d4ebba0e2a21757508a4848fa5e1d57da233af57e580f97f0223c59", + "sha256:a9d1e245b1c9fba1d2cb8c042253ef1b83a2dbfec30ed69975bbce599b4510bb" + ], + "markers": "python_version >= '3.10' and python_version < '3.15'", + "version": "==0.10.0" + }, + "pyasn1": { + "hashes": [ + "sha256:9c447d8431c947fe4c8febc4ed9e760bc29011a5b01e5c74b67025bd9fb8ce81", + "sha256:deda9277cfd454080ec40b207fb6df82206a3a2688735233cdcd8d3d565f088b" + ], + "markers": "python_version >= '3.8'", + "version": "==0.6.4" + }, + "pyasn1-modules": { + "hashes": [ + "sha256:29253a9207ce32b64c3ac6600edc75368f98473906e8fd1043bd6b5b1de2c14a", + "sha256:677091de870a80aae844b1ca6134f54652fa2c8c5a52aa396440ac3106e941e6" + ], + "markers": "python_version >= '3.8'", + "version": "==0.4.2" + }, + "pycparser": { + "hashes": [ + "sha256:600f49d217304a5902ac3c37e1281c9fe94e4d0489de643a9504c5cdfdfc6b29", + "sha256:b727414169a36b7d524c1c3e31839a521725078d7b2ff038656844266160a992" + ], + "markers": "python_version >= '3.10'", + "version": "==3.0" + }, + "pycryptodomex": { + "hashes": [ + "sha256:02d87b80778c171445d67e23d1caef279bf4b25c3597050ccd2e13970b57fd51", + "sha256:06698f957fe1ab229a99ba2defeeae1c09af185baa909a31a5d1f9d42b1aaed6", + "sha256:14c37aaece158d0ace436f76a7bb19093db3b4deade9797abfc39ec6cd6cc2fe", + "sha256:189afbc87f0b9f158386bf051f720e20fa6145975f1e76369303d0f31d1a8d7c", + "sha256:1c3a65ad441746b250d781910d26b7ed0a396733c6f2dbc3327bd7051ec8a541", + "sha256:1c6d919fc8429e5cb228ba8c0d4d03d202a560b421c14867a65f6042990adc8e", + "sha256:267a3038f87a8565bd834317dbf053a02055915acf353bf42ededb9edaf72010", + "sha256:27e13c80ac9a0a1d050ef0a7e0a18cc04c8850101ec891815b6c5a0375e8a245", + "sha256:43c446e2ba8df8889e0e16f02211c25b4934898384c1ec1ec04d7889c0333587", + "sha256:47f6d318fe864d02d5e59a20a18834819596c4ed1d3c917801b22b92b3ffa648", + "sha256:4e79f1aaff5a3a374e92eb462fa9e598585452135012e2945f96874ca6eeb1ff", + "sha256:4f2596e643d4365e14d0879dc5aafe6355616c61c2176009270f3048f6d9a61f", + "sha256:52e5ca58c3a0b0bd5e100a9fbc8015059b05cffc6c66ce9d98b4b45e023443b9", + "sha256:55ccbe27f049743a4caf4f4221b166560d3438d0b1e5ab929e07ae1702a4d6fd", + "sha256:58b851b9effd0d072d4ca2e4542bf2a4abcf13c82a29fd2c93ce27ee2a2e9462", + "sha256:6b8962204c47464d5c1c4038abeadd4514a133b28748bcd9fa5b6d62e3cec6fa", + "sha256:6bbcb1dd0f646484939e142462d9e532482bc74475cecf9c4903d4e1cd21f003", + "sha256:71909758f010c82bc99b0abf4ea12012c98962fbf0583c2164f8b84533c2e4da", + "sha256:7b37e08e3871efe2187bc1fd9320cc81d87caf19816c648f24443483005ff886", + "sha256:7de1e40a41a5d7f1ac42b6569b10bcdded34339950945948529067d8426d2785", + "sha256:8a4fcd42ccb04c31268d1efeecfccfd1249612b4de6374205376b8f280321744", + "sha256:91979028227543010d7b2ba2471cf1d1e398b3f183cb105ac584df0c36dac28d", + "sha256:a33986a0066860f7fcf7c7bd2bc804fa90e434183645595ae7b33d01f3c91ed8", + "sha256:a9d446e844f08299236780f2efa9898c818fe7e02f17263866b8550c7d5fb328", + "sha256:add243d204e125f189819db65eed55e6b4713f70a7e9576c043178656529cec7", + "sha256:b2c2537863eccef2d41061e82a881dcabb04944c5c06c5aa7110b577cc487545", + "sha256:bc65bdd9fc8de7a35a74cab1c898cab391a4add33a8fe740bda00f5976ca4708", + "sha256:bdc69d0d3d989a1029df0eed67cc5e8e5d968f3724f4519bd03e0ec68df7543c", + "sha256:bffc92138d75664b6d543984db7893a628559b9e78658563b0395e2a5fb47ed9", + "sha256:c25e30a20e1b426e1f0fa00131c516f16e474204eee1139d1603e132acffc314", + "sha256:c7947ab8d589e3178da3d7cdeabe14f841b391e17046954f2fbcd941705762b5", + "sha256:c84b239a1f4ec62e9c789aafe0543f0594f0acd90c8d9e15bcece3efe55eca66", + "sha256:c885da45e70139464f082018ac527fdaad26f1657a99ee13eecdce0f0ca24ab4", + "sha256:d9825410197a97685d6a1fa2a86196430b01877d64458a20e95d4fd00d739a08", + "sha256:da4fa650cef02db88c2b98acc5434461e027dce0ae8c22dd5a69013eaf510006", + "sha256:df027262368334552db2c0ce39706b3fb32022d1dce34673d0f9422df004b96a", + "sha256:ebfff755c360d674306e5891c564a274a47953562b42fb74a5c25b8fc1fb1cb5", + "sha256:eca54f4bb349d45afc17e3011ed4264ef1cc9e266699874cdd1349c504e64798", + "sha256:f489c4765093fb60e2edafdf223397bc716491b2b69fe74367b70d6999257a5c", + "sha256:fdfac7cda115bca3a5abb2f9e43bc2fb66c2b65ab074913643803ca7083a79ea", + "sha256:febec69c0291efd056c65691b6d9a339f8b4bc43c6635b8699471248fe897fea" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6'", + "version": "==3.23.0" + }, + "pydantic": { + "hashes": [ + "sha256:4d351024c75c0f085a9febbb665ce8c0c6ec5d30e903bdb6394b7ede26aebb49", + "sha256:e561593fccf61e8a20fc46dfc2dfe075b8be7d0188df33f221ad1f0139180f9d" + ], + "markers": "python_version >= '3.9'", + "version": "==2.12.5" + }, + "pydantic-core": { + "hashes": [ + "sha256:0177272f88ab8312479336e1d777f6b124537d47f2123f89cb37e0accea97f90", + "sha256:01a3d0ab748ee531f4ea6c3e48ad9dac84ddba4b0d82291f87248f2f9de8d740", + "sha256:0384e2e1021894b1ff5a786dbf94771e2986ebe2869533874d7e43bc79c6f504", + "sha256:03b77d184b9eb40240ae9fd676ca364ce1085f203e1b1256f8ab9984dca80a84", + "sha256:03ca43e12fab6023fc79d28ca6b39b05f794ad08ec2feccc59a339b02f2b3d33", + "sha256:05a2c8852530ad2812cb7914dc61a1125dc4e06252ee98e5638a12da6cc6fb6c", + "sha256:070259a8818988b9a84a449a2a7337c7f430a22acc0859c6b110aa7212a6d9c0", + "sha256:08daa51ea16ad373ffd5e7606252cc32f07bc72b28284b6bc9c6df804816476e", + "sha256:0cbaad15cb0c90aa221d43c00e77bb33c93e8d36e0bf74760cd00e732d10a6a0", + "sha256:100baa204bb412b74fe285fb0f3a385256dad1d1879f0a5cb1499ed2e83d132a", + "sha256:112e305c3314f40c93998e567879e887a3160bb8689ef3d2c04b6cc62c33ac34", + "sha256:16f80f7abe3351f8ea6858914ddc8c77e02578544a0ebc15b4c2e1a0e813b0b2", + "sha256:1746d4a3d9a794cacae06a5eaaccb4b8643a131d45fbc9af23e353dc0a5ba5c3", + "sha256:1962293292865bca8e54702b08a4f26da73adc83dd1fcf26fbc875b35d81c815", + "sha256:1d1d9764366c73f996edd17abb6d9d7649a7eb690006ab6adbda117717099b14", + "sha256:1f8d33a7f4d5a7889e60dc39856d76d09333d8a6ed0f5f1190635cbec70ec4ba", + "sha256:22f0fb8c1c583a3b6f24df2470833b40207e907b90c928cc8d3594b76f874375", + "sha256:239edca560d05757817c13dc17c50766136d21f7cd0fac50295499ae24f90fdf", + "sha256:242a206cd0318f95cd21bdacff3fcc3aab23e79bba5cac3db5a841c9ef9c6963", + "sha256:25e1c2af0fce638d5f1988b686f3b3ea8cd7de5f244ca147c777769e798a9cd1", + "sha256:266fb4cbf5e3cbd0b53669a6d1b039c45e3ce651fd5442eff4d07c2cc8d66808", + "sha256:2782c870e99878c634505236d81e5443092fba820f0373997ff75f90f68cd553", + "sha256:287dad91cfb551c363dc62899a80e9e14da1f0e2b6ebde82c806612ca2a13ef1", + "sha256:29452c56df2ed968d18d7e21f4ab0ac55e71dc59524872f6fc57dcf4a3249ed2", + "sha256:299e0a22e7ae2b85c1a57f104538b2656e8ab1873511fd718a1c1c6f149b77b5", + "sha256:2a5e06546e19f24c6a96a129142a75cee553cc018ffee48a460059b1185f4470", + "sha256:2b761d210c9ea91feda40d25b4efe82a1707da2ef62901466a42492c028553a2", + "sha256:2c010c6ded393148374c0f6f0bf89d206bf3217f201faa0635dcd56bd1520f6b", + "sha256:2ff4321e56e879ee8d2a879501c8e469414d948f4aba74a2d4593184eb326660", + "sha256:3006c3dd9ba34b0c094c544c6006cc79e87d8612999f1a5d43b769b89181f23c", + "sha256:33cb885e759a705b426baada1fe68cbb0a2e68e34c5d0d0289a364cf01709093", + "sha256:346285d28e4c8017da95144c7f3acd42740d637ff41946af5ce6e5e420502dd5", + "sha256:34a64bc3441dc1213096a20fe27e8e128bd3ff89921706e83c0b1ac971276594", + "sha256:35b44f37a3199f771c3eaa53051bc8a70cd7b54f333531c59e29fd4db5d15008", + "sha256:378bec5c66998815d224c9ca994f1e14c0c21cb95d2f52b6021cc0b2a58f2a5a", + "sha256:3f37a19d7ebcdd20b96485056ba9e8b304e27d9904d233d7b1015db320e51f0a", + "sha256:3f84d5c1b4ab906093bdc1ff10484838aca54ef08de4afa9de0f5f14d69639cd", + "sha256:4009935984bd36bd2c774e13f9a09563ce8de4abaa7226f5108262fa3e637284", + "sha256:406bf18d345822d6c21366031003612b9c77b3e29ffdb0f612367352aab7d586", + "sha256:4819fa52133c9aa3c387b3328f25c1facc356491e6135b459f1de698ff64d869", + "sha256:482c982f814460eabe1d3bb0adfdc583387bd4691ef00b90575ca0d2b6fe2294", + "sha256:4bc36bbc0b7584de96561184ad7f012478987882ebf9f9c389b23f432ea3d90f", + "sha256:506d766a8727beef16b7adaeb8ee6217c64fc813646b424d0804d67c16eddb66", + "sha256:56121965f7a4dc965bff783d70b907ddf3d57f6eba29b6d2e5dabfaf07799c51", + "sha256:58133647260ea01e4d0500089a8c4f07bd7aa6ce109682b1426394988d8aaacc", + "sha256:5921a4d3ca3aee735d9fd163808f5e8dd6c6972101e4adbda9a4667908849b97", + "sha256:5a4e67afbc95fa5c34cf27d9089bca7fcab4e51e57278d710320a70b956d1b9a", + "sha256:5cb1b2f9742240e4bb26b652a5aeb840aa4b417c7748b6f8387927bc6e45e40d", + "sha256:62de39db01b8d593e45871af2af9e497295db8d73b085f6bfd0b18c83c70a8f9", + "sha256:634e8609e89ceecea15e2d61bc9ac3718caaaa71963717bf3c8f38bfde64242c", + "sha256:63510af5e38f8955b8ee5687740d6ebf7c2a0886d15a6d65c32814613681bc07", + "sha256:650ae77860b45cfa6e2cdafc42618ceafab3a2d9a3811fcfbd3bbf8ac3c40d36", + "sha256:6561e94ba9dacc9c61bce40e2d6bdc3bfaa0259d3ff36ace3b1e6901936d2e3e", + "sha256:65840751b72fbfd82c3c640cff9284545342a4f1eb1586ad0636955b261b0b05", + "sha256:6cb58b9c66f7e4179a2d5e0f849c48eff5c1fca560994d6eb6543abf955a149e", + "sha256:6f52298fbd394f9ed112d56f3d11aabd0d5bd27beb3084cc3d8ad069483b8941", + "sha256:707625ef0983fcfb461acfaf14de2067c5942c6bb0f3b4c99158bed6fedd3cf3", + "sha256:72f6c8b11857a856bcfa48c86f5368439f74453563f951e473514579d44aa612", + "sha256:753e230374206729bf0a807954bcc6c150d3743928a73faffee51ac6557a03c3", + "sha256:76d0819de158cd855d1cbb8fcafdf6f5cf1eb8e470abe056d5d161106e38062b", + "sha256:76ee27c6e9c7f16f47db7a94157112a2f3a00e958bc626e2f4ee8bec5c328fbe", + "sha256:77b63866ca88d804225eaa4af3e664c5faf3568cea95360d21f4725ab6e07146", + "sha256:79ec52ec461e99e13791ec6508c722742ad745571f234ea6255bed38c6480f11", + "sha256:7b93a4d08587e2b7e7882de461e82b6ed76d9026ce91ca7915e740ecc7855f60", + "sha256:7da7087d756b19037bc2c06edc6c170eeef3c3bafcb8f532ff17d64dc427adfd", + "sha256:7f3bf998340c6d4b0c9a2f02d6a400e51f123b59565d74dc60d252ce888c260b", + "sha256:80aa89cad80b32a912a65332f64a4450ed00966111b6615ca6816153d3585a8c", + "sha256:8566def80554c3faa0e65ac30ab0932b9e3a5cd7f8323764303d468e5c37595a", + "sha256:873e0d5b4fb9b89ef7c2d2a963ea7d02879d9da0da8d9d4933dee8ee86a8b460", + "sha256:88942d3a3dff3afc8288c21e565e476fc278902ae4d6d134f1eeda118cc830b1", + "sha256:8bfeaf8735be79f225f3fefab7f941c712aaca36f1128c9d7e2352ee1aa87bdf", + "sha256:8e7c86f27c585ef37c35e56a96363ab8de4e549a95512445b85c96d3e2f7c1bf", + "sha256:915c3d10f81bec3a74fbd4faebe8391013ba61e5a1a8d48c4455b923bdda7858", + "sha256:93e8740d7503eb008aa2df04d3b9735f845d43ae845e6dcd2be0b55a2da43cd2", + "sha256:941103c9be18ac8daf7b7adca8228f8ed6bb7a1849020f643b3a14d15b1924d9", + "sha256:97aeba56665b4c3235a0e52b2c2f5ae9cd071b8a8310ad27bddb3f7fb30e9aa2", + "sha256:a39455728aabd58ceabb03c90e12f71fd30fa69615760a075b9fec596456ccc3", + "sha256:a3a52f6156e73e7ccb0f8cced536adccb7042be67cb45f9562e12b319c119da6", + "sha256:a668ce24de96165bb239160b3d854943128f4334822900534f2fe947930e5770", + "sha256:a75dafbf87d6276ddc5b2bf6fae5254e3d0876b626eb24969a574fff9149ee5d", + "sha256:aabf5777b5c8ca26f7824cb4a120a740c9588ed58df9b2d196ce92fba42ff8dc", + "sha256:aec5cf2fd867b4ff45b9959f8b20ea3993fc93e63c7363fe6851424c8a7e7c23", + "sha256:b2379fa7ed44ddecb5bfe4e48577d752db9fc10be00a6b7446e9663ba143de26", + "sha256:b4ececa40ac28afa90871c2cc2b9ffd2ff0bf749380fbdf57d165fd23da353aa", + "sha256:b5819cd790dbf0c5eb9f82c73c16b39a65dd6dd4d1439dcdea7816ec9adddab8", + "sha256:b74557b16e390ec12dca509bce9264c3bbd128f8a2c376eaa68003d7f327276d", + "sha256:b80aa5095cd3109962a298ce14110ae16b8c1aece8b72f9dafe81cf597ad80b3", + "sha256:b93590ae81f7010dbe380cdeab6f515902ebcbefe0b9327cc4804d74e93ae69d", + "sha256:b96d5f26b05d03cc60f11a7761a5ded1741da411e7fe0909e27a5e6a0cb7b034", + "sha256:bd3d54f38609ff308209bd43acea66061494157703364ae40c951f83ba99a1a9", + "sha256:bfea2a5f0b4d8d43adf9d7b8bf019fb46fdd10a2e5cde477fbcb9d1fa08c68e1", + "sha256:c007fe8a43d43b3969e8469004e9845944f1a80e6acd47c150856bb87f230c56", + "sha256:c1df3d34aced70add6f867a8cf413e299177e0c22660cc767218373d0779487b", + "sha256:c23e27686783f60290e36827f9c626e63154b82b116d7fe9adba1fda36da706c", + "sha256:c8d8b4eb992936023be7dee581270af5c6e0697a8559895f527f5b7105ecd36a", + "sha256:c9e19dd6e28fdcaa5a1de679aec4141f691023916427ef9bae8584f9c2fb3b0e", + "sha256:d0d2568a8c11bf8225044aa94409e21da0cb09dcdafe9ecd10250b2baad531a9", + "sha256:d38548150c39b74aeeb0ce8ee1d8e82696f4a4e16ddc6de7b1d8823f7de4b9b5", + "sha256:d3a978c4f57a597908b7e697229d996d77a6d3c94901e9edee593adada95ce1a", + "sha256:d5160812ea7a8a2ffbe233d8da666880cad0cbaf5d4de74ae15c313213d62556", + "sha256:dc799088c08fa04e43144b164feb0c13f9a0bc40503f8df3e9fde58a3c0c101e", + "sha256:df3959765b553b9440adfd3c795617c352154e497a4eaf3752555cfb5da8fc49", + "sha256:dfa8a0c812ac681395907e71e1274819dec685fec28273a28905df579ef137e2", + "sha256:e25c479382d26a2a41b7ebea1043564a937db462816ea07afa8a44c0866d52f9", + "sha256:e4f4a984405e91527a0d62649ee21138f8e3d0ef103be488c1dc11a80d7f184b", + "sha256:e536c98a7626a98feb2d3eaf75944ef6f3dbee447e1f841eae16f2f0a72d8ddc", + "sha256:e56ba91f47764cc14f1daacd723e3e82d1a89d783f0f5afe9c364b8bb491ccdb", + "sha256:e672ba74fbc2dc8eea59fb6d4aed6845e6905fc2a8afe93175d94a83ba2a01a0", + "sha256:e7b576130c69225432866fe2f4a469a85a54ade141d96fd396dffcf607b558f8", + "sha256:e8465ab91a4bd96d36dde3263f06caa6a8a6019e4113f24dc753d79a8b3a3f82", + "sha256:e96cea19e34778f8d59fe40775a7a574d95816eb150850a85a7a4c8f4b94ac69", + "sha256:ece5c59f0ce7d001e017643d8d24da587ea1f74f6993467d85ae8a5ef9d4f42b", + "sha256:eceb81a8d74f9267ef4081e246ffd6d129da5d87e37a77c9bde550cb04870c1c", + "sha256:ed2e99c456e3fadd05c991f8f437ef902e00eedf34320ba2b0842bd1c3ca3a75", + "sha256:f0cd744688278965817fd0839c4a4116add48d23890d468bc436f78beb28abf5", + "sha256:f14f8f046c14563f8eb3f45f499cc658ab8d10072961e07225e507adb700e93f", + "sha256:f15489ba13d61f670dcc96772e733aad1a6f9c429cc27574c6cdaed82d0146ad", + "sha256:f31d95a179f8d64d90f6831d71fa93290893a33148d890ba15de25642c5d075b", + "sha256:f41a7489d32336dbf2199c8c0a215390a751c5b014c2c1c5366e817202e9cdf7", + "sha256:f41eb9797986d6ebac5e8edff36d5cef9de40def462311b3eb3eeded1431e425", + "sha256:f547144f2966e1e16ae626d8ce72b4cfa0caedc7fa28052001c94fb2fcaa1c52" + ], + "markers": "python_version >= '3.9'", + "version": "==2.41.5" + }, + "pydash": { + "hashes": [ + "sha256:b2821547e9723f69cf3a986be4db64de41730be149b2641947ecd12e1e11025a", + "sha256:ee70a81a5b292c007f28f03a4ee8e75c1f5d7576df5457b836ec7ab2839cc5d0" + ], + "markers": "python_version >= '3.9'", + "version": "==8.0.6" + }, + "pygithub": { + "hashes": [ + "sha256:11a3473c1c2f1c39c525d0ee8c559f369c6d46c272cb7321c9b0cabc7aa1ce7d", + "sha256:72f5f2677d86bc3a8843aa720c6ce4c1c42fb7500243b136e3d5e14ddb5c3386" + ], + "markers": "python_version >= '3.8'", + "version": "==2.8.0" + }, + "pyjwt": { + "extras": [ + "crypto" + ], + "hashes": [ + "sha256:41571c89ca91598c79e8ef18a2d07367d4810fbbd6f637794879baf1b7703423", + "sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728" + ], + "markers": "python_version >= '3.9'", + "version": "==2.13.0" + }, + "pymongo": { + "hashes": [ + "sha256:00e5313573243636813d17879176578fa3f3072ccf83147b16ce41ec52118c85", + "sha256:035f8299c3f2e8254faa5f4b8265d7628c51385a6097780f65df17963d552980", + "sha256:09de6518847abeed166148e7169095a227aa4c888fa4f56f76fe5f166fa7e7c7", + "sha256:12140d29da1ecbaefee2a9e65433ef15d6c2c38f97bc6dab0ff246a96f9d20cd", + "sha256:142abf2fbd4667a3c8f4ce2e30fdbd287c015f52a838f4845d7476a45340208d", + "sha256:1b96768741e0e03451ef7b07c4857490cc43999e01c7f8da704fe00b3fe5d4d3", + "sha256:1fbe6a044a306ed974bd1788f3ceffc2f5e13f81fdb786a28c948c047f4cea38", + "sha256:2277548bb093424742325b2a88861d913d8990f358fc71fd26004d1b87029bb8", + "sha256:234c80a5f21c8854cc5d6c2f5541ff17dd645b99643587c5e7ed1e21d42003b6", + "sha256:24171b2015052b2f0a3f8cbfa38b973fa87f6474e88236a4dfeb735983f9f49e", + "sha256:26a31af455bffcc64537a7f67e2f84833a57855a82d05a085a1030c471138990", + "sha256:330a17c1c89e2c3bf03ed391108f928d5881298c17692199d3e0cdf097a20082", + "sha256:363445cc0e899b9e55ac9904a868c8a16a6c81f71c48dbadfd78c98e0b54de27", + "sha256:3e8e2a33613b2880d516d9c8616b64d27957c488de2f8e591945cf12094336a5", + "sha256:43fcfc19446e0706bbfe86f683a477d1e699b02369dd9c114ec17c7182d1fe2b", + "sha256:45f0a2fb09704ca5e0df08a794076d21cbe5521d3a8ceb8ad6d51cef12f5f4e7", + "sha256:46d1af3eb2c274f07815372b5a68f99ecd48750e8ab54d5c3ff36a280fb41c8e", + "sha256:4c2d4b76ca658f0f244c8de21af33f33db4d958bfacbce1cf0f8ef4e22c1112f", + "sha256:51ee050a2e026e2b224d2ed382830194be20a81c78e1ef98f467e469071df3ac", + "sha256:56bbfb79b51e95f4b1324a5a7665f3629f4d27c18e2002cfaa60c907cc5369d9", + "sha256:58236ce5ba3a79748c1813221b07b411847fd8849ff34c2891ba56f807cce3e5", + "sha256:622957eed757e44d9605c43b576ef90affb61176d9e8be7356c1a2948812cb84", + "sha256:625dec3e9cd7c3d336285a20728c01bfc56d37230a99ec537a6a8625af783a43", + "sha256:64b60ed7220c52f8c78c7af8d2c58f7e415732e21b3ff7e642169efa6e0b11e7", + "sha256:67f7010851261f638cad9ebf89a8e6266b355ab9b304fe7ad98fec2fb90243df", + "sha256:6892ebf8b2bc345cacfe1301724195d87162f02d01c417175e9f27d276a2f198", + "sha256:6de046444c57f908b92bb03e3bb726b28a989a09e9e387c3af9c207e6a9469b9", + "sha256:7461e777b3da96568c1f077b1fbf9e0c15667ac4d8b9a1cf90d80a69fe3be609", + "sha256:754a5d75c33d49691e2b09a4e0dc75959e271a38cbfd92c6b36f7e4eafc4608e", + "sha256:756b7a2a80ec3dd5b89cd62e9d13c573afd456452a53d05663e8ad0c5ff6632b", + "sha256:7a2a439395f3d4c9d3dc33ba4575d52b6dd285d57db54e32062ae8ef557cab10", + "sha256:7dc31357379318881186213dc5fc49b62601c955504f65c8e72032b5048950a1", + "sha256:818b77c858dfd385b9d9f5f097807edd834073790ba4153c77a0b615da13761f", + "sha256:8baf46384c97f774bc84178662e1fc6e32a2755fbc8e259f424780c2a11a3566", + "sha256:8d62e68ad21661e536555d0683087a14bf5c74b242a4446c602d16080eb9e293", + "sha256:8ea6e5ff4d6747e7b64966629a964db3089e9c1e0206d8f9cc8720c90f5a7af1", + "sha256:9384dc203d4031c6aac8926bd6544e615dafc516db1f0e97404119d3ca396bcc", + "sha256:9481a492851e432122a83755d4e69c06aeb087bbf8370bac9f96d112ac1303fd", + "sha256:97ccf8222abd5b79daa29811f64ef8b6bb678b9c9a1c1a2cfa0a277f89facd1d", + "sha256:99236fd0e0cf6b048a4370d0df6820963dc94f935ad55a2e29af752272abd6c9", + "sha256:9aef07d33839f6429dc24f2ef36e4ec906979cb4f628c57a1c2676cc66625711", + "sha256:a2c0bdcf4d57e4861ed323ba430b585ad98c010a83e46cb8aa3b29c248a82be1", + "sha256:b3fbbcd46b172f012c8a5532f372528b36b4f7d418768403c91149e6bd2c4c05", + "sha256:b570dc8179dcab980259b885116b14462bcf39170e30d8cbcce6f17f28a2ac5b", + "sha256:b5b837df8e414e2a173722395107da981d178ba7e648f612fa49b7ab4e240852", + "sha256:b70201a6dbe19d0d10a886989d3ba4b857ea6ef402a22a61c8ca387b937cc065", + "sha256:b9f379a4333dc3779a6bf7adfd077d4387404ed1561472743486a9c58286f705", + "sha256:bab357c5ff36ba2340dfc94f3338ef399032089d35c3d257ce0c48630b7848b2", + "sha256:bb783d9001b464a6ef3ee76c30ebbb6f977caee7bbc3a9bb1bd2ff596e818c46", + "sha256:c08eb3944b5b361e3762bfec523d69621085238e4d26de988ea4a50e40d1b59c", + "sha256:c4809f8791f9dfb09eb6f5a457575ef89e4b754b950a9ff887d896e38db91673", + "sha256:c4e971349b7bdfb536af29e10f6f6af419edcb7df4f5e502ece6522e1581e37b", + "sha256:c5283dffcf601b793a57bb86819a467473bbb1bf21cd170c0b9648f933f22131", + "sha256:cb6321bde02308d4d313b487d19bfae62ea4d37749fc2325b1c12388e05e4c31", + "sha256:cc808588289f693aba80fae8272af4582a7d6edc4e95fb8fbf65fe6f634116ce", + "sha256:cf193d2dcd91fa1d1dfa1fd036a3b54f792915a4842d323c0548d23d30461b59", + "sha256:d50b18ad6e4a55a75c30f0e669bd15ed1ceb18f9994d6835b4f5d5218592b4a0", + "sha256:da0a13f345f4b101776dbab92cec66f0b75015df0b007b47bd73bfd0305cc56a", + "sha256:db439288516514713c8ee09c9baaf66bc4b0188fbe4cd578ef3433ee27699aab", + "sha256:def51dea1f8e336aed807eb5d2f2a416c5613e97ec64f07479681d05044c217c", + "sha256:e5fedea0e7b3747da836cd5f88b0fa3e2ec5a394371f9b6a6b15927cfeb5455d", + "sha256:ea4415970d2a074d5890696af10e174d84cb735f1fa7673020c7538431e1cb6e", + "sha256:f130b3d7540749a8788a254ceb199a03ede4ee080061bfa5e20e28237c87f2d7" + ], + "markers": "python_version >= '3.9'", + "version": "==4.15.1" + }, + "pynacl": { + "hashes": [ + "sha256:018494d6d696ae03c7e656e5e74cdfd8ea1326962cc401bcf018f1ed8436811c", + "sha256:04316d1fc625d860b6c162fff704eb8426b1a8bcd3abacea11142cbd99a6b574", + "sha256:22de65bb9010a725b0dac248f353bb072969c94fa8d6b1f34b87d7953cf7bbe4", + "sha256:26bfcd00dcf2cf160f122186af731ae30ab120c18e8375684ec2670dccd28130", + "sha256:2fef529ef3ee487ad8113d287a593fa26f48ee3620d92ecc6f1d09ea38e0709b", + "sha256:320ef68a41c87547c91a8b58903c9caa641ab01e8512ce291085b5fe2fcb7590", + "sha256:3bffb6d0f6becacb6526f8f42adfb5efb26337056ee0831fb9a7044d1a964444", + "sha256:44081faff368d6c5553ccf55322ef2819abb40e25afaec7e740f159f74813634", + "sha256:46065496ab748469cdd999246d17e301b2c24ae2fdf739132e580a0e94c94a87", + "sha256:5811c72b473b2f38f7e2a3dc4f8642e3a3e9b5e7317266e4ced1fba85cae41aa", + "sha256:622d7b07cc5c02c666795792931b50c91f3ce3c2649762efb1ef0d5684c81594", + "sha256:62985f233210dee6548c223301b6c25440852e13d59a8b81490203c3227c5ba0", + "sha256:68be3a09455743ff9505491220b64440ced8973fe930f270c8e07ccfa25b1f9e", + "sha256:834a43af110f743a754448463e8fd61259cd4ab5bbedcf70f9dabad1d28a394c", + "sha256:8845c0631c0be43abdd865511c41eab235e0be69c81dc66a50911594198679b0", + "sha256:8a66d6fb6ae7661c58995f9c6435bda2b1e68b54b598a6a10247bfcdadac996c", + "sha256:8b097553b380236d51ed11356c953bf8ce36a29a3e596e934ecabe76c985a577", + "sha256:a84bf1c20339d06dc0c85d9aea9637a24f718f375d861b2668b2f9f96fa51145", + "sha256:a9f9932d8d2811ce1a8ffa79dcbdf3970e7355b5c8eb0c1a881a57e7f7d96e88", + "sha256:bc4a36b28dd72fb4845e5d8f9760610588a96d5a51f01d84d8c6ff9849968c14", + "sha256:c8a231e36ec2cab018c4ad4358c386e36eede0319a0c41fed24f840b1dac59f6", + "sha256:c949ea47e4206af7c8f604b8278093b674f7c79ed0d4719cc836902bf4517465", + "sha256:d071c6a9a4c94d79eb665db4ce5cedc537faf74f2355e4d502591d850d3913c0", + "sha256:d29bfe37e20e015a7d8b23cfc8bd6aa7909c92a1b8f41ee416bbb3e79ef182b2", + "sha256:fe9847ca47d287af41e82be1dd5e23023d3c31a951da134121ab02e42ac218c9" + ], + "markers": "python_version >= '3.8'", + "version": "==1.6.2" + }, + "pyopenssl": { + "hashes": [ + "sha256:28dfcce0162b9211413e26dfbfdf1d24317fbeba18fc93c12400a1856b2a0bc7", + "sha256:f0eb0cb2d581d3ad2b9c489468485e7f2ab6727d08401bcf9d824c3caddf3c1c" + ], + "markers": "python_version >= '3.9'", + "version": "==26.4.0" + }, + "pyparsing": { + "hashes": [ + "sha256:850ba148bd908d7e2411587e247a1e4f0327839c40e2e5e6d05a007ecc69911d", + "sha256:c777f4d763f140633dcb6d8a3eda953bf7a214dc4eff598413c070bcdc117cbc" + ], + "markers": "python_version >= '3.9'", + "version": "==3.3.2" + }, + "python-dateutil": { + "hashes": [ + "sha256:37dd54208da7e1cd875388217d5e00ebd4179249f90fb72437e91a35459a0ad3", + "sha256:a8b2bc7bffae282281c8140a97d3aa9c14da0b136dfe83f850eea9a5f7470427" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2'", + "version": "==2.9.0.post0" + }, + "pytz": { + "hashes": [ + "sha256:89dd22dca55b46eac6eda23b2d72721bf1bdfef212645d81513ef5d03038de57", + "sha256:c2db42be2a2518b28e65f9207c4d05e6ff547d1efa4086469ef855e4ab70178e" + ], + "version": "==2025.1" + }, + "pyyaml": { + "hashes": [ + "sha256:00c4bdeba853cc34e7dd471f16b4114f4162dc03e6b7afcc2128711f0eca823c", + "sha256:0150219816b6a1fa26fb4699fb7daa9caf09eb1999f3b70fb6e786805e80375a", + "sha256:02893d100e99e03eda1c8fd5c441d8c60103fd175728e23e431db1b589cf5ab3", + "sha256:02ea2dfa234451bbb8772601d7b8e426c2bfa197136796224e50e35a78777956", + "sha256:0f29edc409a6392443abf94b9cf89ce99889a1dd5376d94316ae5145dfedd5d6", + "sha256:10892704fc220243f5305762e276552a0395f7beb4dbf9b14ec8fd43b57f126c", + "sha256:16249ee61e95f858e83976573de0f5b2893b3677ba71c9dd36b9cf8be9ac6d65", + "sha256:1d37d57ad971609cf3c53ba6a7e365e40660e3be0e5175fa9f2365a379d6095a", + "sha256:1ebe39cb5fc479422b83de611d14e2c0d3bb2a18bbcb01f229ab3cfbd8fee7a0", + "sha256:214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b", + "sha256:2283a07e2c21a2aa78d9c4442724ec1eb15f5e42a723b99cb3d822d48f5f7ad1", + "sha256:22ba7cfcad58ef3ecddc7ed1db3409af68d023b7f940da23c6c2a1890976eda6", + "sha256:27c0abcb4a5dac13684a37f76e701e054692a9b2d3064b70f5e4eb54810553d7", + "sha256:28c8d926f98f432f88adc23edf2e6d4921ac26fb084b028c733d01868d19007e", + "sha256:2e71d11abed7344e42a8849600193d15b6def118602c4c176f748e4583246007", + "sha256:34d5fcd24b8445fadc33f9cf348c1047101756fd760b4dacb5c3e99755703310", + "sha256:37503bfbfc9d2c40b344d06b2199cf0e96e97957ab1c1b546fd4f87e53e5d3e4", + "sha256:3c5677e12444c15717b902a5798264fa7909e41153cdf9ef7ad571b704a63dd9", + "sha256:3ff07ec89bae51176c0549bc4c63aa6202991da2d9a6129d7aef7f1407d3f295", + "sha256:41715c910c881bc081f1e8872880d3c650acf13dfa8214bad49ed4cede7c34ea", + "sha256:418cf3f2111bc80e0933b2cd8cd04f286338bb88bdc7bc8e6dd775ebde60b5e0", + "sha256:44edc647873928551a01e7a563d7452ccdebee747728c1080d881d68af7b997e", + "sha256:4a2e8cebe2ff6ab7d1050ecd59c25d4c8bd7e6f400f5f82b96557ac0abafd0ac", + "sha256:4ad1906908f2f5ae4e5a8ddfce73c320c2a1429ec52eafd27138b7f1cbe341c9", + "sha256:501a031947e3a9025ed4405a168e6ef5ae3126c59f90ce0cd6f2bfc477be31b7", + "sha256:5190d403f121660ce8d1d2c1bb2ef1bd05b5f68533fc5c2ea899bd15f4399b35", + "sha256:5498cd1645aa724a7c71c8f378eb29ebe23da2fc0d7a08071d89469bf1d2defb", + "sha256:5cf4e27da7e3fbed4d6c3d8e797387aaad68102272f8f9752883bc32d61cb87b", + "sha256:5e0b74767e5f8c593e8c9b5912019159ed0533c70051e9cce3e8b6aa699fcd69", + "sha256:5ed875a24292240029e4483f9d4a4b8a1ae08843b9c54f43fcc11e404532a8a5", + "sha256:5fcd34e47f6e0b794d17de1b4ff496c00986e1c83f7ab2fb8fcfe9616ff7477b", + "sha256:5fdec68f91a0c6739b380c83b951e2c72ac0197ace422360e6d5a959d8d97b2c", + "sha256:6344df0d5755a2c9a276d4473ae6b90647e216ab4757f8426893b5dd2ac3f369", + "sha256:64386e5e707d03a7e172c0701abfb7e10f0fb753ee1d773128192742712a98fd", + "sha256:652cb6edd41e718550aad172851962662ff2681490a8a711af6a4d288dd96824", + "sha256:66291b10affd76d76f54fad28e22e51719ef9ba22b29e1d7d03d6777a9174198", + "sha256:66e1674c3ef6f541c35191caae2d429b967b99e02040f5ba928632d9a7f0f065", + "sha256:6adc77889b628398debc7b65c073bcb99c4a0237b248cacaf3fe8a557563ef6c", + "sha256:79005a0d97d5ddabfeeea4cf676af11e647e41d81c9a7722a193022accdb6b7c", + "sha256:7c6610def4f163542a622a73fb39f534f8c101d690126992300bf3207eab9764", + "sha256:7f047e29dcae44602496db43be01ad42fc6f1cc0d8cd6c83d342306c32270196", + "sha256:8098f252adfa6c80ab48096053f512f2321f0b998f98150cea9bd23d83e1467b", + "sha256:850774a7879607d3a6f50d36d04f00ee69e7fc816450e5f7e58d7f17f1ae5c00", + "sha256:8d1fab6bb153a416f9aeb4b8763bc0f22a5586065f86f7664fc23339fc1c1fac", + "sha256:8da9669d359f02c0b91ccc01cac4a67f16afec0dac22c2ad09f46bee0697eba8", + "sha256:8dc52c23056b9ddd46818a57b78404882310fb473d63f17b07d5c40421e47f8e", + "sha256:9149cad251584d5fb4981be1ecde53a1ca46c891a79788c0df828d2f166bda28", + "sha256:93dda82c9c22deb0a405ea4dc5f2d0cda384168e466364dec6255b293923b2f3", + "sha256:96b533f0e99f6579b3d4d4995707cf36df9100d67e0c8303a0c55b27b5f99bc5", + "sha256:9c57bb8c96f6d1808c030b1687b9b5fb476abaa47f0db9c0101f5e9f394e97f4", + "sha256:9c7708761fccb9397fe64bbc0395abcae8c4bf7b0eac081e12b809bf47700d0b", + "sha256:9f3bfb4965eb874431221a3ff3fdcddc7e74e3b07799e0e84ca4a0f867d449bf", + "sha256:a33284e20b78bd4a18c8c2282d549d10bc8408a2a7ff57653c0cf0b9be0afce5", + "sha256:a80cb027f6b349846a3bf6d73b5e95e782175e52f22108cfa17876aaeff93702", + "sha256:b30236e45cf30d2b8e7b3e85881719e98507abed1011bf463a8fa23e9c3e98a8", + "sha256:b3bc83488de33889877a0f2543ade9f70c67d66d9ebb4ac959502e12de895788", + "sha256:b865addae83924361678b652338317d1bd7e79b1f4596f96b96c77a5a34b34da", + "sha256:b8bb0864c5a28024fac8a632c443c87c5aa6f215c0b126c449ae1a150412f31d", + "sha256:ba1cc08a7ccde2d2ec775841541641e4548226580ab850948cbfda66a1befcdc", + "sha256:bdb2c67c6c1390b63c6ff89f210c8fd09d9a1217a465701eac7316313c915e4c", + "sha256:c1ff362665ae507275af2853520967820d9124984e0f7466736aea23d8611fba", + "sha256:c2514fceb77bc5e7a2f7adfaa1feb2fb311607c9cb518dbc378688ec73d8292f", + "sha256:c3355370a2c156cffb25e876646f149d5d68f5e0a3ce86a5084dd0b64a994917", + "sha256:c458b6d084f9b935061bc36216e8a69a7e293a2f1e68bf956dcd9e6cbcd143f5", + "sha256:d0eae10f8159e8fdad514efdc92d74fd8d682c933a6dd088030f3834bc8e6b26", + "sha256:d76623373421df22fb4cf8817020cbb7ef15c725b9d5e45f17e189bfc384190f", + "sha256:ebc55a14a21cb14062aa4162f906cd962b28e2e9ea38f9b4391244cd8de4ae0b", + "sha256:eda16858a3cab07b80edaf74336ece1f986ba330fdb8ee0d6c0d68fe82bc96be", + "sha256:ee2922902c45ae8ccada2c5b501ab86c36525b883eff4255313a253a3160861c", + "sha256:efd7b85f94a6f21e4932043973a7ba2613b059c4a000551892ac9f1d11f5baf3", + "sha256:f7057c9a337546edc7973c0d3ba84ddcdf0daa14533c2065749c9075001090e6", + "sha256:fa160448684b4e94d80416c0fa4aac48967a969efe22931448d853ada8baf926", + "sha256:fc09d0aa354569bc501d4e787133afc08552722d3ab34836a80547331bb5d4a0" + ], + "markers": "python_version >= '3.8'", + "version": "==6.0.3" + }, + "referencing": { + "hashes": [ + "sha256:381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231", + "sha256:44aefc3142c5b842538163acb373e24cce6632bd54bdb01b21ad5863489f50d8" + ], + "markers": "python_version >= '3.10'", + "version": "==0.37.0" + }, + "requests": { + "hashes": [ + "sha256:2a0d60c172f83ac6ab31e4554906c0f3b3588d37b5cb939b1c061f4907e278e0", + "sha256:f288924cae4e29463698d6d60bc6a4da69c89185ad1e0bcc4104f584e960b9ed" + ], + "markers": "python_version >= '3.10'", + "version": "==2.34.2" + }, + "requests-file": { + "hashes": [ + "sha256:d0f5eb94353986d998f80ac63c7f146a307728be051d4d1cd390dbdb59c10fa2", + "sha256:f14243d7796c588f3521bd423c5dea2ee4cc730e54a3cac9574d78aca1272576" + ], + "version": "==3.0.1" + }, + "requests-oauthlib": { + "hashes": [ + "sha256:7dd8a5c40426b779b0868c404bdef9768deccf22749cde15852df527e6269b36", + "sha256:b3dffaebd884d8cd778494369603a9e7b58d29111bf6b41bdc2dcd87203af4e9" + ], + "markers": "python_version >= '3.4'", + "version": "==2.0.0" + }, + "requests-toolbelt": { + "hashes": [ + "sha256:7681a0a3d047012b5bdc0ee37d7f8f07ebe76ab08caeccfc3921ce23c88d5bc6", + "sha256:cccfdd665f0a24fcf4726e690f65639d272bb0637b9b92dfd91a5568ccf6bd06" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'", + "version": "==1.0.0" + }, + "requestsexceptions": { + "hashes": [ + "sha256:3083d872b6e07dc5c323563ef37671d992214ad9a32b0ca4a3d7f5500bf38ce3", + "sha256:b095cbc77618f066d459a02b137b020c37da9f46d9b057704019c9f77dba3065" + ], + "version": "==1.4.0" + }, + "retrying": { + "hashes": [ + "sha256:bbc004aeb542a74f3569aeddf42a2516efefcdaff90df0eb38fbfbf19f179f59", + "sha256:d102e75d53d8d30b88562d45361d6c6c934da06fab31bd81c0420acb97a8ba39" + ], + "markers": "python_version >= '3.6'", + "version": "==1.4.2" + }, + "rpds-py": { + "hashes": [ + "sha256:0be972be84cfcaf46c8c6edf690ca0f154ac17babf1f6a955a51579b34ad2dc5", + "sha256:127565fead0a10943b282957bd5447804ff3160ad79f2ad2635e6d249e380680", + "sha256:127e08c0642d880cf32ca47ec2a4a77b901f7e2dd1ad9762adb13955d72ffcc9", + "sha256:166cf54d9f44fc6ceb53c7860258dde44a81406646de79f8ed3234fca3b6e538", + "sha256:168c733a7112e071bb7a66460e667edfcff06c017a3c523f7a8a8e08d0140804", + "sha256:1967debc37f64f2c4dc90a7f563aec558b471966e12adcac4e1c4240496b6ebf", + "sha256:1cebd1337c242e4ec2293e541f712b2da849b29f48f0c293684b71c0632625d4", + "sha256:1cf01971c4f2c5553b772a542e4aaf191789cd331bc2cd4ff0e6e65ba49e1e97", + "sha256:1e5822dfc2f0d4ab7e745eaa6d85945069329beeccef965af3f3bb26058fcab6", + "sha256:22bffe6042b9bcb0822bcd1955ec00e245daf17b4344e4ed8e9551b976b63e96", + "sha256:23a439f31ccbeff1574e24889128821d1f7917470e830cf6544dced1c662262a", + "sha256:24e9c5386e16669b674a69c156c8eeefcb578f3b3397b713b08e6d60f3c7b187", + "sha256:270b293dae9058fc9fcedab50f13cebf46fb8ed1d1d54e0521a9da5d6b211975", + "sha256:29dfa0533a5d4c94d4dfa1b694fcb56c9c63aad8330ffdd816fd225d0a7a162f", + "sha256:2a9c6f195058cb45335e8cc3802745c603d716eb96bc9625950c1aac71c0c703", + "sha256:2bfd04c19ddbd6640de0b51894d764bd2758854d5b75bd102d2ef10cb9c293a9", + "sha256:2c54a076ca4d370980ab57bc0e31df57bbe8d41340436a90ef8b1219a3cbb127", + "sha256:2c958bf94822e9290a40aaf2a822d4bc5c88099093e3948ad6c571eca9272e5f", + "sha256:2c99f7e8ccb3dd6e3e4bfeac657a7b208c9bac8075f4b078c02d7404c34107fa", + "sha256:2f7c26fbc5acd2522b95d4177fe4710ffd8e9b20529e703ffbf8db4d93903f05", + "sha256:30c6dc199b24a5e3e81d50da0f00858c5bbdb2617a750395687f4339c5818171", + "sha256:38a2fea2787428f811719ceb9114cb78964a3138838320c29ac39526c79c16ba", + "sha256:3a83ae6c67b7676b9878378547ca8e93ed77a580037bcbcd1d32f739e1e6089c", + "sha256:3cfe765c1da0072636ca06628261e0ea05688e160d5c8a03e0217c3854037223", + "sha256:421aba32367055614287a4292b6a17f1939c9452299f7a0209c117e990b646d4", + "sha256:425560c6fa0415f27261727bb20bd097568485e5eb0c121f1949417d1c516885", + "sha256:4470ce197d4090875cf6affbf1f853338387428df97c4fb7b7106317b8214698", + "sha256:4cf2d36a2357e4d07bb5a4f98801265327b48256867816cfd2ceb001e9754a8f", + "sha256:4f4bca01b63096f606e095734dd56e74e175f94cfbf24ff3d63281cec61f7bb7", + "sha256:501f9f04a588d6a09179368c57071301445191767c64e4b52a6aa9871f1ef5ed", + "sha256:536bceea4fa4acf7e1c61da2b5786304367c816c8895be71b8f537c480b0ea1f", + "sha256:538949e262e46caa31ac01bdb3c1e8f642622922cacbabbae6a8445d9dc33eaf", + "sha256:539d75de9e0d536c84ff18dfeb805398e58227001ce09231a26a08b9aed1ee0e", + "sha256:54f45a148e28767bf343d33a684693c70e451c6f4c0e9904709a723fafbdfc1f", + "sha256:55927d532399c2c646100ff7feb48eaa940ad70f42cd68e1328f3ded9f81ca24", + "sha256:58eadac9cd119677b60e1cf8ac4052f35949d71b8a9e5556efccbe82533cf22a", + "sha256:5e8d07bddee435a2ff6f1920e18feff28d0bc4533e42f4bf6927fbd073312c41", + "sha256:62698275682bf121181861295c9181e789030a2d516071f5b8f3c23c170cd0fc", + "sha256:639c8929aa0afe81be836b04de888460d6bed38b9c54cfc18da8f6bfabf5af5d", + "sha256:67e3a721ffc5d8d2210d3671872298c4a84e4b8035cfe42ffd7cde35d772b146", + "sha256:6de4744d05bd1aa1be4ed7ea1189e3979196808008113bbbf899a460966b925e", + "sha256:6e84adbcf4bf841aed8116a8264b9f50b4cb3e7bd89b516122e616ac56ca269e", + "sha256:7491ee23305ac3eb59e492b6945881f5cd77a6f731061a3f25b77fd40f9e99a4", + "sha256:79486287de1730dbaff3dbd124d0ca4d2ef7f9d29bf2544f1f93c09b5bcbbd12", + "sha256:7b689145a1485c335569bd056464f3243a29af7ed3871c7be31ad624ba239bc7", + "sha256:7f88d653e7b3b779d71ae7454e20dcc9b6bae903f33c269db9f2be41bda3f261", + "sha256:8020133a74bd81b4572dd8e4be028a6b1ebcd70e6726edc3918008c08bee6ee6", + "sha256:808345f53cb952433ca2816f1604ff3515608a81784954f38d4452acfe8e61d5", + "sha256:83e35b57523816c8613fd0776b40cd8bb9f596b37ddd2692eb4a6bb5ab2f8c93", + "sha256:842e7b070435622248c7a2c44ae53fa1440e073cc3023bc919fed570884097a7", + "sha256:847927daf4cffbd4e90e42bc890069897101edd015f956cb8721b3473372edda", + "sha256:882076c00c0a608b131187055ddc5ae29f2e7eaf870d6168980420d58528a5c8", + "sha256:8b95977e7211527ab0ba576e286d023389fbeeb32a6b7b771665d333c60e5342", + "sha256:8bb68f03f395eb793220b45c097bd4d8c32944393da0fad8b999efac0868fc8c", + "sha256:8c2642a7603ec0b16ed77da4555db3b4b472341904873788327c0b0d7b95f1bb", + "sha256:8c3d1e9c15b9d51ca0391e13da1a25a0a4df3c58a37c9dc368e0736cf7f69df0", + "sha256:8c6e5a2f750cc71c3e3b11d71661f21d6f9bc6cebc6564b1466417a1ec03ec77", + "sha256:8d2294a31386bfa251d8c8a39472beee17db67d4f1a6eabea665d35c9a4461c3", + "sha256:8e4320744c1ffdd95a603def63344bfab2d33edeab301c5007e7de9f9f5b3885", + "sha256:8e65860d238379ed982fd9ba690579b5e95af2f4840f99c772816dbe573cb826", + "sha256:8f2e5c5ee828d42cb11760761c0af6507927bec42d0ad5458f97c9203b054617", + "sha256:900a67df3fd1660b035a4761c4ce73c382ea6b35f90f9863c36c6fd8bf8b09bb", + "sha256:913ca42ccad3f8cc6e292b587ae8ae49c8c823e5dce51a736252fc7c7cdfa577", + "sha256:9250a9a0a6fd4648b3f868da8d91a4c52b5811a62df58e753d50ae4454a36f80", + "sha256:931908d9fc855d8f74783377822be318edb6dcb19e47169dc038f9a1bf60b06e", + "sha256:9826217f048f620d9a712672818bf231442c1b35d96b227a07eabd11b4bb6945", + "sha256:9891e594296ab9dada6551c8e7b387b2721f27a67eecd528412e8906247a7b90", + "sha256:9c1255b302953c86a486b81d330d5ee1d5bd937691ce271b6be0ef0e299eaab7", + "sha256:a0811d33247c3d6128a3001d763f2aa056bb3425204335400ac54f89eec3a0d0", + "sha256:a136d453475ac0fcbda502ef1e6504bd28d6d904700915d278deeab0d00fe140", + "sha256:a214c993455f99a89aaeadc9b21241900037adc9d97203e374d75513c5911822", + "sha256:a3086b538543802f84c843911242db20447de00d8752dd0efc936dbcf02218ba", + "sha256:a3450b693fde92133e9f51060568a4c31fcca76d5e53bbd611e689ca446517e9", + "sha256:a550fb4950a06dde3beb4721f5ad4b25bf4513784665b0a8522c792e2bd822a4", + "sha256:a9f4645593036b81bbdb36b9c8e0ea0d1c3fee968c4d59db0344c14087ef143a", + "sha256:aca6c1ef08a82bfe327cc156da694660f599923e2e6665b6d81c9c2d0ac9ffc8", + "sha256:acac386b453c2516111b50985d60ce46e7fadb5ea71ae7b25f4c946935bf27cf", + "sha256:acc992ab27b15f852c76755eb2ab7dce86585ddadba6fa5946e58556088845b4", + "sha256:ae3d4fe8c0b9213624fdce7279d70e3b148b682ca20719ebd193a23ebfa47324", + "sha256:ae50181a047c871561212bb97f7932a2d45fb53e947bd9b57ebad85b529cbc53", + "sha256:ae6dd8f10bd17aad820876d24caec9efdafd80a318d16c0a48edb5e136902c6b", + "sha256:af05d726809bff6b141be124d4c7ce998f9c9c7f30edb1f46c07aa103d540b41", + "sha256:afd70d95892096cdb26f15a00c45907b17817577aa8d1c76b2dcc2788391f9e9", + "sha256:b5c2dc92304aa48a4a60443b548bb12f12e119d4b72f314015e67b9e1be97fca", + "sha256:bc0011654b91cc4fb2ae701bec0a0ba1e552c0714247fa7af6c59e0ccfa3a4e1", + "sha256:bcfbcf66006befb9fd2aeaa9e01feaf881b4dc330a02ba07d2322b1c11be7b5d", + "sha256:bdbd97738551fca3917c1bd7188bec1920bb520104f28e7e1007f9ceb17b7690", + "sha256:c60924535c75f1566b6eb75b5c31a48a43fef04fa2d0d201acbad8a9969c6107", + "sha256:c7b9a2f8f4d8e90af72571d3d495deebdd7e3c75451f5b41719aee166e940fc2", + "sha256:ca6546b66be9dc4738b1b043d5ebd5488c66c578c5ff0fd0e8065313fe3afb76", + "sha256:ccffae9a092a00deb7efd545fe5e2c33c33b88e7c054337e9a74c179347d0b7d", + "sha256:cdc7e35386f3847df728fbcb5e887e2d79c19e2fa1eba9e51b6621d23e3243af", + "sha256:d15fde0e6fb0d88a60d221204873743e5d9f0b7d29165e62cd86d0413ad74ba6", + "sha256:d34c20167764fbcf927194d532dd7e0c56772f0a5f943fa5ef9e9afbba8fb9db", + "sha256:d483fe17f01ad64b7bf7cc38fcefff1ca9fb83f8c2b2542b68f97ffe0611b369", + "sha256:d7469697dce35be237db177d42e2a2ee26e6dcc5fc052078a6fefabd288c6edd", + "sha256:db08f45aecde626498fb3df07bcf6d2ec040af42e859a4f5040d79c200342911", + "sha256:dc319e5a1de4b6913aac94bf6a2f9e847371e0a140a43dd4991db1a09bc2d504", + "sha256:de3eceba0b683bcbb1ab93da016d0270df1f9ae7be716b40214c5dafac6ea45a", + "sha256:dfcc8b909769d19db55c7cc9541eb64b9b774b1057ffffb4f1048070475bb9f9", + "sha256:e059c5dde6452b44424bd1834557556c226b57781dee1227af23518459722b13", + "sha256:e4316bf32babbed84e691e352faf967ce2f0f024174a8643c37c94a1080374fc", + "sha256:e52655eaf81e32593abedaa4bfe33170c8cfedf3365ed9be6e11e07f148f0278", + "sha256:e55d236be29255554da47abe5c577637db7c24a02b8b46f0ca9524c855801868", + "sha256:ea7bb13b7c9a29791f87a0387ba7d3ad3a6d783d827e4d3f27b40a0ff44495e2", + "sha256:ea964164cc9afa72d4d9b23cc28dafae93693c0a53e0b42acbff15b22c3f9ddd", + "sha256:ec829541c45bca16e61c7ae50c20501f213605beb75d1aba91a6ee37fbbb56a4", + "sha256:ecabd69db66de867690f9797f2f8fa27ba501bbc24540cbdbdc649cd15888ba6", + "sha256:ed0c1e5d10cdc7135537988c74a0188da68e2f3c30813ba3744ab1e42e0480f9", + "sha256:f0840b5b17057f7fd918b76183a4b5a0635f43e14eb2ce60dce1d4ee4707ea00", + "sha256:f4d78253f6996be4901669ad25319f842f740eccf4d58e3c7f3dd39e6dde1d8f", + "sha256:f56f1695bc5c0871cbc33dc0130fcf503aab0c57dcc5a6700a4f49eba4f2652e", + "sha256:f826877d462181e5eb1c26a0026b8d0cab05d99844ecb6d8bf3627a2ca0c0442", + "sha256:f8f23ead891a3b762f35ab3b04623da7056545b48aa60d59957e6789914545da", + "sha256:f90938e92afda60266da758ee7d363447f7f0138c9559f9e1811629580582d90", + "sha256:faa679d19a6696fd54259ad321251ad77a13e70e03dd834daa762a44fb6196ef" + ], + "markers": "python_version >= '3.11'", + "version": "==2026.6.3" + }, + "s3transfer": { + "hashes": [ + "sha256:ea3b790c7077558ed1f02a3072fb3cb992bbbd253392f4b6e9e8976941c7d456", + "sha256:eff12264e7c8b4985074ccce27a3b38a485bb7f7422cc8046fee9be4983e4125" + ], + "markers": "python_version >= '3.9'", + "version": "==0.14.0" + }, + "scaleway": { + "hashes": [ + "sha256:b1f9dd1b1450767205234c6f5a345e5e25dc039c780253d698893b5c344ce594", + "sha256:dbf381440d6caf37c878cf16445a63f4969a4aac2257c9b72c744d10ff223a0c" + ], + "markers": "python_version >= '3.10'", + "version": "==2.10.3" + }, + "scaleway-core": { + "hashes": [ + "sha256:56432f755d694669429de51d51c1d0b3361b28dc2f939b28e4cb954610ee76be", + "sha256:fd4112144554d6adae22ff737555eeb0e38cb1063250b3e88c9aebc1b957793b" + ], + "markers": "python_version >= '3.10'", + "version": "==2.10.3" + }, + "schema": { + "hashes": [ + "sha256:f06717112c61895cabc4707752b88716e8420a8819d71404501e114f91043197", + "sha256:f3ffdeeada09ec34bf40d7d79996d9f7175db93b7a5065de0faa7f41083c1e6c" + ], + "version": "==0.7.5" + }, + "setuptools": { + "hashes": [ + "sha256:51a52592b3b99e102b609654876bd65f19f999935166d1352678931132b0c670", + "sha256:f4695c21257f0d9b537ec2692c941d02ee143b7cc1276941349a546573b2ef73" + ], + "markers": "python_version >= '3.10'", + "version": "==84.0.0" + }, + "shodan": { + "hashes": [ + "sha256:c73275386ea02390e196c35c660706a28dd4d537c5a21eb387ab6236fac251f6" + ], + "version": "==1.31.0" + }, + "simplejson": { + "hashes": [ + "sha256:036a27bd0469b9d79557cbddb392969f876cd7f278cfbd0fba81534927a06575", + "sha256:0662cfe0482c9796bd097213b27f006815bfdc9b671264c3c0b7fc0e72b71d00", + "sha256:0da5c9f57206ee7ef280ff7f1d924937b0a64f9a271a5ef371a2ecdbebba7421", + "sha256:0e4b23f71dd781f8830f1663dc01a4944d3dbf87a1f93d78fba1cf64722d0ccf", + "sha256:10048ab9b9e0f7e95f1680829f0925a63b190fa8e8e9bb91369538fe382df827", + "sha256:104d8324c34f25b4b90800bc5fa363780cbc3d8496aef061cba7ce1af9162270", + "sha256:110a14b2702e9fa01d13d510b66bcf823c9ddd700bd0050301bfbd1bcdf95991", + "sha256:112b37ba2ff805da9e657c05b4ffa1a7428eaa191918af106dfacc5ab70663d4", + "sha256:14465703aa66668cc1b697ec834c4d1566b72464f92d3ba4cb00ecd2c4438b2d", + "sha256:1778e09a6e4bb4ef304627915dc4a838569d9e6b737c787925b4e98244bbbc16", + "sha256:19040a17154dc03d289bab68d73ce0a6a0be01de30c584bbdd93490bead14b22", + "sha256:1ad45da7462afc3dc4a0fe374a40b62f816821b046297b4acc670e641e45cc8d", + "sha256:21d1b82f5d58f776a184a42bdf5ce4a6d7c36191a917131c577b41019f6b7daf", + "sha256:225c9caa324c5b554d009fb9cac22aee7711e71bd96f487938c659af467e828e", + "sha256:249e2e220aa6d9b9d936bde84eb7bf79d5b6c5a8273c6e411f8b1635a9073f2d", + "sha256:25773dbc326799824767d40921e88a8f07c5bf1a0738884fb16cab574610aa28", + "sha256:2669ff10c7090ae9099afa9f7ae3a8c1a5170e78f18c7011dd8d5ce73beba6c0", + "sha256:2785ff8edc0e28bf773a32543a6bbed46351453c997b3f6709c744e3c2f7eabb", + "sha256:2867c64d92abd1992c15666fae198203093f593e43d6b81adf176bae530d493a", + "sha256:2ce92b3748f02423e26d2bfb636fb9d7a8f67c8f5854dcae69d350d123b2eee2", + "sha256:2e0d5ead6d14610467ec356ec1f6b5d8a56aa216abaad8d41c8b873b16cf313f", + "sha256:2e708d373a10e4378ef2d59f8361850c7150fd907ed49efe49bc5492160476d1", + "sha256:30944f06a9c0787a8c69d8295b3abc960161f08b5ce26d41be88d2bc5539ea3c", + "sha256:3427a069695405658b2270989d9e6f03f39e34a24d1b8548b562abc282ee400b", + "sha256:37233c72ce88d06acb92747347742b3c07871eba6789f060c179c9302dde8efe", + "sha256:3851658d642c1184d2023f0e6c9ce44a21eb1629e74e7c84ef956b128841fe12", + "sha256:39e3c584071dced8c21b4689f0254303521daeb9b5bc1f4289755d71fa3cb0d3", + "sha256:42ee1aeaa295364bb2c079c42c5796bf1db4b0d5c4bf95f2fcdddba770618cb4", + "sha256:43fa9a1ccf477e415c025ba507ada54984f5ed927d28d304cf50e089818818b0", + "sha256:4484960512db9c8124bfa91e0d8a9f9c302338f1c5454e74c21d7d022df10f46", + "sha256:453a25bcad03b1ec4584998c58c27c5eb54148e13bcbf49b796f953048349c78", + "sha256:45ec18e337fec538b7e902d489505c450b2454653d1290f3f50385e6fd8aa607", + "sha256:4c1eecc2d6a186eaf5d111cf9b311fa9a9ecf68703db7b63ed5938049f3e74f5", + "sha256:4c44ef6b02a4eb67ed17a72342341792149b3ff46f15426c26e970e49addf327", + "sha256:4c47c46e16c8ea9e4850061e6ed5aa2b9cd2074cb2274bfd9c138cba15ce7453", + "sha256:4cbb299d0528ec0447fe366d8c9641860e28f997a62730690fef905f1f41046e", + "sha256:5f09293dc60ca29b4d588583f0423863d1e9faa0074fdbf00a9955ecc6365331", + "sha256:604b8d73f396078c122f696c2fa5f3527a00667633863560096180baf1356257", + "sha256:617e36ae79f4d53c91a4aec95eb09c469ef28fdec7926821254505a1de920e3f", + "sha256:63a5451f557d6be48a231bae932458655c620902b868170b2f1c8afed496f6b4", + "sha256:63c2ada8e58f266491f19eed2eeeb7c25c6141e52f8f9e820f6bb94156cf8dbc", + "sha256:642cec364e0676e2d5a73fa4d31d0c7c55886997caa2fde24e8292ca44d32728", + "sha256:67341c95c0a168ab4a6d1e807e50463f1c8da932c3286d81e201266c427061fa", + "sha256:677fbb192b2cbefb3dc21862eaf0bf560b4b370662503036c513f1e3eb32dfac", + "sha256:67e43e7c0555e10de6d83e1408035652fad28c983516e38c4e3a9a748c9af129", + "sha256:68e62eda21192c5ea9bb92d571ca46a4477fef48762f50d433de2b4253051551", + "sha256:6bbc61cd7982ff77a68df06d103a3ba459eefd1d3cb6f4f4944cdf9f091d7bf7", + "sha256:6c845363eb5fd166fb7c72243da38f4fcfde666ede7fdf2cc6fd7762894626f7", + "sha256:76fe296ca1df23d290033f10aaacf534fd1b3e3007e7f9ff8aa68b21413aaa78", + "sha256:78a3fe0995be42bed62a26aa78e0e0b4d87c6545785346b9cc898f3389569a35", + "sha256:797ad726434bf23c47a1e51140b6d1afb35471984c8fd31db76ba375fc0a296d", + "sha256:7c0573d7370232d71616653080e397df61d4daf1cd7d6a717f23fd21eda90731", + "sha256:7ce252b28fddbdd83db5bd7d93dad2a8a591d7ada098afec9c1b23d6b722a7a4", + "sha256:7f61eefab86235c800e7f4e37d977080ec424bb2bf0b74e95a2d17ecb48eac0a", + "sha256:820c69a4710400e9b248d5670647d60be58824369282d3925e516b3ff1a7cd82", + "sha256:82bfca2b85a34178c25829c703f0a9e9f113a5af7539285bd3efb583a0bf1ba3", + "sha256:82e42ff58ee856f4029c732d35673dbe62d589445a8e6c3c98ced8fd78096617", + "sha256:82fee635d7b73ad801030b05a75fbd34a098da0c2ecf600667a03636d09e1e42", + "sha256:861e393260508efa64d8805a8e49c416c3484907e3f146ce966c69552b49b9a3", + "sha256:8b2da172a6ff43f74463522a1aa1d7a481ac2dba2de4b18ed51e989190352ba7", + "sha256:8e5cdd6a5d52299f345c15ab5678cc4249e24f383f361d986afbc3c7072a6b6b", + "sha256:8eb821ef27f688f59ed4a93b17a666a7ebacf8dd65fecaa2b3c531a3aea62eaf", + "sha256:8f0ad25b7dc4e0fb23858355819f2e994f1a5badcdcde8737eac7921c2f1ed2a", + "sha256:93bf6653420258372444de90194dab8de8ff13d74b5d4263a5fefbbe8b8d2060", + "sha256:95407269340c7f22f09776ea7b717a52cf56cfcf119b5e45f66faa4a26445bea", + "sha256:95a3bb0f78e85f4937f99092239f2011ce06f0f2d803df5c299cc05abbeae008", + "sha256:971aed0647ad6e840a3943bec812fcda5f2d26a5497a4981d1fb49aa4f9a396c", + "sha256:97a02325a00617c26cfc974f4ebb191c8de6e87cb96d33e51612091150637c3d", + "sha256:980fc33353f81fd12d8c49d44f8c2760d1dc8192285e627c5180d141035b228a", + "sha256:a59ebd0533f03fd06ff0c42ba0f02d93cbcdd7944922bf3b93911327a95b901f", + "sha256:a6525ec733f43d0541206cffa64fd2aad5a7ae3eb76566aff49cd4db6382209a", + "sha256:a94ebaecdbaa80d9551a3ec6bf0c9302fc8b53ab6c1b2bfd498a1df4cb28158d", + "sha256:a9ab55d2459f6d0fdf9984a7a0fb0280dae12979f4fcc3171f5096a4fcf5fafe", + "sha256:b70bfd2f67f3351baba08aa3ae9233c83f21fd95ae5e6b3d0ecb8c647929112f", + "sha256:b75c7ef874dbb350f41827cdf3cee23f5257bdcb0df46d4c01b34badb62dcfe8", + "sha256:bbfdaa7c0603f75b7b14b211b7f2be44696d4e26833ad2d91d5c87bf5fb9a920", + "sha256:bccbf4419676b517939852e5aeff2af6aee4dc046881c67a1581fa6f1cb01abd", + "sha256:c08eb9f7a90f77ae470e19a07472e9a79ebc0d1c2315d86a72767665bd5ba79f", + "sha256:c65c763fb20d7ca113c1c14dce2fc04a0fc3a57aceff533d6fdac707c7bffb40", + "sha256:c7494c75b95171194f965ea609e97081837a26494d91dcc046ad27dd9c3503e2", + "sha256:c7876ec2ef53ff5e6714a382b3f8f042a744b944728ae0baef99421740cc57a3", + "sha256:c996a4d38290c515af347740659ce095b425449c164a5c9fa3977caa6eff5dbe", + "sha256:cc0442dea71cd9cbf30a0b8b9929ab5aa6c02c0443a3d977351e6ec5bada4388", + "sha256:d083b89d30948a751d3d97476c2ed91e4caaa24a1a1459bdbadb8876242c71fe", + "sha256:d1fffb56305c5b475ee746cf9e04f97423ba5aaacd292dc1255bd75b1d3b124b", + "sha256:d75cea7a1025edd7e439b2966b3d977c45b5b899e2adaf422811b3ac702ed9fb", + "sha256:de2ed102fff88dacf543699f53ee3a533cc11539a39baa176b7e09dd783069d6", + "sha256:dfb84ace97acbdf1916c5a675387493fc5a7f67c2e15d4a7687143f8c73024d4", + "sha256:dff52fc7af272e84fc21cc5a06c927c823ca6ae00af14f3b0d7707b42775ed98", + "sha256:e2778625bd6c839588373f07d7ade6fc0fb6b8365a146b84f27edfadb13ab597", + "sha256:e294e33dbf316a9bbdd4030d46503c9b0f19470ae7ad6af5bae6c426bc2e869f", + "sha256:e338a0029a0e8e4da2657b63a8df39b0269007dc9b506eadacca384519b2bd9c", + "sha256:ea3426e786425d10e9e82f8a6eda74a7d6eb10d99165ac3d0d3bbcb65c0ea343", + "sha256:ed7473602b6625de793b6acba49aa949f144a475f538792067e4cf2fda2071f5", + "sha256:f42a7911f64ed8f738ba55480c20d5c685851781d411f9473cafa7a643e52fe4", + "sha256:ffd3d82294b47f5ec64050021ace95fd62628a0c1cc8bbf4d06d2d1fb697e055" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7'", + "version": "==4.1.1" + }, + "six": { + "hashes": [ + "sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274", + "sha256:ff70335d468e7eb6ec65b95b99d3a2836546063f63acc5171de367e834932a81" + ], + "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2'", + "version": "==1.17.0" + }, + "slack-sdk": { + "hashes": [ + "sha256:6a56be10dc155c436ff658c6b776e1c082e29eae6a771fccf8b0a235822bbcb1", + "sha256:b1556b2f5b8b12b94e5ea3f56c4f2c7f04462e4e1013d325c5764ff118044fa8" + ], + "markers": "python_version >= '3.7'", + "version": "==3.39.0" + }, + "sniffio": { + "hashes": [ + "sha256:2f6da418d1f1e0fddd844478f41680e794e6051915791a034ff65e5f100525a2", + "sha256:f4324edc670a0f49750a81b895f35c3adb843cca46f0530f79fc1babb23789dc" + ], + "markers": "python_version >= '3.7'", + "version": "==1.3.1" + }, + "stackit-core": { + "hashes": [ + "sha256:04632fc6742790d08ddfcb7f2313e04d1254827397a80250f838a2f81b92645b", + "sha256:b8af91877cdb060d6969a303d8cf20bc0b33b345afd91f679c44a987381e2d47" + ], + "markers": "python_version >= '3.8' and python_version < '4.0'", + "version": "==0.2.0" + }, + "stackit-iaas": { + "hashes": [ + "sha256:3f4a32321b57ac238f73e5d660c6428186b92cc0425c1f0783ba801e377149d9", + "sha256:93523b23442350c7ebefd9129485c4c2a539f694a9c36a0f8edfaba9862057ea" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.4.0" + }, + "stackit-objectstorage": { + "hashes": [ + "sha256:1a3285c6840d95cff591d84fd21803575cb0d010c398e6575ed92987b9c39866", + "sha256:4a3812b4de102b199f061706a802909f9e53ae9b0858769d5bd720f814c8bdbe" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==1.4.0" + }, + "stackit-resourcemanager": { + "hashes": [ + "sha256:dd04bb8353d041a137c4dcba190beabded7acfaff1bc98b218fce20a99389ebc", + "sha256:f44542beab4130857f5a7f465cf02defeef657bdf63c1beeb3102f0ba3c003fe" + ], + "markers": "python_version >= '3.9' and python_version < '4.0'", + "version": "==0.8.0" + }, + "std-uritemplate": { + "hashes": [ + "sha256:42b702d8d7eb8c13b586c527b8f2edaff456b69fee88e817d2f5dc5f088b8765", + "sha256:c245e6d9c6804e435c45fa94ee4a3c8a57e08aeeb45af261101cb0d513964534" + ], + "markers": "python_version >= '3.8' and python_version < '4.0'", + "version": "==2.0.12" + }, + "stevedore": { + "hashes": [ + "sha256:abbd0af7a38a8bbb1d6adea2e35b17609cf004eaac323e88a8d8963640dd2b3c", + "sha256:e520945d4c257700eddc1eb1d79df04b2ea578eef185e0e3fa5b442fc848d3f7" + ], + "markers": "python_version >= '3.11'", + "version": "==5.9.0" + }, + "tabulate": { + "hashes": [ + "sha256:0095b12bf5966de529c0feb1fa08671671b3368eec77d7ef7ab114be2c068b3c", + "sha256:024ca478df22e9340661486f85298cff5f6dcdba14f3813e8830015b9ed1948f" + ], + "markers": "python_version >= '3.7'", + "version": "==0.9.0" + }, + "tldextract": { + "hashes": [ + "sha256:6c90d2a259f5c89f4fcf01f97af15708416a59ffedddff006d67222ab30d0fb0", + "sha256:c017431bc0800f2d3d1b57cce36e06668f0930f60a6d8c4615d4e2b8da298fa9" + ], + "markers": "python_version >= '3.10'", + "version": "==5.3.2" + }, + "typing-extensions": { + "hashes": [ + "sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8", + "sha256:dc983d19a509c94dba722ee6abd33940f7c05a89e243c47e907eb4db6f1a43e5" + ], + "markers": "python_version >= '3.9'", + "version": "==4.16.0" + }, + "typing-inspection": { + "hashes": [ + "sha256:547274fa6b0a561ccf549cc9524b999a578e737d015d8709d021f9d0d13bea47", + "sha256:65b8397ba37ccbce054456aaccddfc91e6e3083c92824df348d96ca832f3f147" + ], + "markers": "python_version >= '3.10'", + "version": "==0.4.4" + }, + "tzdata": { + "hashes": [ + "sha256:4a1518b8993086a7982523e071643f3c0e5f213e75b21318e78bcabfff9d1415", + "sha256:dc096730c87af6cab1b171c9d532be840741ff5d459015e7f6947bd7d7e54931" + ], + "markers": "python_version >= '2'", + "version": "==2026.3" + }, + "tzlocal": { + "hashes": [ + "sha256:cceffc7edecefea1f595541dbd6e990cb1ea3d19bf01b2809f362a03dd7921fd", + "sha256:eb1a66c3ef5847adf7a834f1be0800581b683b5608e74f86ecbcef8ab91bb85d" + ], + "markers": "python_version >= '3.9'", + "version": "==5.3.1" + }, + "uritemplate": { + "hashes": [ + "sha256:480c2ed180878955863323eea31b0ede668795de182617fef9c6ca09e6ec9d0e", + "sha256:962201ba1c4edcab02e60f9a0d3821e82dfc5d2d6662a21abd533879bdb8a686" + ], + "markers": "python_version >= '3.9'", + "version": "==4.2.0" + }, + "urllib3": { + "hashes": [ + "sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c", + "sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897" + ], + "markers": "python_version >= '3.10'", + "version": "==2.7.0" + }, + "uuid6": { + "hashes": [ + "sha256:2d29d7f63f593caaeea0e0d0dd0ad8129c9c663b29e19bdf882e864bedf18fb0", + "sha256:93432c00ba403751f722829ad21759ff9db051dea140bf81493271e8e4dd18b7" + ], + "markers": "python_version >= '3.8'", + "version": "==2024.7.10" + }, + "websocket-client": { + "hashes": [ + "sha256:9e813624b6eb619999a97dc7958469217c3176312b3a16a4bd1bc7e08a46ec98", + "sha256:af248a825037ef591efbf6ed20cc5faa03d3b47b9e5a2230a529eeee1c1fc3ef" + ], + "markers": "python_version >= '3.9'", + "version": "==1.9.0" + }, + "werkzeug": { + "hashes": [ + "sha256:63a77fb8892bf28ebc3178683445222aa500e48ebad5ec77b0ad80f8726b1f50", + "sha256:9bad61a4268dac112f1c5cd4630a56ede601b6ed420300677a869083d70a4c44" + ], + "markers": "python_version >= '3.9'", + "version": "==3.1.8" + }, + "wrapt": { + "hashes": [ + "sha256:0a45ffae742ce91a16e11cb6c7cd71e7f9994f3cbd283b962ab093f5c6dcf525", + "sha256:0bb2797048db0956348cb3058c33bc4184614f13231389cfbccc16a5d32780a7", + "sha256:0d3fb71e65b001adfc42684522eeccd9c21d8ba679945abc993439567b66e59f", + "sha256:0db083387d6e75ec0be8173ecbf0e811cf60bae1cc75a815feb104167ea10d4d", + "sha256:10461884b3014fbfc8eb7d09a93c5f246363e6711d9d881f95eb8c27fdef049f", + "sha256:1236fa25173ca964c97422470482e9011b9e3c7ed0d75798b40b3da3b0e0e760", + "sha256:141ed6211286a9660d8d6702de598b43f0934b4f0eda16393f100a80f501d945", + "sha256:1598becd30f8f2777d18564064eb4f4dbe1ab0e05a8f09786d0ef505ac782bf3", + "sha256:195b1842b4122fb54e3cd3dd5b2b4aa49302a5a61da901df0481f5c97aedde84", + "sha256:1d6159c9b2fefec02314e1332dbbbfaf960e369dfd26bcf7f8b258b5732065b3", + "sha256:22cc5c0a717bd4da87018ae0bffd4c19c6fb679d3ff357216ba566ab26c76cab", + "sha256:242b60c21e30866e6a2fa606c612b47c553fa60c0eaeeeb7797fb842ac0ce609", + "sha256:24da48596326ef8e448cfa837b454f638713d3531262375f00e5a9681682fc07", + "sha256:261f53870cd4fb2bf38f9f972c56c728fd224cb7c65721307de59d9e7e6741ae", + "sha256:2935d5454b3f179a29b12cf390ee47246740ba2c3a7545b1b46ba31a5f2a4a0b", + "sha256:2e49885a62ec4ee854d1b9e6371fda6afd219917225752abf729a3f36d4df9a5", + "sha256:379f670f45b7bb8993edd9f6fc36c6cc65edb81cffa0b504be34acb0303fff0a", + "sha256:3873c3c5ca9f4ef91f693602eca19d1f1e7c410338df82a4ff11d826b5896a8f", + "sha256:392158c9a7f2ab1b8699418bfc0fe6f83548788c418b27d7bf2019ad3405cebb", + "sha256:39febbee6d77301d31da6996b152ce52452da7c7ef72aba10c2fa976dff9c295", + "sha256:3d1c2c1b808600d2ea808e6360910a60ed5f409a4011655e10f9164ba0a414a6", + "sha256:3da470536bf9645143323dd41b32db55c6f4304ad382094c1a1da8a92061e10d", + "sha256:418f54bb09d1762db02c7009b4051149893af3153a87f92d70356703c11eea02", + "sha256:42869085687f0aefd57c0f636c3f9354f8ffb321a8ba9cb52d19beb796e561c5", + "sha256:45c9279b373d15649dfa2c2077cb3408ea1a6d3125afbdab9d6b809a66f68e14", + "sha256:4fa0df3bff4e7ce45759f33fd39335fe2f60477bb9ecf7b8aa41e7d07ee36a23", + "sha256:50f416b74d092bb9f41b424e90dd457f365f7ba4b11de62a23679769a21bd85c", + "sha256:51a7a4181c1295774812271fbcd7c909df372bc25579d4ed9eb875caaf0ae86f", + "sha256:54ca1d5573f69b5fe1d74f1f65799c68015e82f685efec9fd8cfa40a094c44d0", + "sha256:5ab559e1b2551d23d54db2a0001c6d73bad022a254639561c5f6c382a9d6c2fe", + "sha256:5ba1e5e08ddc46130e9682b2c249f2d1dd39bda9106ed4bd401b7519f18f41bd", + "sha256:5d221a6e6ddd302b8397433184e96b59f259f50024b854db1c411a881586b6b8", + "sha256:6208f302f110295d64b22a7ac96500c791bf492dce4366e622e4912b077c9687", + "sha256:626b69db2021aa01671ec7bbc9740e558522bd44c18cf2ce69bf3d666a014109", + "sha256:628f3ba8ec793a5b10a6cd8c6c6b7b55eb552abd1f3bd301336acb74c7a82dfe", + "sha256:629d73378082c00a8173031f9fb30a3ac6abbc894a5bfdfae71fabc60642d501", + "sha256:646d20d413ffcd1b0a2f700076e2d0252d872dcb7754860a73e45a59ea883614", + "sha256:67bfe2485f50368c3fcd2275fc1fd100e350d601e0058921a7c82678a465aeab", + "sha256:681a2d0eefd721998f90642762b8e75c2159ec531b20ad5e437245ea7b06a107", + "sha256:69e477046f2237ef0bc6547544ee73008dc764ca26eff44f09e976d221b34d5d", + "sha256:6db604ef0c67bdb2042ecdfd7b7f037cf09733557ca42360d1018285634f7b98", + "sha256:729126e667da34d251b8ebf8a45ef0c5ddadc21542b3d6e1abf4259ece6508df", + "sha256:73d0b10b64620a2cf4bc3d31775c4d9527e309a5549e4379e3bf71e8d2dc193e", + "sha256:7ebb274aba688b043429eb1500ff8a76ce0cb8ac0812ca3e301f06247b8722b3", + "sha256:8159ec0b0cb7608175eb150de94c19e34f4d47ac655f5ca9baf45df6b688ffd3", + "sha256:816877aa749253149f9ecfd2635d4d948ecfa338e1a0311d187b1acb1bb8a3eb", + "sha256:85de890ff968196e92dd1ae73a9fb8970495e7650a457b1c9ef0ac3dd550bce2", + "sha256:8f8a1c6472675956cece9a8f403f43c3594f1681319eed2dd56f60877397c636", + "sha256:9045917809c63fdf7abe3a2ceaed3d670b8ee4500ddd9291192d30aeb34467c5", + "sha256:932dced0a7b2950ed58a3325536a1dcb7b58e7330af54e8552d2e566b5328b99", + "sha256:93513bec052c6cd987f9f580c3df068c8bc4ebae6543736be3ca7ec5959cafcd", + "sha256:9790ea25190a4e0fe4cdf4eeb868e9d75f8a024a70a5b6bf9c348a3a2b72e731", + "sha256:9f5d2aec29dfc76c37e23897dee92766a3fd4f3bff3ae7fc9c6b4bf37d8c1360", + "sha256:a65e8db2b4e90c2e7ade931086351c98ef420bf7a94ee08c95ac8a3cbbc43579", + "sha256:a6b5984cd65dd639546f0eb4b8eacf1c31cb2fe9fb5c27bffe240987cdb2cf84", + "sha256:a6e19531ae33c508cea7d84a7edfda01fa86e51b8d1a93a77712c55e6e469152", + "sha256:abc71504669d126d91f89fc0e388c6295d8fbd2439be884f175133fda8aa403c", + "sha256:ac870cc97b73bb00ac353329e9559a4bebc47c4c86792ed9b23b58c15b6ad838", + "sha256:ad71df7a04dd3497e9302e81f4a7c91bd401ea0e15a9df9029527900f94bee43", + "sha256:b1e5aa486e269b00ed35e64771c7d0ab8096cfd2643405ca8cd60ebedc099a51", + "sha256:b4fc96b159af0a3e0faa72475a69d66292bea72a5bed1e1aca1bffbddc3cb2b0", + "sha256:b767a9566f165dd14decf8f4194c6bb0ce3a8420cec213824e05a99400c9260a", + "sha256:bff9a671bc00709cab5a7f745c592b5671873449db0ee2a569af994f16b29a4d", + "sha256:c3b476ae63b4a3b4da681aafcb25ff3542d289fbda8b5da7caf76aaffafafdbb", + "sha256:c4bded758ad6f03b965830944a2f0bc5b2eb3767fe5a7310134315d1a6610e98", + "sha256:c8388ba7faf5dbf9ee106bb70d66f257629b1bd98091123e19e8a4553a319199", + "sha256:c8858d8ff9822a081e3cc49ae1b3b22f0f789c14001cdac8f94564010d9c9d66", + "sha256:c88abcf53daef80e01a75c7530e727fa6e2c1888fe83e3dcdba4c96216a1f5c7", + "sha256:cc2cea812e5cb179a796b766747e7d3b21088760d8deb95676d482b8c8e6fa7d", + "sha256:cd3a2edf0427013736b8127955cec62608c56e53ea47e82812ea32059cda407f", + "sha256:cdc021cb0b62471d6aac7f2bd92f3b4658073775f9ee7fcd325c511129e7bcc8", + "sha256:ce9f398f868d2b3b27aa2ea4de79645ef9077aeeac8dfc2814b0d542c6a2b87f", + "sha256:d0077f3d65541925fa83002f967b22ad6550d24813ac64cb905f717194128d9c", + "sha256:d0f7284f88f4833705132d06d3b425a43095c2cbd07c58166aac3ab646ba12a4", + "sha256:d2cc64539da63e39ffb9c7ede849b6e8ddaaf7b3876b5cfb04efd85a5f3f4eb6", + "sha256:d8c7ed08477429752b8c44991f40ad7838b18332a160698740a6bfbc10d998a2", + "sha256:df4ce31150bcd5d9f36f816aac3010ab4f4bf8672ac1d3b0ac7d539ec61c7c02", + "sha256:e045ff75d7d94900fc32896ed93c45ce2d2cac28c9dead582ff9a5a49d446e35", + "sha256:e2e692bc0d63f881cf7006730a56bd4e0c2fab5dc318466942805d692b166276", + "sha256:e31734c5077f29f892b2565eee5106d610278151ad49fc6a9d69a647cd5730e2", + "sha256:e3b9eaa742ae7a0aaaaad4ca4b69469d757af2d6e6663ef1dadc47adec0aeb41", + "sha256:e3f3d7ec0a51fbfe00d3aef047641ff2c58b25565b4717fc1f90e050be01cba8", + "sha256:e5301c35cf75655eb33498f2bd6ae8703ca19940e3167dc9cdf740c712a39c60", + "sha256:ea52a0d0f08c584943d5764be0e84efa912c8da23c23e1e285ff2f5641c18fcc", + "sha256:ed635a9ca4f3a5a2b900c10c69e823373bc00ebc114b459383596d3487da3570", + "sha256:fb8e2e6704a1e0b1b989546c69e2688371ef4a07fa5f61bde3eb6211186f5ac1", + "sha256:fc648a335d7e01adb3640b25f02fd0ea05886cf04d0af7f4ee902bc7b5e466e8", + "sha256:fc82c2ccc8e234c844f5303d9f2984b346dcdd53e94823ce8420d2c75b4b9023", + "sha256:fd1f2f557dd3491fe75905e578f4db967393d40d1a8f468edc4d40ac7f2d5944", + "sha256:fd85b0aa88efdb189d6ae2f35f4526943a8f091c38599c9c31478241c819e6a1" + ], + "markers": "python_version >= '3.9'", + "version": "==2.3.0" + }, + "xlsxwriter": { + "hashes": [ + "sha256:254b1c37a368c444eac6e2f867405cc9e461b0ed97a3233b2ac1e574efb4140c", + "sha256:9a5db42bc5dff014806c58a20b9eae7322a134abb6fce3c92c181bfb275ec5b3" + ], + "markers": "python_version >= '3.8'", + "version": "==3.2.9" + }, + "xmltodict": { + "hashes": [ + "sha256:6d94c9f834dd9e44514162799d344d815a3a4faec913717a9ecbfa5be1bb8e61", + "sha256:a4a00d300b0e1c59fc2bfccb53d7b2e88c32f200df138a0dd2229f842497026a" + ], + "markers": "python_version >= '3.9'", + "version": "==1.0.4" + }, + "yarl": { + "hashes": [ + "sha256:0055afc45e864b92729ac7600e2d102c17bef060647e74bca75fa84d66b9ff36", + "sha256:0465ec8cedc2349b97a6b595ace64084a50c6e839eca40aa0626f38b8350e331", + "sha256:0ebfaffe1a16cb72141c8e09f18cc76856dbe58639f393a4f2b26e474b96b871", + "sha256:16a2f5010280020e90f5330257e6944bc33e73593b136cc5a241e6c1dc292498", + "sha256:17f57620f5475b3c69109376cc87e42a7af5db13c9398e4292772a706ff10780", + "sha256:2120b96872df4a117cde97d270bac96aea7cc52205d305cf4611df694a487027", + "sha256:240cbec09667c1fed4c6cd0060b9ec57332427d7441289a2ed8875dc9fb2b224", + "sha256:24e861e9630e0daddcb9191fb187f60f034e17a4426f8101279f0c475cd74144", + "sha256:2729fcfc4f6a596fb0c50f32090400aa9367774ac296a00387e65098c0befa76", + "sha256:2c1fe720934a16ea8e7146175cba2126f87f54912c8c5435e7f7c7a51ef808d3", + "sha256:2cabe6546e41dabe439999a23fcb5246e0c3b595b4315b96ef755252be90caeb", + "sha256:2dbe06fc16bc91502bca713704022182e5729861ae00277c3a23354b40929740", + "sha256:3363fcc96e665878946ad7a106b9a13eac0541766a690ef287c0232ac768b6ec", + "sha256:377fe3732edbaf78ee74efdf2c9f49f6e99f20e7f9d2649fda3eb4badd77d76e", + "sha256:3ac6aff147deb9c09461b2d4bbdf6256831198f5d8a23f5d37138213090b6d8a", + "sha256:3f45789ce415a7ec0820dc4f82925f9b5f7732070be1dec1f5f23ec381435a24", + "sha256:4103b77b8a8225e413107d2349b65eb3c1c52627b5cc5c3c4c1c6a798b218950", + "sha256:4377407001ca3c057773f44d8ddd6358fa5f691407c1ba92210bd3cf8d9e4c95", + "sha256:46c2f213e23a04b93a392942d782eb9e413e6ef6bf7c8c53884e599a5c174dcb", + "sha256:47e98aab9d8d82ff682e7b0b5dded33bf138a32b817fcf7fa3b27b2d7c412928", + "sha256:4a36f9becdd4c5c52a20c3e9484128b070b1dcfc8944c006f3a528295a359a9c", + "sha256:4af7b7e1be0a69bee8210735fe6dcfc38879adfac6d62e789d53ba432d1ffa41", + "sha256:4d97a951a81039050e45f04e96689b58b8243fa5e62aa14fe67cb6075300885e", + "sha256:4db9aecb141cb7a5447171b57aa1ed3a8fee06af40b992ffc31206c0b0121550", + "sha256:53e549287ef628fecba270045c9701b0c564563a9b0577d24a4ec75b8ab8040f", + "sha256:56b149b22de33b23b0c6077ab9518c6dcb538ad462e1830e68d06591ccf6e38b", + "sha256:570fec8fbd22b032733625f03f10b7ff023bc399213db15e72a7acaef28c2f4e", + "sha256:5b8ee53be440a0cffc991a27be3057e0530122548dbe7c0892df08822fce5ede", + "sha256:5ba4f78df2bcc19f764a4b26a8a4f5049c110090ad5825993aacb052bf8003ad", + "sha256:5c55256dee8f4b27bfbf636c8363383c7c8db7890c7cba5217d7bd5f5f21dab6", + "sha256:5c88e5815a49d289e599f3513aa7fde0bc2092ff188f99c940f007f90f53d104", + "sha256:5fede79c6f73ff2c3ef822864cb1ada23196e62756df53bc6231d351a49516a2", + "sha256:65be18ec59496c13908f02a2472751d9ef840b4f3fb5726f129306bf6a2a7bba", + "sha256:66410eb6345d467151934b49bfa70fb32f5b35a6140baa40ad97d6436abea2e9", + "sha256:665b0a2c463cc9423dd647e0bfd9f4ccc9b50f768c55304d5e9f80b177c1de12", + "sha256:6b8536851f9f65e7f00c7a1d49ba7f2be0ffe2c11555367fc9f50d9f842410a1", + "sha256:6c95b17fe34ed802f17e205112e6e10db92275c34fee290aa9bdc55a9c724027", + "sha256:6e73e7fe93f17a7b191f52ec9da9dd8c06a8fe735a1ecbd13b97d1c723bff385", + "sha256:6efbccc3d7f75d5b03105172a8dc86d82ba4da86817952529dd93185f4a88be2", + "sha256:709f1efed56c4a145793c046cd4939f9959bcd818979a787b77d8e09c57a0840", + "sha256:79af890482fc94648e8cde4c68620378f7fef60932710fa17a66abc039244da2", + "sha256:7bcbe0fcf850eae67b6b01749815a4f7161c560a844c769ad7b48fcd99f791c4", + "sha256:7c0494a31a1ac5461a226e7947a9c9b78c44e1dc7185164fa7e9651557a5d9bc", + "sha256:7ce27823052e2013b597e0c738b13e7e36b8ccb9400df8959417b052ab0fd92c", + "sha256:7f72c74aa99359e27a2ee8d6613fefa28b5f76a983c083074dfc2aaa4ab46213", + "sha256:7fa5e51397466ea7e98de493fa2ff1b8193cfef8a7b0f9b4842f92d342df0dba", + "sha256:82632daed195dcc8ea664e8556dc9bdbd671960fb3776bd92806ce05792c2448", + "sha256:82f75e05912e84b7a0fe57075d9c59de3cb352b928330f2eb69b2e1f54c3e1f0", + "sha256:841f0852f48fefea3b12c9dfec00704dfa3aef5215d0e3ce564bb3d7cd8d57c6", + "sha256:874019bd513008b009f58657134e5d0c5e030b3559bd0553976837adf52fe966", + "sha256:88f50c94e21a0a7f14042c015b0eba1881af78562e7bf007e0033e624da59750", + "sha256:89a1bbb58e0e3f7a283653d854b1e95d65e5cfd4af224dac5f02629ec1a3e621", + "sha256:8a6987eaad834cb32dd57d9d582225f0054a5d1af706ccfbbdba735af4927e13", + "sha256:8ac73abdc7ab75610f95a8fd994c6457e87752b02a63987e188f937a1fc180f0", + "sha256:8ccf9aca873b767977c73df497a85dbedee4ee086ae9ae49dc461333b9b79f58", + "sha256:90333fd89b43c0d08ac85f3f1447593fc2c66de18c3d6378d7125ea118dc7a54", + "sha256:92ab3e11448f2ff7bf53c5a26eff0edc086898ec8b21fb154b85839ce1d88075", + "sha256:9335a099ad87287c37fe5d1a982ff392fa5efe5d14b40a730b1ec1d6a41382b4", + "sha256:96d30286dd02679e32a39aa8f0b7498fc847fcda46cfc09df5513e82ce252440", + "sha256:9baafc71b04f8f4bb0703b21d6fc9f0c30b346c636a532ff16ec8491a5ea4b1f", + "sha256:9d1216a7f6f77836617dba35687c5b78a4170afc3c3f18fc788f785ba26565c4", + "sha256:9d399bdcfb4a0f659b9b3788bbc89babe63d9a6a65aacdf4d4e7065ff2e6316c", + "sha256:9e4e16c73d717c5cf27626c524d0a2e261ad20e46932b2670f64ad5dde23e26f", + "sha256:9f4d8cf085a4c6a40fb97ea0f46938a8df43c85d31f9d45e2a8867ea9293790d", + "sha256:a33700d13d9b7d84fd10947b09ff69fb9a792e519c8cb9764a3ca70baa6c23a7", + "sha256:a3732e66413163e72508da9eff9ce9d2846fde51fae45d3605393d3e6cd303e9", + "sha256:a4582acf7ef76482f6f511ebaf1946dae7f2e85ec4728b81a678c01df63bd723", + "sha256:a61834fb15d81322d872eaafd333838ae7c9cea84067f232656f75965933d047", + "sha256:a7cff474ab7cd149765bb784cf6d78b32e18e20473fb7bda860bce98ab58e9da", + "sha256:a8fe66b8f300da93798025a785a5b90b42f3810dc2b72283ff84a41aaaebc293", + "sha256:a929d878fec099030c292803b31e5d5540a7b6a31e6a3cc76cb4685fc2a2f51b", + "sha256:ad5d8201d310b031e6cd839d9bac2d4e5a01533ce5d3d5b50b7de1ef3af1de61", + "sha256:af3aefa655adb5869491fa907e652290386800ae99cc50095cba71e2c6aefdca", + "sha256:c0ebc836c47a6477e182169c6a476fc691d12b518894bf7dd2572f0d59f1c7ed", + "sha256:c687ed078e145f5fd53a14854beff320e1d2ab76df03e2009c98f39a0f68f39a", + "sha256:cbb833ccacdb5519eff9b8b71ee618cc2801c878e77e288775d77c3a2ced858a", + "sha256:cf139c02f5f23ef6532040a30ff662c00a318c952334f211046b8e60b7f17688", + "sha256:d46b86567dd4e248c6c159fcbcdcce01e0a5c8a7cd2334a0fff759d0fa075b16", + "sha256:d693396e5aea78db03decd60aec9ece16c9b40ba00a587f089615ff4e718a81d", + "sha256:d897129df1a22b12aeed2c2c98df0785a2e8e6e0bde87b389491d0025c187077", + "sha256:daba5e594f06114e37db186efd2dd916609071e59daca901a0a2e71f02b142ce", + "sha256:dd625535328fd9882374356269227670189adfcc6a2d90284f323c05862eecbd", + "sha256:e006d3a974c4ee19512e5f058abedb6eef36a5e553c14812bdeba1758d812e6d", + "sha256:e1ae548a9d901adca07899a4147a7c826bbcc06239d3ce9a59f57886a28a4c88", + "sha256:e2935f8c39e3b03e83519292d78f075189978f3f4adc15a78144c7c8e2a1cba5", + "sha256:e42d75862735da90e7fc5a7b23db0c976f737113a54b3c9777a9b665e9cbff75", + "sha256:e7d42c531243450ef0d4d9c172e7ed6ef052640f195629065041b5add4e058d1", + "sha256:e81b83143bee16329c23db3c1b2d82b29892fcbcb849186d2f6e98a5abe9a57f", + "sha256:e8ffa78582120024f476a611d7befc123cee59e47e8309d470cf667d806e613b", + "sha256:ebb0ec7f17803063d5aeb982f3b1bd2b2f4e4fae6751226cbd6ba1fcfe9e63ff", + "sha256:f08c7513ecef5aad65687bfdf6bc601ae9fccd04a42904501f8f7141abad9eb9", + "sha256:f0a658a6d3fafee5c6f63c58f3e785c8c43c93fbc02bf9f2b6663f8185e0971f", + "sha256:f0e466ed7511fe9d459a819edbc6c2585c0b6eabde9fa8a8947552468a7a6ef0", + "sha256:f141474e85b7e54998ec5180530a7cda99ab29e282fa50e0756d89981a9b43c5", + "sha256:f4239bbec5a3577ddb49e4b50aeb32d8e5792098262ae2f63723f916a29b1a25", + "sha256:f540c013589084679a6c7fac07096b10159737918174f5dfc5e11bf5bca4dfe6", + "sha256:f9f3e9c8a9ecffa57bef8fb4fa19e5fa4d2d8307cf6bac5b1fca5e5860f4ba00", + "sha256:fa139875ff98ab97da323cfadfaff08900d1ad42f1b5087b0b812a55c5a06373", + "sha256:fcd3b77e2f17bbe4ca56ec7bcb07992647d19d0b9c05d84886dcd6f9eb810afd", + "sha256:fd8c81f346b58f45818d09ea11db69a8d5fd34a224b79871f6d44f12cd7977b1", + "sha256:fe7b7bb170daccbba19ad33012d2b15f1e7942296fd4d45fc1b79013da8cc0f2", + "sha256:ff330d3c30db4eb6b01d79e29d2d0b407a7ecad39cfd9ec993ece57396a2ec0d", + "sha256:ff405d91509d88e8d44129cd87b18d70acd1f0c1aeabd7bc3c46792b1fe2acba", + "sha256:ffcd54362564dc1a30fb74d8b8a6e5a6b11ebd5e27266adc3b7427a21a6c9104" + ], + "markers": "python_version >= '3.10'", + "version": "==1.24.5" + }, + "zipp": { + "hashes": [ + "sha256:25ad4e16390cd314347dd8f1de67a2ac538ae658ed4ab9db16029c07c188e97f", + "sha256:4cb57381f544315db7688e976e922a2b18cdb513d21cc194eb42232ba2a3e602" + ], + "markers": "python_version >= '3.10'", + "version": "==4.1.0" + }, + "zstd": { + "hashes": [ + "sha256:047803d87d910f4905f48d99aeff1e0539ec2e4f4bf17d077701b5d0b2392a95", + "sha256:05604a693fa53b60ca083992324b08dafd15a4ac37ac4cffe4b43b9eb93d4440", + "sha256:07d2061df22a3efc06453089e6e8b96e58f5bb7a0c4074dcfd0b0ce243ddde72", + "sha256:0a470f8938f69f632b8f88b96578a5e8825c18ddbbea7de63493f74874f963ef", + "sha256:0d8c1dc947e5ccea3bd81043080213685faf1d43886c27c51851fabf325f05c0", + "sha256:0f79492bf86aef6e594b11e29c5589ddd13253db3ada0c7a14fb176b132fb65e", + "sha256:0f97f872cb78a4fd60b6c1024a65a4c52a971e9d991f33c7acd833ee73050f85", + "sha256:114115af8c68772a3205414597f626b604c7879f6662a2a79c88312e0f50361f", + "sha256:1b301b2f9dbb0e848093127fb10cbe6334a697dc3aea6740f0bb726450ee9a34", + "sha256:1d71f9f92b3abe18b06b5f0aefa5b9c42112beef3bff27e36028d147cb4426a6", + "sha256:1ff4c667f29101566a7b71f06bbd677a63192818396003354131f586383db042", + "sha256:24371a7b0475eef7d933c72067d363c5dc17282d2aa5d4f5837774378718509e", + "sha256:27e2ed58b64001c9ef0a8e028625477f1a6ed4ca949412ff6548544945cc59c2", + "sha256:27e55aa2043ba7d8a08aba0978c652d4d5857338a8188aa84522569f3586c7bb", + "sha256:2a653cdd2c52d60c28e519d44bde8d759f2c1837f0ff8e8e1b0045ca62fcf70e", + "sha256:2bc21650f7b9c058a3c4cb503e906fe9cce293941ec1b48bc5d005c3b4422b42", + "sha256:2bf6447373782a2a9df3015121715f6d0b80a49a884c2d7d4518c9571e9fca16", + "sha256:2cec2472760d48a7a3445beaba509d3f7850e200fed65db15a1a66e315baec6a", + "sha256:300db1ede4d10f8b9b3b99ca52b22f0e2303dc4f1cf6994d1f8345ce22dd5a7e", + "sha256:30d339d8e5c4b14c2015b50371fcdb8a93b451ca6d3ef813269ccbb8b3b3ef7d", + "sha256:346d1e4774d89a77d67fc70d53964bfca57c0abecfd885a4e00f87fd7c71e074", + "sha256:3b14793d2a2cb3a7ddd1cf083321b662dd20bc11143abc719456e9bfd22a32aa", + "sha256:3e220d2d7005822bb72a52e76410ca4634f941d8062c08e8e3285733c63b1db7", + "sha256:426e5c6b7b3e2401b734bfd08050b071e17c15df5e3b31e63651d1fd9ba4c751", + "sha256:44a5142123d59a0dbbd9ba9720c23521be57edbc24202223a5e17405c3bdd4a6", + "sha256:489a0ff15caf7640851e63f85b680c4279c99094cd500a29c7ed3ab82505fce0", + "sha256:4d5a85344193ec967d05da8e2c10aed400e2d83e16041d2fdfb713cfc8caceeb", + "sha256:4f6861c8edceb25fda37cdaf422fc5f15dcc88ced37c6a5b3c9011eda51aa218", + "sha256:5189fb44c44ab9b6c45f734bd7093a67686193110dc90dcfaf0e3a31b2385f38", + "sha256:52f27a198e2a72632bae12ec63ebaa31b10e3d5f3dd3df2e01376979b168e2e6", + "sha256:53375b23f2f39359ade944169bbd88f8895eed91290ee608ccbc28810ac360ba", + "sha256:53948be45f286a1b25c07a6aa2aca5c902208eb3df9fe36cf891efa0394c8b71", + "sha256:53abf577aec7b30afa3c024143f4866676397c846b44f1b30d8097b5e4f5c7d7", + "sha256:5414c9ae27069ab3ec8420fe8d005cb1b227806cbc874a7b4c73a96b4697a633", + "sha256:5540ce1c99fa0b59dad2eff771deb33872754000da875be50ac8c2beab42b433", + "sha256:55e2edc4560a5cf8ee9908595e90a15b1f47536ea9aad4b2889f0e6165890a38", + "sha256:56c4b8cd0a88fd721213661c28b87b64fbd14b6019df39b21b0117a68162b0f2", + "sha256:594f256fa72852ade60e3acb909f983d5cf6839b9fc79728dd4b48b31112058f", + "sha256:5a73f0f20f71d4eef970a3fed7baac64d9a2a00b238acc4eca2bd7172bd7effb", + "sha256:5e530b75452fdcff4ea67268d9e7cb37a38e7abbac84fa845205f0b36da81aaf", + "sha256:5fb2ff5718fe89181223c23ce7308bd0b4a427239379e2566294da805d8df68a", + "sha256:624022851c51dd6d6b31dbfd793347c4bd6339095e8383e2f74faf4f990b04c6", + "sha256:632e3c1b7e1ebb0580f6d92b781a8f7901d367cf72725d5642e6d3a32e404e45", + "sha256:6584fd081a6e7d92dffa8e7373d1fced6b3cbf473154b82c17a99438c5e1de51", + "sha256:660945ba16c16957c94dafc40aff1db02a57af0489aa3a896866239d47bb44b0", + "sha256:6922ceac5f2d60bb57a7875168c8aa442477b83e8951f2206cf1e9be788b0a6e", + "sha256:6d8684c69009be49e1b18ec251a5eb0d7e24f93624990a8a124a1da66a92fc8a", + "sha256:6e684e27064b6550aa2e7dc85d171ea1b62cb5930a2c99b3df9b30bf620b5c06", + "sha256:6f5539a10b838ee576084870eed65b63c13845e30a5b552cfe40f7e6b621e61a", + "sha256:6f8189bc58415758bbbd419695012194f5e5e22c34553712d9a3eb009c09808d", + "sha256:70231ba799d681b6fc17456c3e39895c493b5dff400aa7842166322a952b7f2a", + "sha256:70d0c4324549073e05aa72e9eb6a593f89cba59da804b946d325d68467b93ad5", + "sha256:70f29e0504fc511d4b9f921e69637fca79c050e618ba23732a3f75c044814d89", + "sha256:7206934a2bd390080e972a1fed5a897e184dfd71dbb54e978dc11c6b295e1806", + "sha256:73cec37649fda383348dc8b3b5fba535f1dbb1bbaeb60fd36f4c145820208619", + "sha256:74c3f006c9a3a191ed454183f0fb78172444f5cb431be04d85044a27f1b58c7b", + "sha256:787bcf55cefc08d27aca34c6dcaae1a24940963d1a73d4cec894ee458c541ac4", + "sha256:7b13e7eef9aa192804d38bf413924d347c6f6c6ac07f5a0c1ae4a6d7b3af70f0", + "sha256:7c1cc65fc2789dd97a98202df840537de186ed04fd1804a17fcb15d1232442c4", + "sha256:7e0027b20f296d1c9a8e85b8436834cf46560240a29d623aa8eaa8911832eb58", + "sha256:7e998f86a9d1e576c0158bf0b0a6a5c4685679d74ba0053a2e87f684f9bdc8eb", + "sha256:8291d393321fac30604c6bbf40067103fee315aa476647a5eaecf877ee53496f", + "sha256:83a36bb1fd574422a77b36ccf3315ab687aef9a802b0c3312ca7006b74eeb109", + "sha256:8526a32fa9f67b07fd09e62474e345f8ca1daf3e37a41137643d45bd1bc90773", + "sha256:86e64c71b4d00bf28be50e4941586e7874bdfa74858274d9f7571dd5dda92086", + "sha256:883e7b77a3124011b8badd0c7c9402af3884700a3431d07877972e157d85afb8", + "sha256:8c3f4bb8508bc54c00532931da4a5261f08493363da14a5526c986765973e35d", + "sha256:8cc35cc25e2d4a0f68020f05cba96912a2881ebaca890d990abe37aa3aa27045", + "sha256:8dc542a9818712a9fb37563fa88cdbbbb2b5f8733111d412b718fa602b83ba45", + "sha256:8e97933addfd71ea9608306f18dc18e7d2a5e64212ba2bb9a4ccb6d714f9f280", + "sha256:910bd9eac2488439f597504756b03c74aa63ed71b21e5d0aa2c7e249b3f1c13f", + "sha256:92590cf54318849d492445c885f1a42b9dbb47cdc070659c7cb61df6e8531047", + "sha256:92f072819fc0c7e8445f51a232c9ad76642027c069d2f36470cdb5e663839cdb", + "sha256:9714d5642867fceb22e4ab74aebf81a2e62dc9206184d603cb39277b752d5885", + "sha256:97b908ccb385047b0c020ce3dc55e6f51078c9790722fdb3620c076be4a69ecf", + "sha256:9838ec7eb9f1beb2f611b9bcac7a169cb3de708ccf779aead29787e4482fe232", + "sha256:9a24d492c63555b55e6bc73a9e82a38bf7c3e8f7cde600f079210ed19cb061f2", + "sha256:9dc05618eb0abceb296b77e5f608669c12abc69cbf447d08151bcb14d290ab07", + "sha256:a03608499794148f39c932c508d4eb3622e79ca2411b1d0438a2ee8cafdc0111", + "sha256:a130243e875de5aeda6099d12b11bc2fcf548dce618cf6b17f731336ba5338e4", + "sha256:a200c479ee1bb661bc45518e016a1fdc215a1d8f7e4bf6c7de0af254976cfdf6", + "sha256:a371274668182ae06be2e321089b207fa0a75a58ae2fd4dfb7eafded9e041b2f", + "sha256:a59a136a9eaa1849d715c004e30344177e85ad6e7bc4a5d0b6ad2495c5402675", + "sha256:a6105b8fa21dbc59e05b6113e8e5d5aaf56c5d2886aa5778d61030af3256bbb7", + "sha256:a62c2f6f7b8fc69767392084828740bd6faf35ff54d4ccb2e90e199327c64140", + "sha256:ac7bdfedda51b1fcdcf0ab69267d01256fc97ddf666ce894fde0fae9f3630eac", + "sha256:ae1100776cb400100e2d2f427b50dc983c005c38cd59502eb56d2cfea3402ad5", + "sha256:b011bf4cfad78cdf9116d6731234ff181deb9560645ffdcc8d54861ae5d1edfc", + "sha256:b13285c99cc710f60dd270785ec75233018870a1831f5655d862745470a0ca29", + "sha256:b5af6aa041b5515934afef2ef4af08566850875c3c890109088eedbe190eeefb", + "sha256:b835405cc4080b378e45029f2fe500e408d1eaedfba7dd7402aba27af16955f9", + "sha256:b9518caabf59405eddd667bbb161d9ae7f13dbf96967fd998d095589c8d41c86", + "sha256:baf4e8b46d8934d4e85373f303eb048c63897fc4191d8ab301a1bbdf30b7a3cc", + "sha256:bb1cb423fc40468cc9b7ab51a5b33c618eefd2c910a5bffed6ed76fe1cbb20b0", + "sha256:c21d44981b068551f13097be3809fadb7f81617d0c21b2c28a7d04653dde958f", + "sha256:c59218bd36a7431a40591504f299de836ea0d63bc68ea76d58c4cf5262f0fa3c", + "sha256:c6abf4ab9a9d1feb14bc3cbcc32d723d340ce43b79b1812805916f3ac069b073", + "sha256:cdb5ec80da299f63f8aeccec0bff3247e96252d4c8442876363ff1b438d8049b", + "sha256:ceae57e369e1b821b8f2b4c59bc08acd27d8e4bf9687bfa5211bc4cdb080fe7b", + "sha256:d0b0ca097efb5f67157c61a744c926848dcccf6e913df2f814e719aa78197a4b", + "sha256:d104f1cb2a7c142007c29a2a62dfe633155c648317a465674e583c295e5f792d", + "sha256:d17ac6d2584168247796174e599d4adbee00153246287e68881efaf8d48a6970", + "sha256:d2ebe3e60dbace52525fa7aa604479e231dc3e4fcc76d0b4c54d8abce5e58734", + "sha256:d3f14c5c405ea353b68fe105236780494eb67c756ecd346fd295498f5eab6d24", + "sha256:d6b17e5581dd1a13437079bd62838d2635db8eb8aca9c0e9251faa5d4d40a6d7", + "sha256:d6ee5dfada4c8fa32f43cc092fcf7d8482da6ad242c22fdf780f7eebd0febcc7", + "sha256:d7131bb4e55d075cb7847555a1e17fca5b816a550c9b9ac260c01799b6f8e8d9", + "sha256:d9d1bcb6441841c599883139c1b0e47bddb262cce04b37dc2c817da5802c1158", + "sha256:df8083c40fdbfe970324f743f0b5ecc244c37736e5f3ad2670de61dde5e0b024", + "sha256:e17104d0e88367a7571dde4286e233126c8551691ceff11f9ae2e3a3ac1bb483", + "sha256:e2476ba12597e58c5fc7a3ae547ee1bef9dd6b9d5ea80cf8d4034930c5a336e0", + "sha256:e4cf97bb97ed6dbb62d139d68fd42fa1af51fd26fd178c501f7b62040e897c50", + "sha256:ebf6c1d7f0ceb0af5a383d2a1edc8ab9ace655e62a41c8a4ed5a031ee2ef8006", + "sha256:edf816c218e5978033b7bb47dcb453dfb71038cb8a9bf4877f3f823e74d58174", + "sha256:eea9bddf06f3f5e1e450fd647665c86df048a45e8b956d53522387c1dff41b7a", + "sha256:ef201b6f7d3a6751d85cc52f9e6198d4d870e83d490172016b64a6dd654a9583", + "sha256:f19a3e658d92b6b52020c4c6d4c159480bcd3b47658773ea0e8d343cee849f33", + "sha256:f2dda0c76f87723fb7f75d7ad3bbd90f7fb47b75051978d22535099325111b41", + "sha256:f51a965871b25911e06d421212f9be7f7bcd3cedc43ea441a8a73fad9952baa0", + "sha256:f576ec00e99db124309dac1e1f34bc320eb69624189f5fdaf9ebe1dc81581a84", + "sha256:f5d159e57a13147aa8293c0f14803a75e9039fd8afdf6cf1c8c2289fb4d2333a", + "sha256:f799c1e9900ad77e7a3d994b9b5146d7cfd1cbd1b61c3db53a697bf21ffcc57b", + "sha256:f97d8593da0e23a47f148a1cb33300dccd513fb0df9f7911c274e228a8c1a300", + "sha256:f9cf09c2aa6f67750fe9f33fdd122f021b1a23bf7326064a8e21f7af7e77faee", + "sha256:faf3fd38ba26167c5a085c04b8c931a216f1baf072709db7a38e61dea52e316e", + "sha256:fd6262788a98807d6b2befd065d127db177c1cd76bb8e536e0dded419eb7c7fb" + ], + "version": "==1.5.7.2" + } + }, + "develop": {} +} diff --git a/docs/full_discovery_plan.md b/docs/full_discovery_plan.md new file mode 100644 index 0000000..b481d50 --- /dev/null +++ b/docs/full_discovery_plan.md @@ -0,0 +1,104 @@ +# Scrivas — Full AWS Discovery Plan + +**Owner:** Dasnuve · **Prepared:** 2026-08-19 · **Status:** proposed +**Access:** `dasnuve-scrivas-louis-impersonation` → `iam/louis` (mgmt acct `716468089330`, groups `Admin`/`devops`), cross-account `OrganizationAccountAccessRole` into members. + +## Context + +We have completed a preliminary Organizations assessment (see `findings/discovery_report.md`). It confirmed a two-account org (`o-qfj0pvhhv7`: *Scrivas Admin* + *Lazka*), workloads running in the management account (EKS/EC2/RDS), an active compliance stack (Intruder, Secureframe, Macie, Config), and one headline gap — **no delegated administrators**. This document defines the **full discovery** needed to size and shape the proposal: the complete cloud footprint, its cost, its security posture, and its operational maturity across every account and region. + +**Goal:** a defensible, evidence-backed picture of Scrivas's AWS estate that lets us (a) scope remediation/landing-zone work and (b) quantify value (cost, risk, effort). + +**Principles:** read-only only; scripted + reproducible (everything lands in `scripts/` + `findings/`); per-account and per-region coverage; no changes to client resources; secrets/PII never exfiltrated, only referenced. + +--- + +## Phase 0 — Access, scoping & guardrails *(½ day)* +- Confirm the role/permissions boundary of `iam/louis`; document what we can and cannot read (`iam get-account-authorization-details`, simulate key actions). +- Enumerate every account (`organizations list-accounts`) and confirm an assumable path into each (`OrganizationAccountAccessRole` / Control Tower exec role). Record any account we **cannot** reach — that gap is itself a finding. +- Enumerate enabled regions per account (`account list-regions` / `ec2 describe-regions`) to bound the scan surface. +- **Deliverable:** `findings/access_matrix.json` (account × reachable × role × regions). + +## Phase 1 — Organization & governance *(mostly done)* +- Org structure, OUs, SCP inventory **and policy contents** (`organizations list-policies`, `describe-policy`, `list-targets-for-policy`). +- Delegated admins, trusted access, org resource policy, IAM role trust — ✅ done (`scripts/org_assessment.py`). +- Account-level metadata: alternate contacts, root MFA/usage, account status (`account get-alternate-contact`). +- **Deliverable:** extend `org_assessment_report.json` with SCP bodies + OU tree. + +## Phase 2 — Identity & access management *(1 day)* — *per account* +- Users, groups, roles, policies (managed + inline); password policy; access-key age & last-used. +- MFA coverage (console users without MFA), root account usage, unused credentials. +- IAM Access Analyzer external-access findings; SSO / Identity Center config if present. +- **Deliverable:** `findings/iam_.json` + a consolidated IAM posture summary. + +## Phase 3 — Resource footprint inventory *(2 days)* — *per account × region* +Primary engine: **Resource Explorer** / **Config aggregator** / **`tag:GetResources`** for a fast cross-service index, then targeted service calls for depth: + +| Domain | What we enumerate | +|---|---| +| Compute | EC2 (instances, AMIs, EBS), Lambda, ECS, **EKS** (clusters, node groups, versions), Batch, Auto Scaling | +| Storage | S3 (buckets, public-access config, encryption, size via CloudWatch), EBS, EFS, FSx, Backup | +| Database | RDS/Aurora, DynamoDB, ElastiCache, Redshift, OpenSearch | +| Networking | VPCs, subnets, route tables, IGW/NAT, TGW, peering, VPN/DX, ELB/ALB/NLB, Route 53, CloudFront, WAF | +| Serverless/Integration | API Gateway, SQS, SNS, EventBridge, Step Functions | +| Containers/Registry | ECR repos & image scan status | +| Edge/DNS | Route 53 zones, ACM certs (expiry), CloudFront distributions | + +- **Deliverable:** `findings/inventory_.json` + a rolled-up resource census (counts by service/region) feeding the dashboard. + +## Phase 4 — Security posture *(1–2 days)* +- **Detective controls:** GuardDuty findings, Security Hub standards + failed controls, Inspector findings, Macie sensitive-data results, Access Analyzer. +- **Preventive/config:** AWS Config rule compliance, Config recorder coverage per account/region. +- **Exposure:** public S3, public EBS snapshots/AMIs, security groups open to `0.0.0.0/0`, public RDS/ELB, public IPs. +- **Logging & audit:** CloudTrail org-trail status & coverage, log-file validation, VPC Flow Logs coverage, CloudWatch log retention. +- **Data protection:** KMS key inventory & rotation, encryption-at-rest coverage, Secrets Manager/SSM Parameter usage. +- **Deliverable:** `findings/security_posture.json` + prioritized risk register (severity × exploitability × blast radius). + +## Phase 5 — Cost & optimization *(1 day)* +- Cost Explorer: 12-month trend, spend by account/service/region, month-over-month; anomalies. +- Commitment coverage: Savings Plans / Reserved Instances utilization & coverage. +- Waste signals: idle/unattached EBS, unassociated EIPs, idle NAT gateways, oversized instances, old snapshots, Graviton/spot opportunities, gp2→gp3. +- Budgets & Cost Anomaly Detection presence. +- **Deliverable:** `findings/cost_baseline.json` + a quantified savings estimate for the proposal. + +## Phase 6 — Operational & resilience maturity *(1 day)* +- Backup coverage (AWS Backup plans, RDS/EBS snapshot policies), cross-region/DR posture. +- IaC footprint: CloudFormation stacks, Terraform state hints (S3 backends), drift signals. +- Tagging hygiene & coverage (via tag editor / Config) — needed for cost allocation & governance. +- Service quotas nearing limits; Trusted Advisor checks (needs Business/Enterprise support). +- Patch/SSM managed-instance coverage; EKS/RDS end-of-life versions. +- **Deliverable:** `findings/ops_maturity.json`. + +## Phase 7 — Synthesis & deliverables *(1–2 days)* +- Consolidate all `findings/*.json` into a **discovery data model**. +- Update `findings/assessment_dashboard.html` into a full multi-section dashboard (footprint census, cost trend, risk register, maturity scorecard). +- Written **Discovery Report** + **Proposal input pack**: prioritized roadmap (landing zone / delegated-admin security account / cost optimization / OU + SCP guardrails), effort estimates, and quantified value. + +--- + +## Tooling approach +- **Primary:** scripted boto3 (extend the existing `scripts/` pattern — session per account via assume-role, paginated read-only calls, JSON to `findings/`). +- **Accelerators (read-only, optional):** Steampipe/`aws` mods, Prowler (security), or the AWS "Account Assessment for AWS Organizations" solution for cross-account resource-policy scanning. Note any that require deploying resources — prefer client sign-off first. +- Everything reproducible from the repo; no console-only steps in the critical path. + +## Timeline & effort +| Phase | Effort | +|---|---| +| 0 Access & scoping | 0.5 d | +| 1 Governance | done + 0.5 d | +| 2 IAM | 1 d | +| 3 Resource inventory | 2 d | +| 4 Security posture | 1.5 d | +| 5 Cost | 1 d | +| 6 Ops/resilience | 1 d | +| 7 Synthesis & deliverables | 1.5 d | +| **Total** | **~9 working days** | + +## Assumptions & risks +- `iam/louis` retains `Admin`-level read access and `OrganizationAccountAccessRole` remains assumable into members. +- Some data needs paid tiers (Trusted Advisor full checks = Business/Enterprise support; Compute Optimizer must be opted in). +- New accounts/regions added mid-engagement expand scope. +- Strictly read-only; any assessment tooling that provisions resources requires explicit client approval. + +## Out of scope (unless requested) +Application-level code review, penetration testing, non-AWS cloud, and any write/remediation actions. diff --git a/findings/assessment_dashboard.html b/findings/assessment_dashboard.html new file mode 100644 index 0000000..3b32bcd --- /dev/null +++ b/findings/assessment_dashboard.html @@ -0,0 +1,259 @@ +Scrivas — AWS Organizations Assessment + + +
+
+
+
Dasnuve · Cloud Discovery
+

Scrivas — AWS Organizations Assessment

+
Delegated administration, trust policies & trusted access · read-only enumeration
+
+
+ org o-qfj0pvhhv7
+ mgmt 716468089330
+ as iam/louis · 2026-08-19 +
+
+ +
+
+
2
Accounts in org
+
Scrivas Admin · Lazka — no OUs (flat)
+
+
+
6
Trusted access services
+
CloudTrail, GuardDuty, SecurityHub, Inspector…
+
+
+
0
Delegated administrators
+
Security ops run from the mgmt account
+
+
+
2
Third-party cross-account trusts
+
Intruder.io · Secureframe (both ExternalId-gated)
+
+
+ +
+
01

Trusted access services

+ org-enabled service principals
+
+ cloudtrail + securityhub + guardduty + malware-protection.guardduty + inspector2 + notifications +
+

Org-wide security tooling has trusted access enabled — Scrivas has begun + centralizing security. on track

+
+ +
+
02

Delegated administrators

+ list_delegated_administrators
+
+
0
+

No delegated administrator is set despite trusted access being enabled for GuardDuty, + Security Hub and Inspector. These services are therefore administered directly from the + management account. Best practice is to delegate them to a dedicated security/audit + account and keep the management account minimal. + headline gap

+
+
+ +
+
03

Trust policies

+ org resource policy + IAM role trust relationships
+

Organization resource policy: none set. Of 44 IAM roles in the + management account, all but three are AWS service / service-linked roles. Notable external & federated trusts:

+
+
+ IntruderReadOnlyRole + 123311413059:root + ExternalId + Intruder.io — vulnerability scanning +
+
+ SecureframeRole-f983f1e89008 + 728997465891:root + ExternalId + Secureframe — SOC 2 / compliance +
+
+ AmazonEKS_EBS_CSI_DriverRole + oidc.eks.us-east-2 + federated + EKS OIDC (IRSA) +
+
+

Lazka member account (6 roles): only default service-linked roles + + OrganizationAccountAccessRoleno GuardDuty/SecurityHub/Inspector + roles, so org security services are not deployed into the member account.

+
+ +
+
04

Governance signals for the proposal

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SeverityObservationWhy it matters
HighNo delegated administrators despite trusted accessSecurity ops run from the mgmt account; violates multi-account best practice
HighWorkloads in the management account — EKS, EC2, RDS, VPC flow logsBlast-radius & separation-of-duties risk; mgmt account should be minimal
MediumMember account not monitored — Lazka lacks security SLRsCoverage gap; trusted access enabled but not delivered to members
MediumFlat org, no OUs — SCPs enabled but unused for targetingNo policy boundaries; governance won't scale as accounts are added
SignalCompliance stack present — Intruder, Secureframe, Macie, Config, Access AnalyzerClient is actively pursuing compliance — receptive to a landing-zone engagement
+
+
+ +
+ Read-only · boto3 via dasnuve-scrivas-louis-impersonation + Reproduce: scripts/org_assessment.py · scripts/assess_member_account.py + Raw: findings/*.json +
+
+ + diff --git a/findings/discovery_dashboard.html b/findings/discovery_dashboard.html new file mode 100644 index 0000000..e3828b5 --- /dev/null +++ b/findings/discovery_dashboard.html @@ -0,0 +1,303 @@ +Scrivas — AWS Discovery Findings + + +
+
+
+
Dasnuve · Cloud Discovery · Fast Track
+

Scrivas — AWS Discovery Findings

+
Resource footprint · security posture · cost — phases 2–5, read-only
+
+
org o-qfj0pvhhv7
2 accounts · us-east-2 primary
2026-08-19
+
+ +
+
$858/mo
Current run-rate (Jul)
up ~4× from $223 in January
+
4
GuardDuty high/critical findings
severity 8–9, both regions, open
+
13
Security groups open to 0.0.0.0/0
management account, us-east-2
+
5
Access keys > 90 days old
incl. admin keys at 322 & 319 days
+
+ + +
+
05

Cost baseline

Cost Explorer · unblended · payer account
+
+
+
+
$223
Jan
+
$131
Feb
+
$522
Mar
+
$732
Apr
+
$746
May
+
$821
Jun
+
$858
Jul
+
+
Monthly spend, 2026+284% Jan→Jul · 7-mo total ≈ $4,033
+
+
+
Top services · 6-month spend
+
+
EC2 – Compute$2,722
+
EC2 – Other$375
+
AWS WAF$364
+
Security Hub$153
+
VPC$117
+
Config$84
+
GuardDuty$56
+
EKS$47
+
+

EC2 compute is 67% of spend — the primary optimization lever (rightsizing, Savings Plans, Graviton/spot). Security tooling (WAF, Security Hub, Config, GuardDuty) adds ~$110/mo.

+
+
+
+ + +
+
03

Resource footprint

active regions only · us-east-2 primary
+
+
7EC2 instances
+
9EBS volumes (2 unattached)
+
7Elastic IPs
+
9S3 buckets
+
2Regions in use
+
15Idle regions
+
+
+
+

Scrivas Admin management + workloads

+
716468089330 · us-east-2
+
    +
  • 7 EC2 · 9 EBS (2 unattached) · 7 EIPs · 9 S3 buckets
  • +
  • EKS IAM roles present (staging/gpu/infra/apps) — no live clusters returned; likely torn down, roles orphaned
  • +
  • RDS monitoring role present; VPC flow logs enabled
  • +
  • Anti-pattern: production workloads run in the org management account
  • +
+
+
+

Lazka bare & unmonitored

+
547868853286 · us-east-1
+
    +
  • 0 EC2 · 0 S3 · 0 IAM users — effectively empty
  • +
  • Only default service-linked roles + OrganizationAccountAccessRole
  • +
  • Security Hub not enabled; no GuardDuty detector
  • +
  • Covered by the org CloudTrail, but otherwise dark
  • +
+
+
+
+ + +
+
04

Security posture & IAM

prioritized risk register
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SeverityFindingEvidenceWhy it matters
HighOpen GuardDuty high/critical findingssev 8–9 in us-east-1 & us-east-2Active threat signals unremediated; no delegated security owner to triage
High13 security groups open to the internet0.0.0.0/0 ingress, us-east-2Direct attack surface on the workload account — needs port-level review
HighStale admin access keysadmin keys 322 & 319 days; +3 others >90dLong-lived static credentials for privileged users — top breach vector
MediumConsole users without MFA2 of 10 IAM usersAccount-takeover risk; fails CIS AWS baseline
MediumMember account unmonitoredLazka: no GuardDuty / Security HubDetection blind spot; org security services not delivered to members
GoodOrg CloudTrail configured wellmulti-region + org trail + log-file validationSolid audit foundation to build on
GoodNo public S3 buckets or public RDS0 of 9 buckets public; 0 public DBsData-exposure basics are in order
+
+
+ + +
+
CIS

Compliance benchmark

Prowler 5.39 · 632 checks · 1,230 findings · mgmt account
+
+
+
+
70%Checks passing (861)
+
2Critical failures
+
111High failures
+
189Medium failures
+
+
Pass rate by framework
+
+
SOC 281%
+
ISO 27001:202277%
+
CIS 3.074%
+
NIST CSF 2.071%
+
PCI DSS 4.057%
+
+

SOC 2 at 81% aligns with their Secureframe program — a focused push closes the gap. PCI is lowest (not in scope unless they process cards).

+
+
+
Critical & notable high failures
+
+
CRITRoot account has no hardware MFA
+
CRITAWS-managed policy grants *:* admin
+
HIGHNo delegated admin: Config / GuardDuty / Security Hub
+
HIGHIMDSv2 not enforced at account level
+
HIGHIAM users rely on long-lived credentials
+
HIGHSecrets Manager rotation disabled (19 secrets)
+
HIGHKMS key auto-rotation off · SCP region restriction absent
+
+

Full evidence: findings/prowler/*.html · *.ocsf.json · compliance/

+
+
+
+ + +
+

Proposal levers

where we create value
+
+ + + + + + + + + +
WorkstreamDriver from discoveryOutcome
Landing zone & account separationWorkloads in mgmt acct; flat org; empty LazkaMove workloads to a dedicated account; OUs + SCP guardrails
Delegated security accountNo delegated admin; unaddressed GD findings; Lazka darkCentral GuardDuty/Security Hub admin; org-wide monitoring
Cost optimizationEC2 = 67% of spend; 4× growth; unattached EBSRightsizing + Savings Plans + cleanup → recurring savings
Identity hardeningStale admin keys; 2 users w/o MFARotate/retire keys, enforce MFA, move to short-lived roles/SSO
Exposure reduction13 internet-open SGsLeast-privilege ingress; WAF already in place to leverage
+
+
+ +
+ Read-only · boto3 via dasnuve-scrivas-louis-impersonation + Reproduce: scripts/fast_discovery.py + Raw: findings/fast_discovery.json + Benchmark: prowler aws 632 checks · findings/prowler/ + Phases 2–5 + CIS benchmark · phase 6 on ice +
+
diff --git a/findings/discovery_report.md b/findings/discovery_report.md new file mode 100644 index 0000000..bbc4373 --- /dev/null +++ b/findings/discovery_report.md @@ -0,0 +1,72 @@ +# Scrivas — AWS Organizations Discovery & Account Assessment + +**Prepared by:** Dasnuve · **Date:** 2026-08-19 +**Access used:** `dasnuve-scrivas-louis-impersonation` profile → `arn:aws:iam::716468089330:user/louis` (member of `Admin`, `devops`) +**Method:** Read-only boto3 enumeration. Scripts in `scripts/`, raw output in `findings/*.json`. + +--- + +## 1. Organization at a glance + +| Property | Value | +|---|---| +| Organization ID | `o-qfj0pvhhv7` | +| Feature set | `ALL` | +| Management account | `716468089330` — *Scrivas Admin* (`ScrivasAdmin@scrivas.com`) | +| Member accounts | `547868853286` — *Lazka* (`lgarrido@gmail.com`) | +| Organizational Units | **None** (flat — all accounts under Root) | +| Policy types enabled | `SERVICE_CONTROL_POLICY` | + +Two-account, no-OU structure. All security tooling and all workloads currently live in the **management account**. + +--- + +## 2. Assessment findings — the three targets + +### 2a. Trusted access services (6 enabled) +`cloudtrail` · `securityhub` · `guardduty` (+ `malware-protection.guardduty`) · `inspector2` · `notifications` + +Org-wide security services have trusted access enabled — the client has started centralizing security. + +### 2b. Delegated administrators — **NONE** ⚠️ *(headline gap)* +`list_delegated_administrators` returns empty. GuardDuty, Security Hub, and Inspector have org trusted-access enabled but **no member account is delegated to administer them**, so they are operated directly from the management account. AWS best practice is to delegate these to a dedicated security/audit account and keep the management account free of workloads and day-to-day operations. + +### 2c. Trust policies +- **Organization resource policy:** none set. +- **IAM role trust relationships (management account, 44 roles):** almost all AWS service / service-linked roles. Two third-party **cross-account** trusts, both correctly gated with an `ExternalId`: + - `IntruderReadOnlyRole` → trusts `123311413059` (**Intruder.io** — external vuln scanning) + - `SecureframeRole-f983f1e89008` → trusts `728997465891` (**Secureframe** — SOC 2 / compliance automation) + - One OIDC-federated EKS role (`AmazonEKS_EBS_CSI_DriverRole`, cluster in `us-east-2`). +- **Lazka member account (6 roles):** only default service-linked roles + `OrganizationAccountAccessRole` (trusts the management account). **No GuardDuty/SecurityHub/Inspector roles present** → org-enabled security services are *not* deployed into the member account. + +--- + +## 3. Governance signals for the proposal + +| # | Observation | Why it matters | +|---|---|---| +| 1 | **No delegated administrators** despite trusted access enabled | Security ops run from the mgmt account; violates AWS multi-account best practice | +| 2 | **Workloads in the management account** — EKS (`scrivas-staging`, gpu/infra/apps node groups), EC2, RDS, VPC flow logs | Blast-radius & separation-of-duties risk; mgmt account should be minimal | +| 3 | **Flat org, no OUs** | No policy boundaries (SCP targeting), hard to scale governance | +| 4 | **Member account not monitored** — Lazka lacks security service-linked roles | Coverage gap; trusted access enabled but not delivered to members | +| 5 | Third-party access via Intruder + Secureframe; Macie/Config/Access Analyzer present | Client is pursuing compliance — receptive to a landing-zone / governance engagement | + +--- + +## 4. Recommended next discovery steps +1. Enumerate the full resource footprint per account (compute/storage/network/cost) to size the proposal. +2. Pull SCP contents attached to Root to understand existing guardrails. +3. Pull CloudTrail configuration & organization trail status. +4. Cost & Usage (Cost Explorer) for spend baseline and optimization signals. + +--- + +## 5. How to reproduce +```bash +# Org-level assessment (management account) +python3 scripts/org_assessment.py --profile dasnuve-scrivas-louis-impersonation + +# Member-account extension (assumes OrganizationAccountAccessRole) +python3 scripts/assess_member_account.py --account 547868853286 --name Lazka +``` +Outputs: `findings/org_assessment_report.json`, `findings/member_lazka_547868853286.json`. diff --git a/findings/fast_discovery.json b/findings/fast_discovery.json new file mode 100644 index 0000000..c67ec97 --- /dev/null +++ b/findings/fast_discovery.json @@ -0,0 +1,461 @@ +{ + "generated": "2026-08-19T16:24:41.068499+00:00", + "payer_account": "716468089330", + "accounts": [ + { + "account_id": "547868853286", + "name": "Lazka", + "active_regions": [ + "us-east-1" + ], + "enabled_region_count": 17, + "iam": { + "user_count": 0, + "users_without_mfa": 0, + "stale_keys_over_90d": [], + "password_policy": "none set", + "account_summary": { + "GroupPolicySizeQuota": 5120, + "InstanceProfilesQuota": 1000, + "Policies": 0, + "GroupsPerUserQuota": 10, + "InstanceProfiles": 0, + "AttachedPoliciesPerUserQuota": 10, + "Users": 0, + "PoliciesQuota": 1500, + "Providers": 0, + "AccountMFAEnabled": 0, + "AccessKeysPerUserQuota": 2, + "AssumeRolePolicySizeQuota": 2048, + "PolicyVersionsInUseQuota": 10000, + "GlobalEndpointTokenVersion": 1, + "VersionsPerPolicyQuota": 5, + "AttachedPoliciesPerGroupQuota": 10, + "PolicySizeQuota": 6144, + "Groups": 0, + "AccountSigningCertificatesPresent": 0, + "UsersQuota": 5000, + "ServerCertificatesQuota": 20, + "MFADevices": 0, + "UserPolicySizeQuota": 2048, + "PolicyVersionsInUse": 6, + "ServerCertificates": 0, + "Roles": 6, + "RolesQuota": 1000, + "SigningCertificatesPerUserQuota": 2, + "MFADevicesInUse": 0, + "RolePolicySizeQuota": 10240, + "AttachedPoliciesPerRoleQuota": 20, + "AccountAccessKeysPresent": 0, + "AccountPasswordPresent": 0, + "GroupsQuota": 300 + }, + "users": [] + }, + "census": { + "s3_buckets": 0, + "by_region": { + "us-east-1": { + "(empty)": true + } + } + }, + "exposure": { + "public_buckets": [], + "open_security_groups": [], + "public_rds": [] + }, + "security_services": { + "cloudtrail": [ + { + "name": "us-east-2", + "multi_region": true, + "org_trail": true, + "log_validation": true + } + ], + "guardduty_findings_by_severity": {}, + "securityhub": { + "us-east-1": "not enabled" + } + } + }, + { + "account_id": "716468089330", + "name": "Scrivas Admin", + "active_regions": [ + "us-east-1", + "us-east-2" + ], + "enabled_region_count": 17, + "iam": { + "user_count": 10, + "users_without_mfa": 2, + "stale_keys_over_90d": [ + "admin:***H7XN (322d)", + "admin:***5KWA (319d)", + "igor@devteamspace.com:***6YNU (316d)", + "scrivas-storage-user:***AXMK (161d)", + "Vasilii:***DFAO (147d)" + ], + "password_policy": "none set", + "account_summary": { + "GroupPolicySizeQuota": 5120, + "InstanceProfilesQuota": 1000, + "Policies": 7, + "GroupsPerUserQuota": 10, + "InstanceProfiles": 3, + "AttachedPoliciesPerUserQuota": 10, + "Users": 10, + "PoliciesQuota": 1500, + "Providers": 1, + "AccountMFAEnabled": 1, + "AccessKeysPerUserQuota": 2, + "AssumeRolePolicySizeQuota": 2048, + "PolicyVersionsInUseQuota": 10000, + "GlobalEndpointTokenVersion": 1, + "VersionsPerPolicyQuota": 5, + "AttachedPoliciesPerGroupQuota": 10, + "PolicySizeQuota": 6144, + "Groups": 6, + "AccountSigningCertificatesPresent": 0, + "UsersQuota": 5000, + "ServerCertificatesQuota": 20, + "MFADevices": 13, + "UserPolicySizeQuota": 2048, + "PolicyVersionsInUse": 61, + "ServerCertificates": 0, + "Roles": 44, + "RolesQuota": 1000, + "SigningCertificatesPerUserQuota": 2, + "MFADevicesInUse": 10, + "RolePolicySizeQuota": 10240, + "AttachedPoliciesPerRoleQuota": 20, + "AccountAccessKeysPresent": 0, + "AccountPasswordPresent": 1, + "GroupsQuota": 300 + }, + "users": [ + { + "user": "admin", + "mfa": true, + "keys": [ + { + "id": "H7XN", + "status": "Active", + "age_days": 322, + "last_used": "2025-10-29T14:59:00+00:00" + }, + { + "id": "5KWA", + "status": "Active", + "age_days": 319, + "last_used": "2025-10-05T09:36:00+00:00" + } + ] + }, + { + "user": "aksinya", + "mfa": true, + "keys": [] + }, + { + "user": "Azamat", + "mfa": true, + "keys": [] + }, + { + "user": "Dilbag", + "mfa": true, + "keys": [] + }, + { + "user": "gitlab-ci-ecr-push", + "mfa": false, + "keys": [ + { + "id": "5Y4W", + "status": "Active", + "age_days": 62, + "last_used": "2026-08-18T17:18:00+00:00" + } + ] + }, + { + "user": "igor@devteamspace.com", + "mfa": true, + "keys": [ + { + "id": "6YNU", + "status": "Active", + "age_days": 316, + "last_used": "2025-10-30T19:26:00+00:00" + } + ] + }, + { + "user": "louis", + "mfa": true, + "keys": [ + { + "id": "RESB", + "status": "Active", + "age_days": 1, + "last_used": "2026-08-19T16:10:00+00:00" + } + ] + }, + { + "user": "scrivas-storage-user", + "mfa": false, + "keys": [ + { + "id": "AXMK", + "status": "Active", + "age_days": 161, + "last_used": "2026-03-18T14:20:00+00:00" + } + ] + }, + { + "user": "Vasilii", + "mfa": true, + "keys": [ + { + "id": "DFAO", + "status": "Active", + "age_days": 147, + "last_used": "2026-08-19T15:38:00+00:00" + } + ] + }, + { + "user": "Yegor", + "mfa": true, + "keys": [] + } + ] + }, + "census": { + "s3_buckets": 9, + "by_region": { + "us-east-1": { + "(empty)": true + }, + "us-east-2": { + "ec2_instances": 7, + "ebs_volumes": 9, + "ebs_unattached": 2, + "eips": 7 + } + } + }, + "exposure": { + "public_buckets": [], + "open_security_groups": [ + { + "region": "us-east-2", + "group": "sg-0256d81b7afd54cf9", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-0256d81b7afd54cf9", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-09c07fdd8e013a9c0", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-09c07fdd8e013a9c0", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-09dff2d35b97ded21", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-09dff2d35b97ded21", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-00c13b6b4f05b6748", + "from_port": 3478, + "to_port": 3478, + "proto": "udp" + }, + { + "region": "us-east-2", + "group": "sg-00c13b6b4f05b6748", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-00c13b6b4f05b6748", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-0621cd7244c8006b3", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-0621cd7244c8006b3", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-0823502d51c886ab1", + "from_port": 80, + "to_port": 80, + "proto": "tcp" + }, + { + "region": "us-east-2", + "group": "sg-0823502d51c886ab1", + "from_port": 443, + "to_port": 443, + "proto": "tcp" + } + ], + "public_rds": [] + }, + "security_services": { + "cloudtrail": [ + { + "name": "us-east-2", + "multi_region": true, + "org_trail": true, + "log_validation": true + } + ], + "guardduty_findings_by_severity": { + "us-east-1": { + "2.0": 4, + "5.0": 1, + "9.0": 1 + }, + "us-east-2": { + "8.0": 1, + "9.0": 1, + "2.0": 3, + "5.0": 6 + } + }, + "securityhub": { + "us-east-1": "enabled", + "us-east-2": "enabled" + } + }, + "cost": { + "monthly_total": [ + { + "month": "2026-01-01", + "total": 223.29 + }, + { + "month": "2026-02-01", + "total": 130.76 + }, + { + "month": "2026-03-01", + "total": 522.3 + }, + { + "month": "2026-04-01", + "total": 731.93 + }, + { + "month": "2026-05-01", + "total": 745.58 + }, + { + "month": "2026-06-01", + "total": 821.01 + }, + { + "month": "2026-07-01", + "total": 858.16 + } + ], + "top_services_6mo": [ + { + "service": "Amazon Elastic Compute Cloud - Compute", + "cost": 2722.15 + }, + { + "service": "EC2 - Other", + "cost": 374.59 + }, + { + "service": "AWS WAF", + "cost": 364.0 + }, + { + "service": "AWS Security Hub", + "cost": 152.97 + }, + { + "service": "Amazon Virtual Private Cloud", + "cost": 116.52 + }, + { + "service": "AWS Config", + "cost": 84.34 + }, + { + "service": "Amazon GuardDuty", + "cost": 56.2 + }, + { + "service": "Amazon Elastic Container Service for Kubernetes", + "cost": 46.75 + }, + { + "service": "AWS CloudTrail", + "cost": 41.48 + }, + { + "service": "AmazonCloudWatch", + "cost": 21.42 + }, + { + "service": "AWS Key Management Service", + "cost": 15.18 + }, + { + "service": "Amazon Elastic Load Balancing", + "cost": 10.56 + } + ] + } + } + ] +} \ No newline at end of file diff --git a/findings/member_lazka_547868853286.json b/findings/member_lazka_547868853286.json new file mode 100644 index 0000000..dc9f7a2 --- /dev/null +++ b/findings/member_lazka_547868853286.json @@ -0,0 +1,132 @@ +{ + "generated": "2026-08-19T16:10:07.425514+00:00", + "account_id": "547868853286", + "account_name": "Lazka", + "access": { + "assumed": true, + "role_used": "OrganizationAccountAccessRole", + "assumed_arn": "arn:aws:sts::547868853286:assumed-role/OrganizationAccountAccessRole/scrivas-discovery" + }, + "iam_role_trust_policies": [ + { + "RoleName": "AWSServiceRoleForAwsUserNotifications", + "Path": "/aws-service-role/notifications.amazonaws.com/", + "Kind": [ + "service" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "notifications.amazonaws.com" + }, + "Action": "sts:AssumeRole" + } + ] + } + }, + { + "RoleName": "AWSServiceRoleForCloudTrail", + "Path": "/aws-service-role/cloudtrail.amazonaws.com/", + "Kind": [ + "service" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "cloudtrail.amazonaws.com" + }, + "Action": "sts:AssumeRole" + } + ] + } + }, + { + "RoleName": "AWSServiceRoleForOrganizations", + "Path": "/aws-service-role/organizations.amazonaws.com/", + "Kind": [ + "service" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "organizations.amazonaws.com" + }, + "Action": "sts:AssumeRole" + } + ] + } + }, + { + "RoleName": "AWSServiceRoleForSupport", + "Path": "/aws-service-role/support.amazonaws.com/", + "Kind": [ + "service" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "support.amazonaws.com" + }, + "Action": "sts:AssumeRole" + } + ] + } + }, + { + "RoleName": "AWSServiceRoleForTrustedAdvisor", + "Path": "/aws-service-role/trustedadvisor.amazonaws.com/", + "Kind": [ + "service" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "Service": "trustedadvisor.amazonaws.com" + }, + "Action": "sts:AssumeRole" + } + ] + } + }, + { + "RoleName": "OrganizationAccountAccessRole", + "Path": "/", + "Kind": [ + "cross-account/aws" + ], + "Vendor": null, + "AssumeRolePolicyDocument": { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": { + "AWS": "arn:aws:iam::716468089330:root" + }, + "Action": "sts:AssumeRole" + } + ] + } + } + ] +} \ No newline at end of file diff --git a/findings/org_assessment_report.json b/findings/org_assessment_report.json new file mode 100644 index 0000000..8e787ad --- /dev/null +++ b/findings/org_assessment_report.json @@ -0,0 +1,923 @@ +{ + "generated": "2026-08-19T16:08:34.074423+00:00", + "caller": { + "Account": "716468089330", + "Arn": "arn:aws:iam::716468089330:user/louis" + }, + "organization": { + "Id": "o-qfj0pvhhv7", + "Arn": "arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7", + "FeatureSet": "ALL", + "MasterAccountArn": "arn:aws:organizations::716468089330:account/o-qfj0pvhhv7/716468089330", + "MasterAccountId": "716468089330", + "MasterAccountEmail": "ScrivasAdmin@scrivas.com", + "AvailablePolicyTypes": [ + { + "Type": "SERVICE_CONTROL_POLICY", + "Status": "ENABLED" + } + ] + }, + "trusted_access_services": [ + { + "ServicePrincipal": "cloudtrail.amazonaws.com", + "DateEnabled": "2025-10-20T14:05:58.424000-04:00" + }, + { + "ServicePrincipal": "guardduty.amazonaws.com", + "DateEnabled": "2026-02-19T06:26:23.375000-05:00" + }, + { + "ServicePrincipal": "inspector2.amazonaws.com", + "DateEnabled": "2026-02-19T06:26:23.873000-05:00" + }, + { + "ServicePrincipal": "malware-protection.guardduty.amazonaws.com", + "DateEnabled": "2026-02-19T06:26:25.203000-05:00" + }, + { + "ServicePrincipal": "notifications.amazonaws.com", + "DateEnabled": "2026-04-07T11:57:56.557000-04:00" + }, + { + "ServicePrincipal": "securityhub.amazonaws.com", + "DateEnabled": "2026-02-19T06:26:23.087000-05:00" + } + ], + "delegated_administrators": [], + "org_resource_policy": { + "error": "An error occurred (ResourcePolicyNotFoundException) when calling the DescribeResourcePolicy operation: No resource-based policy found." + }, + "iam_role_trust_policies": [ + { + "RoleName": "AmazonEKSAutoClusterRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/AmazonEKSAutoClusterRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": [ + "sts:AssumeRole", + "sts:TagSession" + ], + "Principal": { + "Service": "eks.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AmazonEKSAutoNodeRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/AmazonEKSAutoNodeRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AmazonEKSPodIdentityAmazonEBSCSIDriverRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonEBSCSIDriverRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": [ + "sts:AssumeRole", + "sts:TagSession" + ], + "Principal": { + "Service": "pods.eks.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AmazonEKSPodIdentityAmazonVPCCNIRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonVPCCNIRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": [ + "sts:AssumeRole", + "sts:TagSession" + ], + "Principal": { + "Service": "pods.eks.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AmazonEKS_EBS_CSI_DriverRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole", + "Kind": [ + "federated" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRoleWithWebIdentity", + "Principal": { + "Federated": "arn:aws:iam::716468089330:oidc-provider/oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF" + }, + "Condition": { + "StringEquals": { + "oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF:aud": "sts.amazonaws.com", + "oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF:sub": "system:serviceaccount:kube-system:ebs-csi-controller-sa" + } + } + } + ] + }, + { + "RoleName": "applications-eks-node-group-20251007184911320300000008", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/applications-eks-node-group-20251007184911320300000008", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAccessAnalyzer", + "Path": "/aws-service-role/access-analyzer.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/access-analyzer.amazonaws.com/AWSServiceRoleForAccessAnalyzer", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "access-analyzer.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonEKS", + "Path": "/aws-service-role/eks.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/eks.amazonaws.com/AWSServiceRoleForAmazonEKS", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "eks.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonEKSNodegroup", + "Path": "/aws-service-role/eks-nodegroup.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/eks-nodegroup.amazonaws.com/AWSServiceRoleForAmazonEKSNodegroup", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "eks-nodegroup.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonGuardDuty", + "Path": "/aws-service-role/guardduty.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/guardduty.amazonaws.com/AWSServiceRoleForAmazonGuardDuty", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "guardduty.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonGuardDutyMalwareProtection", + "Path": "/aws-service-role/malware-protection.guardduty.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/malware-protection.guardduty.amazonaws.com/AWSServiceRoleForAmazonGuardDutyMalwareProtection", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "malware-protection.guardduty.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonInspector2", + "Path": "/aws-service-role/inspector2.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "inspector2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonInspector2Agentless", + "Path": "/aws-service-role/agentless.inspector2.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "agentless.inspector2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAmazonMacie", + "Path": "/aws-service-role/macie.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/macie.amazonaws.com/AWSServiceRoleForAmazonMacie", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "macie.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForApplicationInsights", + "Path": "/aws-service-role/application-insights.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/application-insights.amazonaws.com/AWSServiceRoleForApplicationInsights", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "application-insights.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAutoScaling", + "Path": "/aws-service-role/autoscaling.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "autoscaling.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForAwsUserNotifications", + "Path": "/aws-service-role/notifications.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/notifications.amazonaws.com/AWSServiceRoleForAwsUserNotifications", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "notifications.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForCloudTrail", + "Path": "/aws-service-role/cloudtrail.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/cloudtrail.amazonaws.com/AWSServiceRoleForCloudTrail", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "cloudtrail.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForConfig", + "Path": "/aws-service-role/config.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/config.amazonaws.com/AWSServiceRoleForConfig", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "config.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForEC2Spot", + "Path": "/aws-service-role/spot.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "spot.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForElasticLoadBalancing", + "Path": "/aws-service-role/elasticloadbalancing.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/elasticloadbalancing.amazonaws.com/AWSServiceRoleForElasticLoadBalancing", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "elasticloadbalancing.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForGlobalAccelerator", + "Path": "/aws-service-role/globalaccelerator.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/globalaccelerator.amazonaws.com/AWSServiceRoleForGlobalAccelerator", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "globalaccelerator.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForOrganizations", + "Path": "/aws-service-role/organizations.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/organizations.amazonaws.com/AWSServiceRoleForOrganizations", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "organizations.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForRDS", + "Path": "/aws-service-role/rds.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "rds.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForResourceExplorer", + "Path": "/aws-service-role/resource-explorer-2.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/resource-explorer-2.amazonaws.com/AWSServiceRoleForResourceExplorer", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "resource-explorer-2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForSecurityHub", + "Path": "/aws-service-role/securityhub.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/securityhub.amazonaws.com/AWSServiceRoleForSecurityHub", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "securityhub.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForSecurityHubV2", + "Path": "/aws-service-role/securityhubv2.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/securityhubv2.amazonaws.com/AWSServiceRoleForSecurityHubV2", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "securityhubv2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForServiceQuotas", + "Path": "/aws-service-role/servicequotas.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/servicequotas.amazonaws.com/AWSServiceRoleForServiceQuotas", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "servicequotas.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForSupport", + "Path": "/aws-service-role/support.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/support.amazonaws.com/AWSServiceRoleForSupport", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "support.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSServiceRoleForTrustedAdvisor", + "Path": "/aws-service-role/trustedadvisor.amazonaws.com/", + "Arn": "arn:aws:iam::716468089330:role/aws-service-role/trustedadvisor.amazonaws.com/AWSServiceRoleForTrustedAdvisor", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "trustedadvisor.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "AWSSystemsManagerDefaultEC2InstanceManagementRole", + "Path": "/service-role/", + "Arn": "arn:aws:iam::716468089330:role/service-role/AWSSystemsManagerDefaultEC2InstanceManagementRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ssm.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "CloudTrailRoleForCloudWatchLogs_MainTrail", + "Path": "/service-role/", + "Arn": "arn:aws:iam::716468089330:role/service-role/CloudTrailRoleForCloudWatchLogs_MainTrail", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "cloudtrail.amazonaws.com" + }, + "Condition": { + "StringEquals": { + "aws:SourceArn": "arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2", + "aws:SourceAccount": "716468089330" + } + } + } + ] + }, + { + "RoleName": "EC2-CloudWatchAgent-Role", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "EC2-SSM-Access", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/EC2-SSM-Access", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "EC2SSMRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/EC2SSMRole", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "FlowLogsToCloudWatch", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/FlowLogsToCloudWatch", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "vpc-flow-logs.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "gpu-eks-node-group-20251007184911320100000007", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/gpu-eks-node-group-20251007184911320100000007", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "infrastructure-eks-node-group-20251007184911319500000006", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/infrastructure-eks-node-group-20251007184911319500000006", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "ec2.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "IntruderReadOnlyRole", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/IntruderReadOnlyRole", + "Kind": [ + "cross-account/aws" + ], + "Vendor": "Intruder.io (external vulnerability scanning)", + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "AWS": "arn:aws:iam::123311413059:root" + }, + "Condition": { + "StringEquals": { + "sts:ExternalId": "8bb7691d-579b-41ef-ae48-5cc3983bcc7f" + } + } + } + ] + }, + { + "RoleName": "rds-monitoring-role", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/rds-monitoring-role", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "monitoring.rds.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "scrivas-staging-cluster-20251007184855668200000001", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "eks.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "SecureframeRole-f983f1e89008", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008", + "Kind": [ + "cross-account/aws" + ], + "Vendor": "Secureframe (SOC 2 / compliance automation)", + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "AWS": "arn:aws:iam::728997465891:root" + }, + "Condition": { + "StringEquals": { + "sts:ExternalId": "d3f0ba8c-2023-4cf6-8846-f983f1e89008" + } + } + } + ] + }, + { + "RoleName": "vpc-flow-logs-role", + "Path": "/", + "Arn": "arn:aws:iam::716468089330:role/vpc-flow-logs-role", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "vpc-flow-logs.amazonaws.com" + }, + "Condition": null + } + ] + }, + { + "RoleName": "VPCFlowLogs-Cloudwatch-1781174191538", + "Path": "/service-role/", + "Arn": "arn:aws:iam::716468089330:role/service-role/VPCFlowLogs-Cloudwatch-1781174191538", + "Kind": [ + "service" + ], + "Vendor": null, + "Statements": [ + { + "Effect": "Allow", + "Action": "sts:AssumeRole", + "Principal": { + "Service": "vpc-flow-logs.amazonaws.com" + }, + "Condition": { + "StringEquals": { + "aws:SourceAccount": "716468089330" + }, + "ArnLike": { + "aws:SourceArn": "arn:aws:ec2:us-east-2:716468089330:vpc-flow-log/*" + } + } + } + ] + } + ] +} \ No newline at end of file diff --git a/findings/prowler/prowler-output-716468089330-20260819124039.html b/findings/prowler/prowler-output-716468089330-20260819124039.html new file mode 100644 index 0000000..9dac4ee --- /dev/null +++ b/findings/prowler/prowler-output-716468089330-20260819124039.html @@ -0,0 +1,60130 @@ + + + + + + + + + + + + + + Prowler - The Handy Cloud Security Tool + + +
+
+
+ prowler-logo +
+
+ Report Information +
+
    +
  • +
    +
    + Version: 5.39.1 +
    +
    +
  • +
  • + Parameters used: aws --profile dasnuve-scrivas-louis-impersonation --region us-east-2 us-east-1 -M csv json-ocsf html -o /Users/alvaro/Develop/dasnuve/scrivas/findings/prowler --no-banner +
  • +
  • + Date: 2026-08-19T12:40:39.730996 +
  • +
+
+
+
+
+
+ AWS Assessment Summary +
+
    +
  • + AWS Account: 716468089330 +
  • +
  • + AWS-CLI Profile: dasnuve-scrivas-louis-impersonation +
  • +
  • + Audited Regions: us-east-1, us-east-2 +
  • +
+
+
+
+
+
+ AWS Credentials +
+
    +
  • + User Id: AIDA2NUGTOHZOHX3GWS4T +
  • +
  • + Caller Identity ARN: arn:aws:iam::716468089330:user/louis +
  • +
+
+
+
+
+
+ Assessment Overview +
+
    +
  • + Total Findings: 1224 +
  • +
  • + Passed: 861 +
  • +
  • + Passed (Muted): 0 +
  • +
  • + Failed: 363 +
  • +
  • + Failed (Muted): 0 +
  • +
  • + Total Resources: 269 +
  • +
+
+
+
+
+
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
StatusSeverityService NameRegionCheck IDCheck TitleResource IDResource TagsStatus ExtendedRiskRecommendationCompliance
PASSlowaccessanalyzerus-east-1accessanalyzer_enabledIAM Access Analyzer is enabledarn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zdIAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd is enabled.

Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity.

Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes.

+•CIS-7.0: 2.18 + +•CIS-1.4: 1.20 + +•CIS-1.5: 1.20 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC + +•CIS-2.0: 1.20 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6 + +•CIS-5.0: 1.19 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view + +•CIS-3.0: 1.20 + +•CIS-6.0: 2.19 + +•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.2.6 + +•ISO27001-2022: A.8.3 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-02 + +•CIS-4.0.1: 1.20 + +•NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e +

FAILlowaccessanalyzerus-east-2accessanalyzer_enabledIAM Access Analyzer is enabledarn:aws:accessanalyzer:us-east-2:716468089330:analyzer/unknownIAM Access Analyzer in account 716468089330 is not enabled.

Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity.

Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes.

+•CIS-7.0: 2.18 + +•CIS-1.4: 1.20 + +•CIS-1.5: 1.20 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC + +•CIS-2.0: 1.20 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6 + +•CIS-5.0: 1.19 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view + +•CIS-3.0: 1.20 + +•CIS-6.0: 2.19 + +•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.2.6 + +•ISO27001-2022: A.8.3 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-02 + +•CIS-4.0.1: 1.20 + +•NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e +

PASSlowaccessanalyzerus-east-1accessanalyzer_enabled_without_findingsIAM Access Analyzer analyzer is active and has no active findingsarn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zdIAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd does not have active findings.

Unresolved Active findings indicate unintended external or internal access paths.
+- Confidentiality: public/cross-account reads of data (buckets, snapshots, secrets)
+- Integrity: rogue role assumption or KMS use enabling policy/data changes
+- Lateral movement across accounts

Enable IAM Access Analyzer in all relevant Regions and org/account scopes. Triage every Active finding:
+- Remove unintended access by tightening resource and trust policies
+- Enforce least privilege and separation of duties
+- Archive only validated, intended access
+- Continuously monitor and automate reviews

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: AM-09.04AC, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: ov_2, ac_4, cm_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view + +•AWS-Foundational-Technical-Review: SECOPS-001 + +•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01 + +•SecNumCloud-3.2: 9.4 + +•ISO27001-2022: A.8.3 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-02 + +•NIS2: 2.1.2.g, 2.1.2.h +

MANUALmediumaccountus-east-2account_maintain_current_contact_detailsAWS account contact information is currentarn:aws:iam::716468089330:rootLogin to the AWS Console. Choose your account name on the top right of the window -> My Account -> Contact Information.

Outdated or single-person contacts delay security notifications, slow incident response, and complicate account recovery.
+
+AWS may throttle services during abuse mitigation, reducing availability. Missed alerts enable ongoing misuse, risking data exfiltration and unauthorized changes (integrity).

Adopt:
+- Primary and alternate contacts for security, billing, operations
+- Shared, monitored aliases and SMS-capable phone numbers (non-personal)
+- Centralized management across accounts with periodic reviews
+- Least privilege for who can modify contact data
+- Regular reachability tests and documented ownership

+•CIS-7.0: 2.2 + +•CIS-1.4: 1.1 + +•CIS-1.5: 1.1 + +•KISA-ISMS-P-2023: 2.10.2 + +•C5-2025: IAM-03.01AS, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B + +•CIS-2.0: 1.1 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 + +•CIS-5.0: 1.1 + +•AWS-Account-Security-Onboarding: Billing, emergency, security contacts + +•CIS-3.0: 1.1 + +•ENS-RD2022: op.ext.7.aws.am.1 + +•CIS-6.0: 2.1 + +•ISO27001-2022: A.5.5 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-03 + +•CIS-4.0.1: 1.1 + +•NIS2: 2.2.3, 3.5.3.a, 5.1.7.b +

FAILmediumaccountus-east-2account_maintain_different_contact_details_to_security_billing_and_operationsAWS account has distinct Security, Billing, and Operations contact details, different from each other and from the root contactarn:aws:iam::716468089330:rootSECURITY, BILLING and OPERATIONS contacts not found or they are not different between each other and between ROOT contact.

Missing or shared contacts can delay response to abuse alerts, credential compromise, or billing anomalies, reducing availability (possible AWS traffic throttling) and raising confidentiality and integrity risk through extended exposure. If AWS cannot reach you, urgent mitigation may disrupt service.

Maintain distinct, monitored Security, Billing, and Operations alternate contacts that differ from the root contact.
+- Use team aliases and 24x7 phones
+- Review and test contact paths regularly
+- Centralize at org level for consistency
+
+Applies operational resilience and separation of duties.

+•KISA-ISMS-P-2023: 2.10.2 + +•C5-2025: OIS-04.03B, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•ISO27001-2022: A.5.6 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-03 +

MANUALmediumaccountus-east-2account_security_contact_information_is_registeredAWS account has security alternate contact registeredarn:aws:iam::716468089330:rootLogin to the AWS Console. Choose your account name on the top right of the window -> My Account -> Alternate Contacts -> Security Section.

Missing or outdated security contact can delay or prevent AWS advisories from reaching responders, increasing risk to:
+- Confidentiality: data exfiltration from undetected compromise
+- Integrity: unauthorized changes persist longer
+- Availability: resource abuse (e.g., cryptomining) and outages

Define and maintain a Security alternate contact:
+- Use a monitored alias (e.g., security@domain) and team phone
+- Apply to every account (prefer Org-wide automation)
+- Review after org/personnel changes and test delivery
+- Document ownership and escalation paths
+Align with incident response and least privilege principles.

+•CIS-7.0: 2.3 + +•CIS-1.4: 1.2 + +•CIS-1.5: 1.2 + +•AWS-Foundational-Security-Best-Practices: Account.1 + +•KISA-ISMS-P-2023: 2.10.2 + +•C5-2025: OIS-06.01B, SSO-05.06B, SIM-01.03B + +•CIS-2.0: 1.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 + +•CIS-5.0: 1.2 + +•PCI-4.0: A1.2.3.1 + +•AWS-Account-Security-Onboarding: Billing, emergency, security contacts + +•CIS-3.0: 1.2 + +•ENS-RD2022: op.ext.7.aws.am.1 + +•CIS-6.0: 2.2 + +•ISO27001-2022: A.5.5 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-03 + +•CIS-4.0.1: 1.2 + +•NIS2: 1.1.1.a, 1.2.3, 2.2.1, 3.1.2.d, 3.5.3.a, 5.1.7.b +

MANUALmediumaccountus-east-2account_security_questions_are_registered_in_the_aws_account[DEPRECATED] AWS root user has security challenge questions configuredarn:aws:iam::716468089330:rootLogin to the AWS Console as root. Choose your account name on the top right of the window -> My Account -> Configure Security Challenge Questions.

Absence of these questions can limit support-assisted recovery if root credentials or MFA are lost, reducing availability and slowing incident response. Reliance on KBA also weakens confidentiality due to social engineering. Treat this as a recovery gap and adopt stronger, phishing-resistant factors.

Favor stronger recovery instead of KBA:
+- Enforce MFA for root and minimize root use
+- Keep alternate contacts and root email current and protected
+- Establish a tightly controlled break-glass role, applying least privilege and separation of duties
+- Document and test recovery procedures; monitor root activity

+•CIS-1.4: 1.3 + +•CIS-1.5: 1.3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.3, 2.10.2 + +•CIS-2.0: 1.3 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01 + +•CIS-3.0: 1.3 + +•ENS-RD2022: op.ext.7.aws.am.1 + +•CIS-4.0.1: 1.3 +

FAILlowbackupus-east-2backup_vaults_existAt least one AWS Backup vault existsarn:aws:backup:us-east-2:716468089330:backup-vaultNo Backup Vault exist.

Without a vault, recovery points cannot be created or retained in AWS Backup, degrading availability and integrity. Data may be irrecoverable after deletion, ransomware, or misconfiguration, and RPO/RTO targets may be missed during incidents.

Create and maintain a backup vault in each required region. Enforce least privilege access, encrypt with KMS CMKs, and enable Vault Lock to prevent tampering. Use lifecycle rules and cross-region/cross-account copies, and regularly test restores for defense in depth.

+•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, OPS-08.01B, OPS-09.02B, CRY-16.02B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: be_5, ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•ENS-RD2022: mp.info.6.aws.bcku.1 + +•AWS-Foundational-Technical-Review: BAR-001 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR01, CCC.Core.CN14.AR02, CCC.Core.CN14.AR03 + +•SecNumCloud-3.2: 12.5, 17.6 + +•ISO27001-2022: A.8.13 + +•NIS2: 3.6.2, 4.1.2.f, 4.1.2.g, 4.2.2.b, 4.2.2.e, 12.1.2.c, 12.2.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl +

PASShighbedrockus-east-2bedrock_full_access_policy_attachedIAM role does not have AmazonBedrockFullAccess managed policy attachedarn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRoleIAM Role AmazonEKS_EBS_CSI_DriverRole does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
+- Invoke any model to exfiltrate data or generate harmful content
+- Modify guardrails, logging, and security configurations
+- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
+
+Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

+•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•SecNumCloud-3.2: 9.3 + +•ISO27001-2022: A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighbedrockus-east-2bedrock_full_access_policy_attachedIAM role does not have AmazonBedrockFullAccess managed policy attachedarn:aws:iam::716468089330:role/IntruderReadOnlyRoleIAM Role IntruderReadOnlyRole does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
+- Invoke any model to exfiltrate data or generate harmful content
+- Modify guardrails, logging, and security configurations
+- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
+
+Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

+•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•SecNumCloud-3.2: 9.3 + +•ISO27001-2022: A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighbedrockus-east-2bedrock_full_access_policy_attachedIAM role does not have AmazonBedrockFullAccess managed policy attachedarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008IAM Role SecureframeRole-f983f1e89008 does not have AmazonBedrockFullAccess policy attached.

The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
+- Invoke any model to exfiltrate data or generate harmful content
+- Modify guardrails, logging, and security configurations
+- Incur significant costs through unrestricted model invocations

Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
+
+Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges.

+•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•SecNumCloud-3.2: 9.3 + +•ISO27001-2022: A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

FAILmediumbedrockus-east-1bedrock_guardrails_configuredBedrock has at least one guardrail configured in the audited regionarn:aws:bedrock:us-east-1:716468089330:guardrailsBedrock has no guardrails configured in region us-east-1.

Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere.

Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
+- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
+- Add sensitive information filters and denied topic policies
+- Apply guardrails at the API call level using guardrailIdentifier where supported

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-AI-Security-Framework-1.0: AISF-AI-01 +

FAILmediumbedrockus-east-2bedrock_guardrails_configuredBedrock has at least one guardrail configured in the audited regionarn:aws:bedrock:us-east-2:716468089330:guardrailsBedrock has no guardrails configured in region us-east-2.

Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere.

Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
+- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
+- Add sensitive information filters and denied topic policies
+- Apply guardrails at the API call level using guardrailIdentifier where supported

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-AI-Security-Framework-1.0: AISF-AI-01 +

FAILmediumbedrockus-east-1bedrock_model_invocation_logging_enabledAmazon Bedrock model invocation logging is enabledarn:aws:bedrock:us-east-1:716468089330:model-invocation-loggingBedrock Model Invocation Logging is disabled.

Without invocation logs, you lose auditability and forensic visibility into model activity.
+
+Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response.

Enable model invocation logging and route events to CloudWatch Logs and/or S3.
+
+Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties.

+•SOC2: cc_a_1_1 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•CCC-v2025.10: CCC.GenAI.CN05.AR01 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-AI-05 + +•NIS2: 3.2.3.c +

FAILmediumbedrockus-east-2bedrock_model_invocation_logging_enabledAmazon Bedrock model invocation logging is enabledarn:aws:bedrock:us-east-2:716468089330:model-invocation-loggingBedrock Model Invocation Logging is disabled.

Without invocation logs, you lose auditability and forensic visibility into model activity.
+
+Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response.

Enable model invocation logging and route events to CloudWatch Logs and/or S3.
+
+Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties.

+•SOC2: cc_a_1_1 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•CCC-v2025.10: CCC.GenAI.CN05.AR01 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-AI-05 + +•NIS2: 3.2.3.c +

FAILlowbedrockus-east-1bedrock_prompt_management_existsAmazon Bedrock Prompt Management prompts exist in the regionarn:aws:bedrock:us-east-1:716468089330:prompt-managementNo Bedrock Prompt Management prompts exist in region us-east-1.

Without Prompt Management, prompts are scattered across applications with no central oversight, versioning, or auditability over instructions sent to foundation models, weakening governance and compliance posture.
+
+Managed prompts are a governance enabler; prompt injection defenses are provided by Bedrock guardrails, covered by separate checks.

Adopt Bedrock Prompt Management to centralize prompt definitions, enforce versioning, and maintain governance over model interactions.
+
+Use managed prompts with guardrails and apply least privilege access controls to restrict who can create or modify prompts.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-AI-Security-Framework-1.0: AISF-AI-07 +

PASScriticalcloudformationus-east-2cloudformation_stack_outputs_find_secretsCloudFormation stack outputs do not contain secretsarn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bddNo secrets found in CloudFormation Stack Secureframe-f983f1e89008 Outputs.

Secrets in Outputs are readable to anyone with stack metadata access, enabling credential theft, unauthorized API calls, and lateral movement. Exposure via consoles, exports, or CI logs undermines confidentiality and can lead to privilege escalation and data exfiltration.

Remove secrets from Outputs. Store credentials in Secrets Manager or Parameter Store and reference them via dynamic references; set NoEcho for sensitive parameters. Apply least privilege to view stack metadata, avoid exporting sensitive values, and add automated IaC secret scanning for defense in depth.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: DEV-02.01B + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 +

FAILmediumcloudformationus-east-2cloudformation_stacks_termination_protection_enabledCloudFormation stack has termination protection enabledarn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bddCloudFormation Stack Secureframe-f983f1e89008 has termination protection disabled.

Without termination protection, human error or automation can delete entire stacks, causing immediate availability loss and potential data destruction of managed resources.
+
+Attackers with delete rights can more easily trigger outages and hinder recovery.

Enable termination protection on root stacks for critical workloads. Enforce least privilege on who can alter this setting or delete stacks, require change review via change sets, and apply stack policies plus DeletionPolicy: Retain for data stores for defense in depth.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03 +

PASSmediumcloudtrailus-east-2cloudtrail_bedrock_logging_enabledCloudTrail logs Amazon Bedrock API calls for security auditingarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 from home region us-east-2 has an advanced management event selector to log Amazon Bedrock control-plane API calls.

Without CloudTrail logging for Bedrock control-plane operations, changes to prompts, guardrails, agents, flows, or knowledge bases can become invisible, weakening forensics and incident response. Management events do not capture InvokeModel; pair this control with bedrock_model_invocation_logging_enabled or Bedrock data event selectors for invocation visibility.

Enable CloudTrail logging for Amazon Bedrock on at least one actively logging trail. At minimum, enable management events to capture Bedrock control-plane operations. For invocation-level and other data-plane visibility, add advanced event selectors targeting Bedrock resource types or pair this control with bedrock_model_invocation_logging_enabled.
+
+For broader region coverage, pair this control with a separate multi-region CloudTrail check. Centralize logs in an encrypted bucket or CloudWatch Logs to support defense in depth and forensic readiness for AI workloads.

+•SOC2: cc_7_2 + +•KISA-ISMS-P-2023: 2.9.4 + +•C5-2025: OPS-12.01B, OPS-15.01B + +•HIPAA: 164_308_a_1_ii_d, 164_312_b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-CSF-2.0: pt_1, ae_3, cm_3 + +•NIST-800-53-Revision-5: au_2_b, au_12_a, au_12_c + +•CCC-v2025.10: CCC.AuditLog.CN02.AR01 + +•SecNumCloud-3.2: 12.6 + +•FFIEC: d2-ma-ma-b-2 + +•ISO27001-2022: A.8.15 + +•FedRamp-Moderate-Revision-4: au-2-a-d, au-12-a-c +

FAILmediumcloudtrailus-east-2cloudtrail_bucket_requires_mfa_deleteCloudTrail trail S3 bucket has MFA delete enabledarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 bucket (aws-cloudtrail-logs-716468089330-fb4a4f88) does not have MFA delete enabled.

Without MFA Delete, stolen or over-privileged credentials can permanently delete log versions or change versioning, compromising log integrity and availability. This enables attacker cover-ups, hinders forensics, and weakens evidence for investigations.

Enable MFA Delete on the CloudTrail log bucket with versioning enabled. Enforce least privilege so only tightly controlled identities can delete or alter logs, and require MFA for such actions. Apply defense in depth using a dedicated logging account and log file integrity validation.

+•KISA-ISMS-P-2023: 2.5.3, 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-09.02B, IAM-09.01AC, COM-04.01AC, PSS-05.01B, PSS-07.02B, PSS-12.03AC + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.9.4, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_3 + +•ENS-RD2022: op.exp.8.r4.aws.ct.3 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN07.AR01 + +•SecNumCloud-3.2: 12.7 + +•NIS2: 11.7.2 +

PASSlowcloudtrailus-east-2cloudtrail_cloudwatch_logging_enabledCloudTrail trail has delivered logs to CloudWatch Logs in the last 24 hoursarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Multiregion trail us-east-2 has been logging in the last 24h.

Missing or stale CloudWatch delivery weakens visibility and delays detection, impacting confidentiality and integrity. Adversaries can:
+- Hide privilege escalation
+- Perform unauthorized resource changes
+- Exfiltrate data via API misuse

Integrate every trail with CloudWatch Logs and maintain continuous, near-real-time delivery. Enforce least privilege on the delivery role, prefer multi-Region coverage, and implement metric filters and alerts for sensitive actions. Centralize retention to support defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_a_1_1, pi_1_3 + +•CIS-1.4: 3.4 + +•CIS-1.5: 3.4 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.5 + +•ISO27001-2013: A.12.4.Q + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.01AC, OIS-05.02B, AM-01.01AC, OPS-11.02AC, OPS-13.01B, OPS-13.02B, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-02.01B, SIM-03.07B, COM-04.01AC, PSS-04.01B, PSS-04.05B, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 3.4 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-CSF-2.0: ip_8, ae_1, ae_3, cm_1, cm_3, cm_7 + +•NIST-800-171-Revision-2: 3_3_1, 3_3_2, 3_3_3, 3_3_5, 3_6_1, 3_6_2, 3_12_4 + +•PCI-4.0: 10.2.1.1.10, 10.2.1.2.8, 10.2.1.3.8, 10.2.1.4.8, 10.2.1.5.8, 10.2.1.6.8, 10.2.1.7.8, 10.2.1.8, 10.2.2.8, 10.3.1.8, 10.4.1.1.3, 10.6.3.10, 11.5.2.4, 11.6.1.4, 12.10.5.4, 5.3.4.9, A1.2.1.10, A3.3.1.6, A3.5.1.6 + +•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_6_1, au_6_3, au_7_1, au_12, ca_7, si_4_2, si_4_4, si_4_5, si_4 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_4_1, au_6_1, au_6_3, au_6_4, au_6_5, au_6_6, au_6_9, au_7_1, au_8_b, au_9_7, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, au_16, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•ENS-RD2022: op.exp.8.r1.aws.ct.7, op.mon.3.aws.cwl.1 + +•NIST-CSF-1.1: ae_1, ae_3, cm_2, cm_5, cp_4, ra_5, sc_4, pt_1 + +•AWS-Well-Architected-Framework-Reliability-Pillar: REL06-BP01 + +•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR02, CCC.LB.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-is-is-b-1, d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 + +•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.3, 10.5.4 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-7-1, au-12-a-c, si-4-a-b-c + +•NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSlowcloudtrailus-east-2cloudtrail_insights_existCloudTrail trail has Insights enabledarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 has insight selectors and it is logging.

Without Insights, abnormal API call or error rates can go unnoticed, delaying detection of credential abuse, privilege escalation, or runaway automation. Attackers may rapidly alter policies, delete resources, or exfiltrate data before response, impacting confidentiality and availability.

Enable CloudTrail Insights on all logging trails (ideally all-Region or organization trails). Activate both ApiCallRateInsight and ApiErrorRateInsight. Integrate alerts with monitoring and review anomalies regularly. Apply defense in depth and least privilege to reduce potential blast radius.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-05.02B, SIM-03.07B, COM-04.01AC, PSS-12.03AC + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: cm_1, dp_4 + +•PCI-4.0: 10.3.2.2, 10.3.3.4, 10.3.4.3, 10.5.1.3, 5.3.4.8, A1.2.1.8 + +•ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01 + +•SecNumCloud-3.2: 12.9 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 +

FAILmediumcloudtrailus-east-2cloudtrail_kms_encryption_enabledCloudTrail trail logs are encrypted at rest with a KMS keyarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Multiregion trail us-east-2 has encryption disabled.

Absent a customer-managed KMS key, log protection relies only on storage permissions. Bucket misconfigurations or stolen credentials can expose audit data, aiding evasion and lateral movement. Missing key-level controls, rotation, and usage audit weaken confidentiality and forensic integrity.

Enable SSE-KMS on every trail using a customer-managed KMS key. Apply least privilege so only authorized roles can Decrypt, and enforce separation of duties between key admins and log readers. Rotate keys and monitor key usage to provide defense in depth for CloudTrail data.

+•CISA: your-systems-3, your-data-1 + +•CIS-7.0: 4.5 + +•CIS-1.4: 3.7 + +•CIS-1.5: 3.7 + +•GDPR: article_25, article_30, article_32 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.2 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-11.02AC, OPS-13.03B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, IAM-08.06B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, CRY-10.01AC, CRY-11.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.04B, PSS-12.02B, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 3.7 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5, pt_1, pt_4 + +•CIS-5.0: 3.5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.4, 10.3.3.6, 10.3.4.5, 3.5.1.5, 8.3.2.9, A1.2.1.11 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 3.5 + +•ENS-RD2022: op.exp.8.r4.aws.ct.4, op.exp.8.r4.aws.ct.7 + +•CIS-6.0: 4.5 + +•AWS-Foundational-Technical-Review: SDAT-002 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.3 + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DETECT-01 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•CIS-4.0.1: 3.5 + +•NIS2: 9.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-svc +

PASSmediumcloudtrailus-east-2cloudtrail_log_file_validation_enabledCloudTrail trail has log file validation enabledarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Multiregion trail us-east-2 has log file validation enabled.

Without validation, adversaries can alter, forge, or delete audit entries without detection, compromising log integrity and non-repudiation.
+
+This impairs investigations, enables alert evasion, and obscures unauthorized changes across regions or accounts.

Enable log file integrity validation on all trails (LogFileValidationEnabled=true).
+
+Enforce least privilege on the logs bucket, retain and protect digest files (e.g., S3 Object Lock/MFA Delete), and monitor validation results to support defense in depth.

+•CISA: your-systems-3 + +•CIS-7.0: 4.2 + +•SOC2: cc_7_3, pi_1_3 + +•CIS-1.4: 3.2 + +•CIS-1.5: 3.2 + +•GDPR: article_25, article_32 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.4 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-13.01AC, OPS-15.02AC, OPS-26.05B, OPS-26.01AS, DEV-08.02B, SIM-01.02AC, SIM-03.07B, COM-04.01AC, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_312_b, 164_312_c_1, 164_312_c_2 + +•CIS-2.0: 3.2 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01, SEC06-BP06 + +•NIST-CSF-2.0: ds_6, pt_1 + +•CIS-5.0: 3.2 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_1 + +•PCI-4.0: 10.3.2.5, 10.3.3.7, 10.3.4.6, A1.2.1.12 + +•NIST-800-53-Revision-4: si_7_1, si_7 + +•NIST-800-53-Revision-5: au_9_a, cm_6_a, cm_9_b, pm_11_b, pm_17_b, sa_1_1, sa_10_1, sc_16_1, si_1_a_2, si_4_d, si_7_1, si_7_3, si_7_7, si_7_a + +•CIS-3.0: 3.2 + +•ENS-RD2022: op.exp.8.aws.ct.3 + +•CIS-6.0: 4.2 + +•NIST-CSF-1.1: ds_6, ds_7 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN01.AR01, CCC.AuditLog.CN01.AR02 + +•SecNumCloud-3.2: 10.4, 12.7, 16.6 + +•PCI-3.2.1: 10.5, 10.5.2, 10.5.5 + +•ProwlerThreatScore-1.0: 3.1.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•FedRamp-Moderate-Revision-4: au-9, si-7-1, si-7 + +•FedRAMP-Low-Revision-4: ac-2, au-2, au-9 + +•CIS-4.0.1: 3.2 + +•NIS2: 3.4.2.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla +

PASSmediumcloudtrailus-east-2cloudtrail_logs_s3_bucket_access_logging_enabledCloudTrail trail destination S3 bucket has access logging enabledarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Multiregion Trail us-east-2 S3 bucket access logging is enabled for bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Without access logging on the CloudTrail logs bucket, access and changes to log files lack an independent audit trail. Attackers could read, delete, or replace logs without attribution, undermining log confidentiality and integrity, and slowing incident response.

Enable S3 server access logging on the CloudTrail logs bucket and write logs to a separate, tightly controlled bucket. Apply least privilege, enable versioning, and consider Object Lock to deter tampering. Centralize monitoring to support defense-in-depth and rapid investigation.

+•CIS-7.0: 4.4 + +•SOC2: cc_a_1_1 + +•CIS-1.4: 3.6 + +•CIS-1.5: 3.6 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.7 + +•ISO27001-2013: A.12.4.O + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, IAM-10.01B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, INQ-04.01AC, PSS-04.05B, PSS-12.03AC + +•CIS-2.0: 3.6 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-CSF-2.0: pt_1 + +•CIS-5.0: 3.4 + +•AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM + +•CIS-3.0: 3.4 + +•ENS-RD2022: op.exp.8.r1.aws.ct.6, op.exp.8.r4.aws.ct.5 + +•CIS-6.0: 4.4 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ProwlerThreatScore-1.0: 3.1.3 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•CIS-4.0.1: 3.4 + +•NIS2: 3.2.3.c, 11.1.1, 11.2.2.f +

PASScriticalcloudtrailus-east-2cloudtrail_logs_s3_bucket_is_not_publicly_accessibleCloudTrail trail S3 bucket is not publicly accessiblearn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 from multiregion trail us-east-2 is not publicly accessible.

Exposed CloudTrail logs erode confidentiality and integrity.
+
+Adversaries can harvest API activity to map accounts, roles, and keys, enabling reconnaissance and evasion. If write is allowed, logs can be poisoned or deleted, thwarting investigations and compromising incident timelines.

Apply least privilege to the log bucket:
+- Enable S3 Block Public Access (account and bucket)
+- Remove AllUsers/AuthenticatedUsers ACLs; avoid wildcard principals
+- Permit only CloudTrail and constrain with aws:SourceArn
+
+Use a dedicated private bucket and monitor for permission changes.

+•CIS-1.4: 3.3 + +•CIS-1.5: 3.3 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.6 + +•ISO27001-2013: A.12.4.S, A.12.6.J + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC + +•CIS-2.0: 3.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ds_5, pt_1 + +•ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r4.aws.ct.2, op.exp.8.r4.aws.ct.6 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN04.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 12.7 + +•ProwlerThreatScore-1.0: 2.2.5 + +•ISO27001-2022: A.8.1, A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•NIS2: 3.2.3.c +

PASShighcloudtrailus-east-1cloudtrail_multi_region_enabledRegion has at least one CloudTrail trail loggingarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 is multiregion and it is logging.

Missing coverage in any region creates visibility gaps.
+
+Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity).

Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.
+
+Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 4.1 + +•SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3 + +•CIS-1.4: 3.1 + +•CIS-1.5: 3.1 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.1 + +•ISO27001-2013: A.12.4.T + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 3.1 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03 + +•GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control + +•CIS-5.0: 3.1 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23 + +•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Account-Security-Onboarding: Enable as part of Organization trail + +•CIS-3.0: 3.1 + +•ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1 + +•CIS-6.0: 4.1 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1 + +•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 + +•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ProwlerThreatScore-1.0: 3.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 + +•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 + +•CIS-4.0.1: 3.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07 +

PASShighcloudtrailus-east-2cloudtrail_multi_region_enabledRegion has at least one CloudTrail trail loggingarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 is multiregion and it is logging.

Missing coverage in any region creates visibility gaps.
+
+Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity).

Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.
+
+Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 4.1 + +•SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3 + +•CIS-1.4: 3.1 + +•CIS-1.5: 3.1 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: CloudTrail.1 + +•ISO27001-2013: A.12.4.T + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 3.1 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03 + +•GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control + +•CIS-5.0: 3.1 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23 + +•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Account-Security-Onboarding: Enable as part of Organization trail + +•CIS-3.0: 3.1 + +•ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1 + +•CIS-6.0: 4.1 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1 + +•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3 + +•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ProwlerThreatScore-1.0: 3.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 + +•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 + +•CIS-4.0.1: 3.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07 +

PASSlowcloudtrailus-east-1cloudtrail_multi_region_enabled_logging_management_eventsCloudTrail trail logs management events for read and write operationsarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled.

Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.
+
+Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response.

Enable a multi-region CloudTrail that logs management events for read and write in all regions.
+
+Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4 + +•AWS-Account-Security-Onboarding: Enable as part of Organization trail + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.2, 12.6 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c +

PASSlowcloudtrailus-east-2cloudtrail_multi_region_enabled_logging_management_eventsCloudTrail trail logs management events for read and write operationsarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled.

Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.
+
+Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response.

Enable a multi-region CloudTrail that logs management events for read and write in all regions.
+
+Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4 + +•AWS-Account-Security-Onboarding: Enable as part of Organization trail + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.2, 12.6 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-01 + +•NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c +

PASSlowcloudtrailus-east-2cloudtrail_s3_dataevents_read_enabledCloudTrail trail records S3 object-level read events for all S3 bucketsarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations.

Without object-level read logging, S3 access is opaque. Attackers or insiders can exfiltrate data via GetObject without audit trails, eroding confidentiality and hindering forensics, anomaly detection, and incident response.

Enable CloudTrail data events for S3 objects with ReadOnly (or All) across all current and future buckets. Use a multi-Region trail, centralize logs in an encrypted bucket with lifecycle retention, and integrate monitoring/alerts to support defense in depth and accountable access.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 4.9 + +•SOC2: cc_2_1, cc_7_2 + +•CIS-1.4: 3.11 + +•CIS-1.5: 3.11 + +•GDPR: article_30 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 3.11 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail + +•CIS-5.0: 3.9 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Account-Security-Onboarding: Confirm that logs are present in S3 bucket and SIEM + +•CIS-3.0: 3.9 + +•ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4 + +•CIS-6.0: 4.9 + +•NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ProwlerThreatScore-1.0: 3.1.6 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 + +•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 + +•CIS-4.0.1: 3.9 + +•NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla +

PASSlowcloudtrailus-east-2cloudtrail_s3_dataevents_write_enabledCloudTrail trail records all S3 object-level API operations for all bucketsarn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations.

Without object-level write logging, unauthorized or accidental changes and deletions can go unobserved, undermining data integrity and availability. Forensics lose visibility into who modified or removed objects, hindering detection of ransomware, rogue automation, or insider tampering.

Enable CloudTrail S3 data events for object-level write (and optionally read) across all buckets on a multi-Region trail. Apply least privilege to log storage, set lifecycle retention, and integrate alerts. Use advanced selectors to target sensitive buckets/operations for cost control and defense in depth.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 4.8 + +•SOC2: cc_2_1, cc_7_2, pi_1_2 + +•CIS-1.4: 3.10 + +•CIS-1.5: 3.10 + +•GDPR: article_30 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 3.10 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail + +•CIS-5.0: 3.8 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.7, 10.2.1.2.7, 10.2.1.3.7, 10.2.1.4.7, 10.2.1.5.7, 10.2.1.6.7, 10.2.1.7.7, 10.2.1.7, 10.2.2.7, 10.3.1.7, 10.6.3.7, 5.3.4.7, A1.2.1.7 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM + +•CIS-3.0: 3.8 + +•ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4 + +•CIS-6.0: 4.8 + +•NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5 + +•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.1.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5 + +•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7 + +•CIS-4.0.1: 3.8 + +•NIS2: 3.2.3.c, 3.2.3.g + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_alarm_state_configuredCloudWatch metric alarm has actions configured for the ALARM statearn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alertCloudWatch metric alarm scrivas-dev-api-error-alert has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
+- Availability: prolonged outages or missed scale-out
+- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_7, ip_8, dp_4 + +•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5 +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_alarm_state_configuredCloudWatch metric alarm has actions configured for the ALARM statearn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alertCloudWatch metric alarm scrivas-stage-error-alert has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
+- Availability: prolonged outages or missed scale-out
+- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_7, ip_8, dp_4 + +•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5 +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_alarm_state_configuredCloudWatch metric alarm has actions configured for the ALARM statearn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prodCloudWatch metric alarm scrivas_prod has actions configured for the ALARM state.

Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
+- Availability: prolonged outages or missed scale-out
+- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss

Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_7, ip_8, dp_4 + +•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5 +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_enabledCloudWatch metric alarm has actions enabledarn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alertCloudWatch metric alarm scrivas-dev-api-error-alert has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_8, dp_4 + +•CCC-v2025.10: CCC.LB.CN06.AR01 + +•SecNumCloud-3.2: 16.2 +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_enabledCloudWatch metric alarm has actions enabledarn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alertCloudWatch metric alarm scrivas-stage-error-alert has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_8, dp_4 + +•CCC-v2025.10: CCC.LB.CN06.AR01 + +•SecNumCloud-3.2: 16.2 +

PASShighcloudwatchus-east-2cloudwatch_alarm_actions_enabledCloudWatch metric alarm has actions enabledarn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prodCloudWatch metric alarm scrivas_prod has actions enabled.

With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk.

Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting.

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_8, dp_4 + +•CCC-v2025.10: CCC.LB.CN06.AR01 + +•SecNumCloud-3.2: 16.2 +

FAILmediumcloudwatchus-east-2cloudwatch_changes_to_network_acls_alarm_configuredCloudWatch log metric filter and alarm exist for Network ACL (NACL) change eventsarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Absent monitoring of NACL changes reduces detection of policy tampering, risking loss of confidentiality (opened ingress/egress), degraded network integrity (lateral movement, bypassed segmentation), and reduced availability (traffic blackholes or lockouts).

Implement a CloudWatch Logs metric filter and alarm for NACL change events from CloudTrail and route alerts to responders. Enforce least privilege on NACL management, require change control, and use defense in depth with configuration monitoring and flow logs to validate and monitor network posture.

+•CIS-7.0: 5.11 + +•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.4: 4.11 + +•CIS-1.5: 4.11 + +•MITRE-ATTACK: T1496 + +•ISO27001-2013: A.12.4.D + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•HIPAA: 164_308_a_6_i + +•CIS-2.0: 4.11 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ra_5, cm_1, dp_4 + +•CIS-5.0: 4.11 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 + +•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b + +•CIS-3.0: 4.11 + +•CIS-6.0: 5.11 + +•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 + +•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.12 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-2, ca-7, ir-4 + +•CIS-4.0.1: 4.11 + +•NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 6.4.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_changes_to_network_gateways_alarm_configuredCloudWatch Logs metric filter and alarm exist for changes to network gatewaysarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without this monitoring, gateway changes can expose private networks to the Internet or break connectivity. Adversaries or mistakes can enable data exfiltration, bypass network inspection, and trigger outages via deletions or detachments, impacting confidentiality and availability.

Send CloudTrail to CloudWatch Logs and create a metric filter for the listed gateway events with an alarm that notifies responders. Enforce least privilege for gateway modifications, require change approvals, and route alerts to monitored channels as part of defense in depth.

+•CIS-7.0: 5.12 + +•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.4: 4.12 + +•CIS-1.5: 4.12 + +•MITRE-ATTACK: T1496 + +•ISO27001-2013: A.12.4.C + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B + +•HIPAA: 164_308_a_6_i + +•CIS-2.0: 4.12 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ra_5, ae_2, ae_3, cm_1, dp_4 + +•CIS-5.0: 4.12 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 + +•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b + +•CIS-3.0: 4.12 + +•CIS-6.0: 5.12 + +•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 + +•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.13 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ir-4 + +•CIS-4.0.1: 4.12 + +•NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_changes_to_network_route_tables_alarm_configuredAccount monitors VPC route table changes with a CloudWatch Logs metric filter and alarmarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without monitoring of route table changes, unauthorized or accidental edits can redirect traffic, bypass inspection, or blackhole routes, impacting confidentiality (exfiltration), integrity (tampered paths), and availability (outages from misrouted traffic).

Implement a CloudWatch Logs metric filter and alarm on CloudTrail for these route table events and notify responders. Enforce least privilege for route modifications, require change control, and apply defense in depth with VPC Flow Logs and guardrails to prevent and quickly contain unsafe routing changes.

+•CIS-7.0: 5.13 + +•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.4: 4.13 + +•CIS-1.5: 4.13 + +•MITRE-ATTACK: T1496 + +•ISO27001-2013: A.12.4.B + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, COS-03.02B, PSS-04.01B + +•HIPAA: 164_308_a_6_i + +•CIS-2.0: 4.13 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ae_2, ae_3, cm_1, dp_4 + +•CIS-5.0: 4.13 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 + +•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b + +•CIS-3.0: 4.13 + +•CIS-6.0: 5.13 + +•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 + +•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.14 + +•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ir-4 + +•CIS-4.0.1: 4.13 + +•NIS2: 2.2.3, 3.2.3.a, 3.2.3.f, 3.2.4, 6.4.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_changes_to_vpcs_alarm_configuredAWS account has a CloudWatch Logs metric filter and alarm for VPC changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on VPC changes, unauthorized or accidental edits to routes, peering, or attributes can go unnoticed, exposing private networks and enabling data exfiltration (C), lateral movement and traffic tampering (I), and outages from misrouted or bridged networks (A).

Create a CloudWatch Logs metric filter and alarm on CloudTrail for critical VPC change events, and notify responders. Apply least privilege to network changes, require change approvals, and use defense in depth (segmentation, route controls) to prevent and contain unauthorized modifications.

+•CIS-7.0: 5.14 + +•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.4: 4.14 + +•CIS-1.5: 4.14 + +•MITRE-ATTACK: T1496 + +•ISO27001-2013: A.12.4.A + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B + +•HIPAA: 164_308_a_6_i + +•CIS-2.0: 4.14 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ra_5, ae_2, cm_1 + +•CIS-5.0: 4.14 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4 + +•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b + +•CIS-3.0: 4.14 + +•CIS-6.0: 5.14 + +•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5 + +•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.15 + +•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ir-4 + +•CIS-4.0.1: 4.14 + +•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumcloudwatchus-east-2cloudwatch_cross_account_sharing_disabledCloudWatch does not allow cross-account sharingarn:aws:iam:us-east-2:716468089330:roleCloudWatch doesn't allow cross-account sharing.

Granting other accounts visibility into observability data reduces confidentiality and enables reconnaissance. Adversaries or over-privileged partners can map architectures, profile workloads, and spot alerting gaps, increasing chances of lateral movement and evasion.

Disable cross-account sharing unless strictly required. If needed, restrict access to specific trusted accounts, scope read-only permissions to only necessary resources, and use a dedicated monitoring account. Apply least privilege and separation of duties, and regularly audit role trust and access patterns.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01 + +•ENS-RD2022: op.acc.4.aws.iam.1 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:*Log Group /aws/guardduty/malware-scan-events does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:*Log Group scrivas-gate-prod does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:*Log Group scrivas-backend-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:*Log Group scrivas-search-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:*Log Group scrivas-patient-prod-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:*Log Group vpc_logs does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:*Log Group scrivas-backend-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:*Log Group scrivas-patient-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:*Log Group scrivas-gate-stage does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:*Log Group scrivas-search-stage-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:*Log Group scrivas-gate-dev does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:*Log Group scrivas-patient-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:*Log Group scrivas-search-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:*Log Group ec2-docker-logs does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:*Log Group scrivas-backend-dev-env does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:*Log Group /aws/vpc/flow-logs/us-east-2 does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:*Log Group aws-cloudtrail-logs-716468089330-e5f9b539 does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:*Log Group RDSOSMetrics does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyarn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:*Log Group /aws/eks/scrivas-stage/cluster does not have AWS KMS keys associated.

Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
+- Confidentiality: weaker key-policy barriers against unauthorized reads
+- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance

Associate each log group with a customer-managed KMS key via kmsKeyId.
+- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
+- Enable rotation and monitor key usage
+- Separate keys by app/tenant to support defense in depth and rapid revocation

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_3, pi_1_4 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_5 + +•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16 + +•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9 + +•NIST-800-53-Revision-4: au_9, sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1, 12.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: au-9, sc-28 + +•FedRAMP-Low-Revision-4: au-9 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:*No secrets found in /aws/guardduty/malware-scan-events log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:*Potential secrets found in log group scrivas-gate-prod in log stream gate-api at 2026-06-10T04:40:33.598-04:00 - Postgres URL with hardcoded password on line 1; at 2026-06-10T04:42:34.736-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:*No secrets found in scrivas-backend-prod-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:*No secrets found in scrivas-search-prod-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:*Potential secrets found in log group scrivas-patient-prod-env in log stream patient-api at 2026-05-21T23:52:27.259-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:*No secrets found in vpc_logs log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:*No secrets found in scrivas-backend-stage-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:*Potential secrets found in log group scrivas-patient-stage-env in log stream patient-api at 2026-04-07T16:47:19.389-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:*Potential secrets found in log group scrivas-gate-stage in log stream gate-api at 2026-04-07T13:11:28.464-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:*No secrets found in scrivas-search-stage-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:*Potential secrets found in log group scrivas-gate-dev in log stream gate-api at 2026-03-17T09:06:17.190-04:00 - Postgres URL with hardcoded password on line 1; at 2026-03-17T09:33:01.067-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:*Potential secrets found in log group scrivas-patient-dev-env in log stream patient-api at 2026-03-05T14:20:05.593-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:*No secrets found in scrivas-search-dev-env log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:*No secrets found in ec2-docker-logs log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:*Potential secrets found in log group scrivas-backend-dev-env in log stream encounter-api at 2026-02-24T08:31:46.315-04:00 - Postgres URL with hardcoded password on line 1.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:*No secrets found in /aws/vpc/flow-logs/us-east-2 log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:*No secrets found in aws-cloudtrail-logs-716468089330-e5f9b539 log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:*No secrets found in RDSOSMetrics log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsarn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:*No secrets found in /aws/eks/scrivas-stage/cluster log group.

Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius.

Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:*Log Group /aws/guardduty/malware-scan-events is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:*Log Group scrivas-gate-prod is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:*Log Group scrivas-backend-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:*Log Group scrivas-search-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:*Log Group scrivas-patient-prod-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:*Log Group vpc_logs is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:*Log Group scrivas-backend-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:*Log Group scrivas-patient-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:*Log Group scrivas-gate-stage is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:*Log Group scrivas-search-stage-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:*Log Group scrivas-gate-dev is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:*Log Group scrivas-patient-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:*Log Group scrivas-search-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:*Log Group ec2-docker-logs is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:*Log Group scrivas-backend-dev-env is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:*Log Group /aws/vpc/flow-logs/us-east-2 is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:*Log Group aws-cloudtrail-logs-716468089330-e5f9b539 is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:*Log Group RDSOSMetrics is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

PASShighcloudwatchus-east-2cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessiblearn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:*Log Group /aws/eks/scrivas-stage/cluster is not publicly accessible.

Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence.

Remove public access from log group resource policies. Replace Principal:&#34;*&#34; and Resource:&#34;*&#34; with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews.

+•SOC2: pi_1_4 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01 + +•SecNumCloud-3.2: 12.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•NIS2: 3.2.3.c +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:*Log Group /aws/guardduty/malware-scan-events has less than 365 days retention period (90 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:*Log Group scrivas-gate-prod comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:*Log Group scrivas-backend-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:*Log Group scrivas-search-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:*Log Group scrivas-patient-prod-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:*Log Group vpc_logs has less than 365 days retention period (30 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:*Log Group scrivas-backend-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:*Log Group scrivas-patient-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:*Log Group scrivas-gate-stage comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:*Log Group scrivas-search-stage-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:*Log Group scrivas-gate-dev comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:*Log Group scrivas-patient-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:*Log Group scrivas-search-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:*Log Group ec2-docker-logs comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:*Log Group scrivas-backend-dev-env comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:*Log Group /aws/vpc/flow-logs/us-east-2 comply with 365 days retention period since it has 365 days.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:*Log Group aws-cloudtrail-logs-716468089330-e5f9b539 comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

FAILmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:*Log Group RDSOSMetrics has less than 365 days retention period (30 days).

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

PASSmediumcloudwatchus-east-2cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresarn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:*Log Group /aws/eks/scrivas-stage/cluster comply with 365 days retention period since it never expires.

Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines.

Define a minimum retention baseline (e.g., &gt;=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth.

+•SOC2: cc_7_2, cc_7_3, cc_c_1_2 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B + +•HIPAA: 164_312_b + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2 + +•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11 + +•NIST-800-53-Revision-4: au_11, si_12 + +•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12 + +•ENS-RD2022: op.exp.8.r3.aws.cw.1 + +•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1 + +•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c + +•ProwlerThreatScore-1.0: 3.2.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12 + +•FedRAMP-Low-Revision-4: au-11 + +•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07 +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabledCloudWatch Logs metric filter and alarm exist for AWS Config configuration changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on AWS Config changes, actions like StopConfigurationRecorder or DeleteDeliveryChannel can silently suspend recording and delivery.
+
+This degrades the integrity and availability of configuration audit data, enabling undetected changes and delaying incident response.

Create a CloudWatch Logs metric filter and alarm for config.amazonaws.com events (StopConfigurationRecorder, DeleteDeliveryChannel, PutDeliveryChannel, PutConfigurationRecorder). Route CloudTrail to Logs, notify responders, and enforce least privilege and separation of duties on Config changes to prevent abuse.

+•CIS-7.0: 5.9 + +•SOC2: cc_5_2 + +•CIS-1.4: 4.9 + +•CIS-1.5: 4.9 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.F + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•CIS-2.0: 4.9 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_7, dp_4 + +•CIS-5.0: 4.9 + +•CIS-3.0: 4.9 + +•CIS-6.0: 5.9 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.10 + +•ISO27001-2022: A.8.15, A.8.16 + +•CIS-4.0.1: 4.9 + +•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabledCloudWatch Logs metric filter and alarm exist for CloudTrail configuration changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Absent this monitoring, logging can be stopped or altered without notice, eroding visibility.
+
+That enables covert activity and data exfiltration without audit evidence, harming confidentiality, the integrity of records, and the availability of reliable logs for detection and forensics.

Implement a metric filter for trail configuration events and a linked alarm that notifies response channels.
+
+Apply least privilege and separation of duties for trail changes, add defense in depth with centralized logging and validation, and regularly test that alerts fire.

+•CISA: your-data-2 + +•CIS-7.0: 5.5 + +•SOC2: cc_5_2 + +•CIS-1.4: 4.5 + +•CIS-1.5: 4.5 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.J + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, SIM-03.07B, COM-04.01AC, PSS-04.01B + +•CIS-2.0: 4.5 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_3, cm_7, dp_4 + +•CIS-5.0: 4.5 + +•AWS-Account-Security-Onboarding: Critical alert on cloudtrail settings changes + +•CIS-3.0: 4.5 + +•ENS-RD2022: op.exp.8.aws.ct.2, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3 + +•CIS-6.0: 5.5 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR01, CCC.Logging.CN07.AR01, CCC.LB.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.6 + +•ISO27001-2022: A.8.15, A.8.16 + +•CIS-4.0.1: 4.5 + +•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.2.4, 3.5.4, 7.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_authentication_failuresAccount has a CloudWatch Logs metric filter and alarm for AWS Management Console authentication failuresarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Absent visibility into failed console logins enables undetected brute-force and credential-stuffing attempts, extending attacker dwell time.
+
+Successful guesses can grant console access, risking data confidentiality, configuration integrity, and availability through destructive changes.

Implement a log metric filter for ConsoleLogin failures and attach a CloudWatch alarm with actionable notifications. Tune thresholds to reduce noise and route alerts to incident response.
+
+Apply least privilege and enforce MFA to limit impact, and correlate alerts with source IP and user context.

+•CIS-7.0: 5.6 + +•SOC2: pi_1_3 + +•CIS-1.4: 4.6 + +•CIS-1.5: 4.6 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.I + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, PSS-04.01B + +•HIPAA: 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii + +•CIS-2.0: 4.6 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ra_5, ip_7, ip_8, pt_1, ae_2, cm_1, cm_3, cm_7, dp_4 + +•CIS-5.0: 4.6 + +•AWS-Account-Security-Onboarding: Alert on rise of ConsoleLoginFailures events + +•CIS-3.0: 4.6 + +•ENS-RD2022: op.exp.8.aws.ct.5 + +•CIS-6.0: 5.6 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.7 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.6 + +•NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 7.2.b +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_aws_organizations_changesCloudWatch Logs metric filter and alarm exist for AWS Organizations changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on AWS Organizations changes, attackers or misconfigurations can silently alter governance, enabling unauthorized access and policy bypass. They could create/remove accounts, change or detach SCPs, or delete the organization, risking data exposure (C), privilege escalation (I), and service disruption (A).

Send CloudTrail events to CloudWatch Logs, add a metric filter for organizations.amazonaws.com change events, and attach an alarm that notifies responders. Enforce least privilege and separation of duties for org admins, require MFA and approvals, and regularly test alerts to ensure timely detection and response.

+•CIS-7.0: 5.15 + +•SOC2: cc_5_2 + +•CIS-1.4: 4.15 + +•CIS-1.5: 4.15 + +•MITRE-ATTACK: T1496 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•CIS-2.0: 4.15 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ae_3, cm_7 + +•CIS-5.0: 4.15 + +•CIS-3.0: 4.15 + +•CIS-6.0: 5.15 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.16 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.15 + +•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmkAccount has a CloudWatch log metric filter and alarm for disabling or scheduled deletion of customer-managed KMS keysarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Missing alerts on CMK disablement or scheduled deletion undermines availability and integrity: encrypted data may become undecryptable, backups unusable, and recovery impossible. Attackers or insiders can change key states unnoticed, causing outages and irreversible data loss.

Establish CloudWatch metric filters and alarms for DisableKey and ScheduleKeyDeletion CloudTrail events to enable rapid response.
+- Apply least privilege to KMS administration
+- Enforce change control and separation of duties
+- Use deletion waiting periods and monitor all regions

+•CIS-7.0: 5.7 + +•CIS-1.4: 4.7 + +•CIS-1.5: 4.7 + +•MITRE-ATTACK: T1485, T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.10.1.C, A.12.4.H + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.02AC, OIS-08.02B, HR-03.02AC, AM-01.01AC, AM-07.02B, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, CRY-05.02B, PSS-04.01B + +•CIS-2.0: 4.7 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ae_2, cm_7 + +•CIS-5.0: 4.7 + +•CIS-3.0: 4.7 + +•ENS-RD2022: op.exp.10.aws.cmk.4, op.exp.10.aws.cmk.5 + +•CIS-6.0: 5.7 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.KeyMgmt.CN01.AR01 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.8 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.7 + +•NIS2: 3.2.3.c, 3.2.3.g, 3.5.4, 7.2.b +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_for_s3_bucket_policy_changesCloudWatch log metric filter and alarm exist for S3 bucket policy changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on S3 policy and ACL changes, unauthorized modifications can go unnoticed, weakening confidentiality and integrity. Misuse could expose buckets publicly, grant write/delete access, or alter replication paths, enabling data exfiltration and destructive actions.

Establish and maintain metric filters and alarms for S3 bucket policy, ACL, CORS, lifecycle, and replication changes. Route alerts to monitored channels and integrate with SIEM. Enforce least privilege, require change reviews, and use defense in depth to prevent and quickly detect unsafe bucket policy changes.

+•CIS-7.0: 5.8 + +•SOC2: cc_5_2 + +•CIS-1.4: 4.8 + +•CIS-1.5: 4.8 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.G + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•CIS-2.0: 4.8 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: pt_1, ae_1, ae_2, cm_7 + +•CIS-5.0: 4.8 + +•CIS-3.0: 4.8 + +•CIS-6.0: 5.8 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR02 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.9 + +•ISO27001-2022: A.8.15, A.8.16 + +•CIS-4.0.1: 4.8 + +•NIS2: 2.2.3, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_policy_changesCloudWatch Logs metric filter and alarm exist for IAM policy changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Absent alerting on IAM policy changes, privilege modifications can go unnoticed, enabling privilege escalation, hidden backdoors, or permission revocations. This threatens confidentiality and integrity, and may impact availability if critical access is removed or misconfigured.

Create a metric filter for IAM policy create/update/delete and attach/detach events with an alarm to notify responders.
+- Enforce least privilege and separation of duties for policy changes
+- Require approvals and central logging across Regions/accounts
+- Integrate alerts with incident response

+•CIS-7.0: 5.4 + +•SOC2: cc_5_2, pi_1_3 + +•CIS-1.4: 4.4 + +•CIS-1.5: 4.4 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.K + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•CIS-2.0: 4.4 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_3, ae_2, cm_7 + +•CIS-5.0: 4.4 + +•CIS-3.0: 4.4 + +•ENS-RD2022: op.exp.8.aws.ct.5 + +•CIS-6.0: 5.4 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•PCI-3.2.1: 8.1, 8.1.2 + +•ProwlerThreatScore-1.0: 3.3.5 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.4 + +•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_root_usageAccount has a CloudWatch Logs metric filter and alarm for root account usagearn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on root activity, full-privilege actions can proceed unnoticed, impacting:
+- confidentiality via data access/exfiltration
+- integrity via policy/config tampering
+- availability via deletions or shutdowns
+Delayed detection increases blast radius and persistence.

Enable real-time alerts for root activity using a log metric filter and a high-priority alarm with notifications.
+
+Reduce exposure: enforce least privilege, keep root for break-glass with MFA, disable root access keys, and route alerts into incident response for defense in depth.

+•CIS-7.0: 5.3 + +•SOC2: pi_1_3 + +•CIS-1.4: 4.3 + +•CIS-1.5: 4.3 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.L + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01B, IAM-03.03B, IAM-06.04B, IAM-06.05B, PSS-04.01B + +•HIPAA: 164_308_a_6_i, 164_308_a_6_ii + +•CIS-2.0: 4.3 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ip_8, ae_2, cm_7, dp_4 + +•CIS-5.0: 4.3 + +•AWS-Account-Security-Onboarding: Critical alert on every root user activity + +•CIS-3.0: 4.3 + +•ENS-RD2022: op.exp.8.aws.ct.5, op.exp.8.aws.cw.1 + +•CIS-6.0: 5.3 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01 + +•SecNumCloud-3.2: 12.9 + +•PCI-3.2.1: 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 3.3.4 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-04, AISF-DETECT-05 + +•CIS-4.0.1: 4.3 + +•NIS2: 2.3.1, 3.2.1, 3.2.2, 3.2.3.c, 3.2.3.e, 3.2.3.g, 3.5.4, 7.2.b, 9.2.c.vii +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_security_group_changesCloudWatch Logs metric filter and alarm exist for security group changesarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on security group changes, unauthorized or mistaken rules can expose services to the Internet, enabling brute force and lateral movement (confidentiality, integrity). Deletions or restrictive edits can break connectivity (availability). Delayed detection increases attacker dwell time and impact.

Establish real-time alerts for security group modifications by sending CloudTrail to CloudWatch, creating metric filters and alarms, and notifying responders.
+- Enforce least privilege on SG changes
+- Use change management and tagging
+- Centralize logs, test alarms, and maintain runbooks
+- Layer with NACLs and WAF for defense in depth

+•CIS-7.0: 5.10 + +•SOC2: cc_5_2 + +•CIS-1.4: 4.10 + +•CIS-1.5: 4.10 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.E + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B + +•CIS-2.0: 4.10 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_3, ip_8, ae_1, ae_2, cm_7, dp_4 + +•CIS-5.0: 4.10 + +•CIS-3.0: 4.10 + +•CIS-6.0: 5.10 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.11 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.10 + +•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 11.5.2.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_sign_in_without_mfaCloudWatch log metric filter and alarm exist for Management Console sign-in without MFAarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on non-MFA console logins, successful use of stolen passwords can go undetected, enabling:
+- Unauthorized console access and IAM changes
+- Data exfiltration or deletion
+
+Impacts: loss of confidentiality and integrity, and potential availability disruption.

Enforce MFA for all console-capable identities and maintain alerts for ConsoleLogin with MFAUsed != \&#34;Yes\&#34;.
+
+Apply least privilege, route alarms to monitored channels, and tune for SSO to reduce noise. Test alarms regularly and review coverage as part of defense in depth.

+•CIS-7.0: 5.2 + +•CIS-1.4: 4.2 + +•CIS-1.5: 4.2 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.M + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-16.01B, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, IAM-09.02B, IAM-09.01AC, PSS-04.01B, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 4.2 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•CIS-5.0: 4.2 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•CIS-3.0: 4.2 + +•ENS-RD2022: op.exp.8.aws.ct.5 + +•CIS-6.0: 5.2 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.3 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.2 + +•NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 9.2.c.vii, 11.7.2 +

FAILmediumcloudwatchus-east-2cloudwatch_log_metric_filter_unauthorized_api_callsCloudWatch Logs metric filter and alarm exist for unauthorized API callsarn:aws:logs:us-east-2:716468089330:log-groupNo CloudWatch log groups found with metric filters or alarms associated.

Without alerting on unauthorized API calls, permission probing and failed access by compromised identities can go unnoticed. Attackers can enumerate services, pivot, and attempt privilege escalation, threatening data confidentiality and integrity.

Enable real-time alerting by adding a CloudWatch Logs metric filter for unauthorized errors (*UnauthorizedOperation, AccessDenied*) and associating it with an alarm that notifies responders.
+- Enforce least privilege to reduce noise
+- Integrate with IR tooling for defense in depth

+•CIS-7.0: 5.1 + +•SOC2: pi_1_3 + +•CIS-1.4: 4.1 + +•CIS-1.5: 4.1 + +•MITRE-ATTACK: T1496 + +•GDPR: article_25 + +•ISO27001-2013: A.12.4.N + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-06.05B, PSS-04.01B + +•CIS-2.0: 4.1 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_3, ra_5, ip_7, ip_8, pt_1, ae_1, ae_2, cm_1, cm_3, cm_7, dp_4 + +•CIS-5.0: 4.1 + +•CIS-3.0: 4.1 + +•ENS-RD2022: op.exp.8.aws.ct.5 + +•CIS-6.0: 5.1 + +•NIST-CSF-1.1: cm_2, ra_5, sc_4 + +•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02 + +•SecNumCloud-3.2: 12.9 + +•ProwlerThreatScore-1.0: 3.3.2 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-05 + +•CIS-4.0.1: 4.1 + +•NIS2: 3.2.3.c, 3.2.3.g, 3.2.4, 3.4.2.c, 3.5.4 +

FAILhighconfigus-east-2config_delegated_admin_and_org_aggregator_all_regionsAWS Config has a delegated administrator and an organization aggregator covering all AWS regionsarn:aws:config:us-east-2:716468089330:config-aggregator/unknownAWS Config has no Organization Aggregator configured in any region (no delegated administrator registered for config.amazonaws.com).

Without an org-wide AWS Config aggregator and a delegated administrator, configuration data is fragmented across accounts and regions, compliance reporting is incomplete, and drift detection is delayed. Adversaries or misconfigurations can persist in unmonitored accounts, eroding audit readiness and regulatory posture.

Register a delegated administrator for AWS Config via AWS Organizations and create at least one Configuration Aggregator with an OrganizationAggregationSource that covers all AWS regions. This centralizes configuration data across the organization for unified compliance and audit reporting.

PASSmediumconfigus-east-2config_recorder_all_regions_enabledAWS Config recorder is enabled and not in failure state or disabledarn:aws:config:us-east-2:716468089330:recorderAWS Config recorder default is enabled.

Gaps in Config recording create blind spots. Changes in unmonitored Regions aren't captured, weakening integrity and auditability. Adversaries can alter resources or stage assets unnoticed, enabling misconfigurations and delaying incident response.

Enable AWS Config in every Region with continuous recording and maintain healthy recorder status.

+•CIS-7.0: 4.3 + +•SOC2: cc_2_1, cc_3_1, cc_3_4, cc_8_1, pi_1_3 + +•CIS-1.4: 3.5 + +•CIS-1.5: 3.5 + +•MITRE-ATTACK: T1190, T1078, T1204, T1098, T1136, T1525, T1562, T1110, T1040, T1119, T1530, T1485, T1486, T1491, T1499, T1496, T1498 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: Config.1 + +•ISO27001-2013: A.12.4.P + +•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OIS-05.01B, PS-02.01B, PS-02.01AS, PS-02.02AS, DEV-08.02B + +•HIPAA: 164_308_a_1_ii_a + +•CIS-2.0: 3.5 + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02 + +•GxP-EU-Annex-11: 10-change-and-configuration-management, 4.5-validation-development-quality, 4.6-validation-quality-performance + +•NIST-CSF-2.0: rm_1, po_3, po_4, ov_3, pt_1 + +•CIS-5.0: 3.3 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1 + +•AWS-Account-Security-Onboarding: Enable continuous recording for most of the resources, Confirm that records are present in central aggregator + +•CIS-3.0: 3.3 + +•ENS-RD2022: op.exp.1.aws.cfg.1, op.exp.1.aws.cfg.2, op.exp.3.aws.cfg.1, op.exp.3.r3.aws.cfg.1, op.mon.3.r2.aws.cfg.1, op.mon.3.r6.aws.cfg.1 + +•CIS-6.0: 4.3 + +•NIST-CSF-1.1: cm_2, am_1, ra_5, sc_4, ip_12 + +•CCC-v2025.10: CCC.Core.CN04.AR01 + +•SecNumCloud-3.2: 8.1, 12.2, 13.1, 14.2, 17.5, 18.3 + +•PCI-3.2.1: 2.4, 2.4.a, 10.5, 10.5.2, 11.5, 11.5.a, 11.5.b + +•ProwlerThreatScore-1.0: 3.3.1 + +•ISO27001-2022: A.5.16, A.5.22 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-01 + +•CIS-4.0.1: 3.3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy, ksi-mla-07 +

PASSmediumconfigus-east-2config_recorder_using_aws_service_roleAWS Config recorder uses the AWSServiceRoleForConfig service-linked rolearn:aws:config:us-east-2:716468089330:recorderAWS Config recorder default is using AWSServiceRoleForConfig.

Using a custom or incorrect role can break recording or create blind spots, undermining the integrity and availability of configuration history. Over‑privileged roles weaken least privilege, increasing risk of unauthorized access, stealthy changes, and delayed incident response.

Use the AWS‑managed service‑linked role AWSServiceRoleForConfig for all recorders to enforce least privilege and consistent trust.
+
+Avoid custom roles; restrict who can modify the recorder or role; monitor for drift and ensure recording remains enabled as part of defense in depth.

+•KISA-ISMS-P-2023: 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, DEV-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rm_1, po_4, ov_3, pt_1 + +•SecNumCloud-3.2: 13.1 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-01 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-piy +

FAILmediumdrsus-east-1drs_job_existRegion has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery jobarn:aws:drs:us-east-1:716468089330:recovery-jobDRS is not enabled for this region.

Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
+During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime.

Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery.

+•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490 + +•KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2 + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2 + +•NIST-CSF-2.0: be_5, ip_9 + +•ENS-RD2022: op.cont.3.aws.drs.1 +

FAILmediumdrsus-east-2drs_job_existRegion has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery jobarn:aws:drs:us-east-2:716468089330:recovery-jobDRS is not enabled for this region.

Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
+During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime.

Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery.

+•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490 + +•KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2 + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2 + +•NIST-CSF-2.0: be_5, ip_9 + +•ENS-RD2022: op.cont.3.aws.drs.1 +

PASSmediumdynamodbus-east-2dynamodb_table_autoscaling_enabledDynamoDB table uses on-demand capacity or has auto scaling enabled for read and write capacity unitsarn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock +•ManagedBy=terraform + +•Purpose=terraform-backend-lock +DynamoDB table terraform-lock automatically scales capacity on demand.

Insufficient capacity scaling causes throttling that degrades availability and increases latency.
+
+Sustained throttling can trigger retry storms, timeouts, and backlogs, risking missed writes or out-of-order processing that impacts data integrity and drives operational costs.

Adopt elastic capacity: prefer on-demand for unpredictable traffic, or use PROVISIONED with auto scaling on both reads and writes.
+
+Define safe utilization targets and bounds, monitor consumption, and plan for bursts to maintain availability and resilience over manual fixed throughput.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: ds_4 +

FAILmediumdynamodbus-east-2dynamodb_table_deletion_protection_enabledDynamoDB table has deletion protection enabledarn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock +•ManagedBy=terraform + +•Purpose=terraform-backend-lock +DynamoDB table terraform-lock does not have deletion protection enabled.

Without deletion protection, tables can be removed by authorized actions or misconfigured automation, causing irrecoverable data loss and service outage. This impacts integrity and availability, and increases the blast radius of compromised credentials or mistaken runbooks.

Enable deletion protection on critical tables.
+- Enforce least privilege to restrict who can modify this setting
+- Require change control to disable it before planned deletes
+- Combine with PITR and backups for defense in depth
+- Use automation to make this the default for new tables

+•AWS-Foundational-Security-Best-Practices: DynamoDB.6, DynamoDB.7 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: AM-07.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: ds_3, ds_4, pt_5 + +•SecNumCloud-3.2: 17.4 +

FAILmediumdynamodbus-east-2dynamodb_table_protected_by_backup_planDynamoDB table is protected by a backup planarn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock +•ManagedBy=terraform + +•Purpose=terraform-backend-lock +DynamoDB table terraform-lock is not protected by a backup plan.

Without a backup plan, table data lacks governed copies, harming availability and integrity. Accidental deletes, corrupt writes, or malicious actions can become unrecoverable, and RPO/RTO worsen. You also forfeit cross-Region/account copies and immutability features, increasing downtime and data loss.

Place all critical tables under an AWS Backup backup plan following defense in depth and least privilege:
+- Use tag-based assignments for coverage at scale
+- Define schedules, retention, and cross-Region/account copies
+- Enable Vault Lock for immutability
+- Regularly test restores and restrict backup deletion

+•AWS-Foundational-Security-Best-Practices: DynamoDB.4 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: be_5, ds_4, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.9, 10.3.3.11 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR02 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 4.1.4, 12.1.2.c, 12.2.2.b +

PASSmediumdynamodbus-east-2dynamodb_tables_kms_cmk_encryption_enabledDynamoDB table is encrypted at rest with AWS KMSarn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock +•ManagedBy=terraform + +•Purpose=terraform-backend-lock +DynamoDB table terraform-lock has KMS encryption enabled with key ec1c4624-868a-4759-a6cb-78a0853bd17f.

Relying on the default service-owned key reduces control over confidentiality: no custom key policies, limited auditability, and no independent rotation or disablement. This weakens least-privilege enforcement and incident response, and can impede meeting mandates that require customer-controlled keys.

Encrypt tables with KMS keys in your account-prefer customer-managed keys for sensitive data. +

    +
  • Enforce least-privilege key policies and scope grants
  • +
  • Enable rotation and monitor key usage
  • +
  • Separate duties for key admins vs data users
  • +
  • Restrict which principals can use the key for DynamoDB
  • +

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•MITRE-ATTACK: T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, IAM-09.03B, IAM-09.02AC, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1 + +•NIST-800-171-Revision-2: 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.11, 3.5.1.12, 8.3.2.18, 8.3.2.19 + +•NIST-800-53-Revision-4: sc_13 + +•NIST-800-53-Revision-5: au_9_3, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.dydb.1 + +•AWS-Foundational-Technical-Review: SDAT-002 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.5, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 +

FAILmediumdynamodbus-east-2dynamodb_tables_pitr_enabledDynamoDB table has point-in-time recovery (PITR) enabledarn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock +•ManagedBy=terraform + +•Purpose=terraform-backend-lock +DynamoDB table terraform-lock does not have point-in-time recovery enabled.

Without PITR, unintended or malicious writes/deletes cannot be precisely rolled back, leading to permanent data loss and corrupted state. Failures from buggy deployments, compromised credentials, or faulty batch jobs reduce data integrity and availability, and prolong incident recovery and forensic analysis.

Enable PITR on critical tables and set a recovery window aligned to your RPO (1-35 days). Enforce least privilege on who can modify backup settings. Regularly test restores and monitor backup status. Embed PITR in IaC and change control for consistency, and apply defense in depth with on-demand backups for key milestones.

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: DynamoDB.2 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_13_2 + +•ASD-Essential-Eight-Nov 2023: E8-8.1, E8-8.2 + +•PCI-4.0: 10.3.3.10, 10.5.1.6, 3.2.1.5, 3.3.1.1.5, 3.3.1.3.5, 3.3.2.5, 3.3.3.5 + +•NIST-800-53-Revision-4: cp_9, cp_10, si_12 + +•NIST-800-53-Revision-5: cp_1_2, cp_2_5, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, sc_5_2, si_13_5 + +•NIST-CSF-1.1: ip_4, ip_9, rp_1, rp_1 + +•AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03 + +•SecNumCloud-3.2: 12.5 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c + +•FedRamp-Moderate-Revision-4: cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: cp-9, cp-10, sc-5 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna, ksi-rpl +

PASSmediumec2us-east-1ec2_ami_account_block_public_accessAMI block public access is enabled at the account levelarn:aws:ec2:us-east-2:716468089330:accountAMI Block Public Access is enabled in us-east-1.

Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors.

Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly.

PASSmediumec2us-east-2ec2_ami_account_block_public_accessAMI block public access is enabled at the account levelarn:aws:ec2:us-east-2:716468089330:accountAMI Block Public Access is enabled in us-east-2.

Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors.

Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly.

PASShighec2us-east-2ec2_ebs_default_encryptionEBS default encryption is enabledarn:aws:ec2:us-east-2:716468089330:volumeEBS Default Encryption is activated.

Without encryption by default, data on new EBS volumes and snapshots may be stored in plaintext. A compromised account or mis-shared snapshot can expose disk contents, enabling data exfiltration, offline analysis, and loss of confidentiality.

Enable EBS encryption by default in every region and select a customer-managed KMS key. Apply least privilege to key use, rotate keys, and monitor access. Enforce encrypted volume creation with organizational guardrails and secure templates as defense in depth.

+•CISA: your-systems-3, your-data-1 + +•CIS-7.0: 6.1.1 + +•MITRE-ATTACK: T1119 + +•AWS-Foundational-Security-Best-Practices: EC2.7 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93EBS Snapshot vol-07bd5c93cb1ce9a93 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844cEBS Snapshot vol-049bd3b9fbf52844c is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189EBS Snapshot vol-00abcebca9a065189 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554EBS Snapshot vol-0fc1a9c187da02554 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283aEBS Snapshot vol-0655f47f37fd9283a is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386cEBS Snapshot vol-06fd9a9b51f0c386c is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06EBS Snapshot vol-0ca0556d08ef42c06 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3bEBS Snapshot vol-03f685457f48aef3b is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

PASShighec2us-east-2ec2_ebs_volume_encryptionEBS volume is encryptedarn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850EBS Snapshot vol-096ef60e2b2bc8850 is encrypted.

Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
+
+Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement.

Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
+
+Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_5 + +•CIS-1.4: 2.2.1 + +•CIS-1.5: 2.2.1 + +•MITRE-ATTACK: T1119 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: EC2.3 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•CIS-2.0: 2.2.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-g, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•CIS-5.0: 5.1.1 + +•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.20, 8.3.2.34 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4 + +•CIS-3.0: 2.2.1 + +•ENS-RD2022: mp.si.2.aws.kms.1 + +•CIS-6.0: 6.1.1 + +•NIST-CSF-1.1: ds_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ProwlerThreatScore-1.0: 4.2.1 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-28 + +•CIS-4.0.1: 5.1.1 +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93EBS Volume vol-07bd5c93cb1ce9a93 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844cEBS Volume vol-049bd3b9fbf52844c is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189EBS Volume vol-00abcebca9a065189 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554EBS Volume vol-0fc1a9c187da02554 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283aEBS Volume vol-0655f47f37fd9283a is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386cEBS Volume vol-06fd9a9b51f0c386c is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06EBS Volume vol-0ca0556d08ef42c06 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3bEBS Volume vol-03f685457f48aef3b is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILmediumec2us-east-2ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planarn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850EBS Volume vol-096ef60e2b2bc8850 is not protected by a backup plan.

Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response.

Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity.

+•AWS-Foundational-Security-Best-Practices: EC2.28 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 3.1, 3.1.c + +•ISO27001-2022: A.8.14 + +•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93Snapshots not found for the EBS volume vol-07bd5c93cb1ce9a93.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844cSnapshots not found for the EBS volume vol-049bd3b9fbf52844c.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189Snapshots not found for the EBS volume vol-00abcebca9a065189.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554Snapshots not found for the EBS volume vol-0fc1a9c187da02554.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283aSnapshots not found for the EBS volume vol-0655f47f37fd9283a.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386cSnapshots not found for the EBS volume vol-06fd9a9b51f0c386c.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06Snapshots not found for the EBS volume vol-0ca0556d08ef42c06.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3bSnapshots not found for the EBS volume vol-03f685457f48aef3b.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

FAILhighec2us-east-2ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotarn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850Snapshots not found for the EBS volume vol-096ef60e2b2bc8850.

Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics.

Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
+- Schedule regular snapshots with retention controls
+- Encrypt snapshots and enforce least privilege access
+- Replicate to another Region/account for DR
+- Periodically test restores and document procedures

+•SOC2: cc_7_5 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•ASD-Essential-Eight-Nov 2023: E8-8.1 + +•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2 + +•SecNumCloud-3.2: 12.5 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-008ec7fbfb6122115 +•Name=ML_dev +Elastic IP 16.58.108.209 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0f1b179c7dbcd4a49 +•Name=Netbird_elasticip +Elastic IP 16.59.189.218 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b3287d784d49d661 +•Name=Scrivas_stage_env +Elastic IP 18.118.91.126 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b8681b277d57fe92 +•Name=scrivas-dev-env +Elastic IP 3.14.230.56 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-096b94ac565c27327 +•Name=Ml_prod_ip +Elastic IP 3.147.5.202 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-02269883e142e58a1 +•Name=scrivas_prod_env +Elastic IP 3.150.90.196 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfacearn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0dfd7e61faef43c26 +•Name=ML_stage +Elastic IP 52.14.227.224 is associated with an instance or network interface.

Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned.

Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies.

+•CISA: your-systems-1, your-surroundings-1 + +•AWS-Foundational-Security-Best-Practices: EC2.12 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_4_1 + +•NIST-CSF-1.1: ds_3 + +•FFIEC: d1-g-it-b-1 + +•PCI-3.2.1: 2.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_account_imdsv2_enabledIMDSv2 is required by default for EC2 instances at the account levelarn:aws:ec2:us-east-2:716468089330:accountIMDSv2 is not enabled by default for EC2 instances.

Without a default of IMDSv2, new instances may enable IMDSv1, exposing metadata via simple HTTP. SSRF or proxy misconfigs can steal temporary IAM credentials, enabling data exfiltration (confidentiality), unauthorized API changes (integrity), and lateral movement that can disrupt services (availability).

Enforce IMDSv2 at the account level in every Region by setting http_tokens to required. Add guardrails with SCP/IAM conditions. Standardize AMIs and launch templates to require tokens, validate workload compatibility, and apply least privilege to instance roles for defense in depth. For containers, prefer hop limit 2.

+•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•C5-2025: OPS-25.01B + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.i +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

FAILlowec2us-east-2ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 does not have detailed monitoring enabled.

Without 1-minute metrics, visibility drops, delaying detection of:
+- Sudden CPU/network/disk spikes affecting availability
+- Malicious workloads (crypto-mining, brute force)
+- Data exfiltration patterns
+Slower detection expands blast radius, raising incident impact and response cost.

Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7 + +•NIS2: 3.2.3.h +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 has IMDSv2 enabled and required.

Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources.

Apply defense in depth:
+- Require IMDSv2 tokens on all instances (http_tokens: required)
+- Disable metadata where not needed (http_endpoint: disabled)
+- Minimize hop limit to 1 when feasible
+- Update SDKs/apps for IMDSv2
+- Restrict instance profile permissions (least privilege)
+- Block metadata access from untrusted workloads

+•CIS-7.0: 6.7 + +•SOC2: cc_7_2 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: EC2.8 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•CIS-2.0: 5.6 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.7 + +•NIST-800-171-Revision-2: 3_12_4 + +•PCI-4.0: 8.2.8.4 + +•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3 + +•CIS-3.0: 5.6 + +•CIS-6.0: 6.7 + +•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4 + +•ProwlerThreatScore-1.0: 4.1.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-3, ca-7 + +•CIS-4.0.1: 5.7 + +•NIS2: 6.7.2.i + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b at IP 16.58.108.209 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db is not internet facing with an instance profile.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e at IP 3.14.230.56 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 at IP 52.14.227.224 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb at IP 18.118.91.126 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd at IP 3.150.90.196 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighec2us-east-2ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 at IP 3.147.5.202 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability.

Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•ENS-RD2022: mp.com.4.aws.vpc.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 is managed by Systems Manager.

Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability.

Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth.

+•CISA: your-systems-1 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.1 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2 + +•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3 + +•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12 + +•SecNumCloud-3.2: 8.1, 12.10, 12.12 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•FFIEC: d1-g-it-b-1, d3-pc-im-b-5 + +•ISO27001-2022: A.5.26 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-8, sa-3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b is not older than 180 days (100 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db is not older than 180 days (159 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e is not older than 180 days (154 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 is not older than 180 days (97 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb is not older than 180 days (145 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd is not older than 180 days (91 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 is not older than 180 days (91 days).

Long-lived instances often run unpatched OS and agents, enabling:
+- Exploitation of known CVEs loss of confidentiality
+- Privilege escalation and tampering integrity compromise
+- Malware/crypto-mining and instability reduced availability
+
+Aged hosts also drift from baselines and impede response.

Adopt short-lived, patched workloads:
+- Rebuild regularly from hardened, updated images; rotate AMIs
+- Use centralized patch management and vulnerability scanning
+- Retire or modernize legacy hosts; tag for lifecycle
+- Apply least privilege and defense in depth to limit blast radius
+
+Adjust max_ec2_instance_age_in_days to match policy.

+•CISA: your-systems-1 + +•AWS-Foundational-Security-Best-Practices: EC2.4 + +•KISA-ISMS-P-2023: 2.9.2 + +•HIPAA: 164_308_a_1_ii_b + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•GxP-21-CFR-Part-11: 11.10-a + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2 + +•ASD-Essential-Eight-Nov 2023: E8-2.8 + +•NIST-800-53-Revision-4: cm_2 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6 + +•NIST-CSF-1.1: ds_7, ip_1 + +•FFIEC: d1-g-it-b-1 + +•ISO27001-2022: A.8.10 + +•FedRamp-Moderate-Revision-4: cm-2 + +•FedRAMP-Low-Revision-4: cm-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 virtualization type is set to HVM.

Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts.

Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions.

+•AWS-Foundational-Security-Best-Practices: EC2.24 + +•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internetarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Cassandra ports open to the Internet.

Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
+
+Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC.

Apply least privilege network access:
+- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
+- Allow only trusted subnets or VPN/bastion
+- Keep nodes in private subnets; segment inter-node traffic
+- Enforce authentication and TLS/mTLS for clients and JMX
+- Add defense in depth with NACLs and monitoring

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have CIFS ports open to the Internet.

Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability.

Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
+
+Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing.

+•CIS-7.0: 6.1.2 + +•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•CIS-5.0: 5.1.2 + +•CIS-6.0: 6.1.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.1.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Elasticsearch/Kibana ports open to the Internet.

Public access to Elasticsearch/Kibana can lead to:
+- Unauthorized queries or dashboard viewing confidentiality loss
+- Index changes or cluster control via 9300 integrity impact
+- Scans and bulk queries availability degradation
+
+Enables data exfiltration and lateral movement.

Apply least privilege to network exposure:
+- Restrict 9200, 9300, 5601 to trusted sources or keep them private
+- Use private subnets, VPN/peering, or bastion/SSM for admin access
+- Enforce authentication and TLS on Elasticsearch/Kibana
+- Avoid public IPs unless strictly required

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have FTP ports open to the Internet.

Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
+
+Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners.

Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Kafka port 9092 open to the Internet.

Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host.

Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Kerberos ports open to the Internet.

Public Kerberos exposure risks CIA:
+- Password spraying/AS-REP roasting against accounts
+- Unauthorized password changes on 464
+- Realm/user enumeration and DoS of KDC/services
+
+Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm.

Restrict Kerberos ports to trusted sources only.
+- Prefer private connectivity (VPN, peering) over public exposure
+- Place KDCs/services in private subnets without public IPs
+- Apply least privilege with narrowly scoped security group rules and NACLs
+- Add defense-in-depth: host firewalls and monitor authentication activity

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have LDAP ports open to the Internet.

Publicly reachable LDAP/LDAPS enables:
+- Directory enumeration and weak/anonymous bind attempts
+- Password spraying and credential theft (cleartext on 389)
+- Unauthorized queries causing data exfiltration
+
+Abuse may lead to privilege escalation and availability impact via account lockouts.

Limit LDAP to trusted networks:
+- Allowlist specific source CIDRs in security groups (least privilege)
+- Use private connectivity (peering/VPN) instead of Internet
+- Require LDAPS, strong certificates, and disable insecure binds
+- Add NACLs and monitoring for defense in depth
+
+If external access is required, place a proxy and enforce rate limits.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Memcached port 11211 open to the Internet.

Internet-exposed Memcached weakens:
+- Availability: abuse for reflection/amplification and resource exhaustion
+- Confidentiality: unauthorized reads of cached objects and metadata
+- Integrity: manipulation of cache entries influencing app behavior
+
+Public reachability also aids reconnaissance and lateral movement.

Apply least privilege on network access:
+- Restrict TCP 11211 to trusted sources or internal subnets only
+- Place instances in private subnets; avoid public IPs
+- Layer defense in depth with NACLs and routing to block Internet paths
+- Prefer private connectivity (peering/VPN) and implement service-level authentication where available

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have MongoDB ports open to the Internet.

Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
+- Data extraction (confidentiality)
+- Collection tampering or deletion (integrity)
+- DoS or ransomware disruptions (availability)
+A compromised DB host can also enable lateral movement within the environment.

Apply least privilege to MongoDB access:
+- Remove Internet-wide rules; allow only trusted sources
+- Keep DBs on private subnets without public IPs; use private connectivity or proxies
+- Enforce strong auth and TLS
+- Add segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have MySQL port 3306 open to the Internet.

Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads.

Restrict TCP 3306 to trusted sources per least privilege:
+- Allow DB access only from specific application subnets or security groups
+- Place database hosts in private subnets without public IPs
+- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Oracle ports open to the Internet.

Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface.

Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have PostgreSQL port 5432 open to the Internet.

Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale.

Restrict PostgreSQL to trusted sources only:
+- Remove 0.0.0.0/0 and ::/0 rules
+- Apply least privilege security groups (allow from app tier or VPN)
+- Place instances in private subnets without public IPs
+- Enforce TLS and strong auth; disable unused listeners
+- Layer with NACLs and monitoring for defense in depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have RDP port 3389 open to the Internet.

Internet-exposed RDP allows:
+- Brute force and credential reuse on Windows logons
+- Exploitation of RDP flaws for remote code execution
+- Lateral movement and data exfiltration
+This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware.

Remove Internet-wide RDP. Apply least privilege:
+- Restrict TCP 3389 to trusted IPs
+- Prefer private access via VPN or a hardened bastion; consider Session Manager
+- Use just-in-time access and short-lived rules
+- Enforce strong auth (e.g., NLA) and monitor logs
+Adopt defense in depth with layered network controls.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Redis port 6379 open to the Internet.

Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement.

Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
+
+Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have SQL Server ports open to the Internet.

Internet-reachable SQL services enable:
+- Brute-force and credential-stuffing of DB logins
+- Exploitation of SQL Server flaws for remote code execution
+- Unauthorized queries and data exfiltration
+This threatens confidentiality and integrity, and facilitates lateral movement from the database host.

Enforce least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 1433-1434
+- Allow only trusted IPs or app tiers via security group references
+- Keep databases in private subnets without public IPs; access via VPN or bastion
+- Require TLS and strong authentication; monitor access.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have SSH port 22 open to the Internet.

Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability.

Apply least privilege on SSH:
+- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
+- Prefer Session Manager or a hardened bastion behind VPN
+- Use key-based auth; disable passwords
+- Add defense in depth with network controls and monitor access logs

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +Instance i-095bd68aff22b103b does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +Instance i-02754e7ae419cd5db does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +Instance i-010066e6c9027aa6e does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +Instance i-046e7fc4677eaa796 does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +Instance i-067bdb5e3e09fa4bb does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +Instance i-073154fb4fa773bbd does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +Instance i-0055a6b877ba156e7 does not have Telnet port 23 open to the Internet.

Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover.

Eliminate Telnet: disable the service and block TCP 23.
+
+Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•ProwlerThreatScore-1.0: 2.1.6 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•NIS2: 6.7.2.g +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

FAILmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db not associated with an Instance Profile Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

PASSmediumec2us-east-2ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile rolearn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role.

Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius.

Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies.

+•CIS-7.0: 2.16 + +•CIS-1.4: 1.18 + +•CIS-1.5: 1.18 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC + +•CIS-2.0: 1.18 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05 + +•CIS-5.0: 1.17 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2 + +•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3 + +•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a + +•CIS-3.0: 1.18 + +•CIS-6.0: 2.17 + +•FFIEC: d3-pc-am-b-1 + +•ProwlerThreatScore-1.0: 1.2.4 + +•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 1.18 + +•NIS2: 11.1.1, 11.2.2.d +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b has a Public IP: 16.58.108.209 (ec2-16-58-108-209.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db has a Public IP: 16.59.189.218 (ec2-16-59-189-218.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e has a Public IP: 3.14.230.56 (ec2-3-14-230-56.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 has a Public IP: 52.14.227.224 (ec2-52-14-227-224.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb has a Public IP: 18.118.91.126 (ec2-18-118-91-126.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd has a Public IP: 3.150.90.196 (ec2-3-150-90-196.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

FAILmediumec2us-east-2ec2_instance_public_ipEC2 instance does not have a public IP addressarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 has a Public IP: 3.147.5.202 (ec2-3-147-5-202.us-east-2.compute.amazonaws.com).

Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability.

Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_6 + +•MITRE-ATTACK: T1190 + +•AWS-Foundational-Security-Best-Practices: EC2.9 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ac_3, ac_5, ip_8 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +No secrets found in EC2 instance i-095bd68aff22b103b since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +No secrets found in EC2 instance i-02754e7ae419cd5db since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +No secrets found in EC2 instance i-010066e6c9027aa6e since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +No secrets found in EC2 instance i-046e7fc4677eaa796 since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +No secrets found in EC2 instance i-067bdb5e3e09fa4bb since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +No secrets found in EC2 instance i-073154fb4fa773bbd since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASShighec2us-east-2ec2_instance_secrets_user_dataEC2 instance user data contains no secretsarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +No secrets found in EC2 instance i-0055a6b877ba156e7 since User Data is empty.

Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time.

Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines.

+•MITRE-ATTACK: T1552 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03 + +•NIST-CSF-2.0: ds_5 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-05 + +•NIS2: 3.5.3.a +

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_stopped_older_than_specific_daysEC2 instance has not been stopped longer than the configured maximum daysarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 is not stopped.

Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started.

Establish a lifecycle policy for stopped instances:
+- Tag instances with owner and expiry
+- Terminate instances no longer needed to reclaim EBS cost
+- If retained, start regularly for patching or rebuild from a hardened AMI
+- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
+
+Adjust max_ec2_instance_stopped_days to match policy.

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b uses only one ENI: ( Interfaces: ['eni-0eb7c8be6cbdcdb2e'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db uses only one ENI: ( Interfaces: ['eni-0c6930a5310520d0f'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e uses only one ENI: ( Interfaces: ['eni-0ce22bed73e11293b'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 uses only one ENI: ( Interfaces: ['eni-0e6a8f502a37c7496'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb uses only one ENI: ( Interfaces: ['eni-0f39fad20067101e6'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd uses only one ENI: ( Interfaces: ['eni-047c4fd5cc9b17732'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 uses only one ENI: ( Interfaces: ['eni-0f8af55ce6e60d737'] ).

Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment.

Prefer a single ENI per instance.
+
+If multi-homing is unavoidable:
+- Place ENIs in least-privilege subnets/SGs
+- Keep source/destination check enabled and routes explicit
+- Use gateways/LBs for NAT or ingress, not the host
+- Monitor flow logs and formally approve exceptions
+
+Embed defense in depth and zero trust.

+•AWS-Foundational-Security-Best-Practices: EC2.17 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 Instance i-095bd68aff22b103b is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 Instance i-02754e7ae419cd5db is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 Instance i-010066e6c9027aa6e is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 Instance i-046e7fc4677eaa796 is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 Instance i-067bdb5e3e09fa4bb is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 Instance i-073154fb4fa773bbd is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

PASSmediumec2us-east-2ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 Instance i-0055a6b877ba156e7 is not using an outdated AMI.

Running on a deprecated AMI undermines security and availability:
+- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
+- Unsupported components hinder hardening and forensics
+- AMI removal from catalogs complicates scale-out and recovery (availability)

Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth.

+•ASD-Essential-Eight-Nov 2023: E8-2.8 +

FAILhighec2us-east-2ec2_networkacl_allow_ingress_any_portNetwork ACL does not allow ingress from 0.0.0.0/0 to any portarn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7Network ACL acl-0434045af7cd4bbc7 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

+•CISA: your-data-2 + +•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_networkacl_allow_ingress_any_portNetwork ACL does not allow ingress from 0.0.0.0/0 to any portarn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8Network ACL acl-0cabb33741ea2f4f8 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

+•CISA: your-data-2 + +•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_networkacl_allow_ingress_any_portNetwork ACL does not allow ingress from 0.0.0.0/0 to any portarn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345Network ACL acl-0e58a8e59c5863345 has every port open to the Internet.

Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control.

Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting.

+•CISA: your-data-2 + +•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_22Network ACL does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7Network ACL acl-0434045af7cd4bbc7 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
+
+Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
+- Do not allow 0.0.0.0/0 to TCP 22
+- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
+
+Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 + +•CIS-5.0: 5.2 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_22Network ACL does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8Network ACL acl-0cabb33741ea2f4f8 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
+
+Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
+- Do not allow 0.0.0.0/0 to TCP 22
+- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
+
+Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 + +•CIS-5.0: 5.2 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_22Network ACL does not allow ingress from the Internet to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345Network ACL acl-0e58a8e59c5863345 has SSH port 22 open to the Internet.

An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
+
+Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity.

Apply least privilege at the subnet layer:
+- Do not allow 0.0.0.0/0 to TCP 22
+- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
+
+Pair tight security groups with periodic rule reviews and change control to maintain defense in depth.

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03 + +•CIS-5.0: 5.2 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_3389Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7Network ACL acl-0434045af7cd4bbc7 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs. +

    +
  • Restrict RDP to specific admin IP ranges
  • +
  • Prefer bastion hosts or Session Manager over direct RDP
  • +
  • Use private subnets and layer controls for defense in depth
  • +

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_3389Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8Network ACL acl-0cabb33741ea2f4f8 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs. +

    +
  • Restrict RDP to specific admin IP ranges
  • +
  • Prefer bastion hosts or Session Manager over direct RDP
  • +
  • Use private subnets and layer controls for defense in depth
  • +

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

FAILmediumec2us-east-2ec2_networkacl_allow_ingress_tcp_port_3389Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345Network ACL acl-0e58a8e59c5863345 has Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity.

Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs. +

    +
  • Restrict RDP to specific admin IP ranges
  • +
  • Prefer bastion hosts or Session Manager over direct RDP
  • +
  • Use private subnets and layer controls for defense in depth
  • +

+•CIS-7.0: 6.2 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.1 + +•CIS-1.5: 5.1 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.21 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.1 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•CIS-5.0: 5.2 + +•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21 + +•CIS-3.0: 5.1 + +•CIS-6.0: 6.2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2 + +•ProwlerThreatScore-1.0: 2.1.3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.2 + +•NIS2: 6.7.2.g +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASScriticalec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the Internetarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have all ports open to the Internet.

Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk.

Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•ENS-RD2022: mp.com.1.aws.sg.2 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05 + +•SecNumCloud-3.2: 13.2 + +•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5 + +•ProwlerThreatScore-1.0: 2.1.4 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to the Internet.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

FAILhighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance ownersarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) has at least one port open to the Internet but its network interface type (interface) is not allowed.

Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement.

Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40 + +•SecNumCloud-3.2: 9.6, 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cna +

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

FAILmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has a port open to a specific public IP address in ingress rule.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASSmediumec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any port open to a public IP address.

Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0.

Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible.

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any high-risk port open to the Internet.

Public exposure of these ports enables:
+- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
+- Credential theft/data leakage via mail protocols (25, 110, 143)
+- Spam relay on 25
+Impacts: confidentiality, integrity, and availability through exploitation and mass scanning.

Restrict these ports using least privilege:
+- Deny Internet ingress; allow only trusted CIDRs or private connectivity
+- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
+- Disable unnecessary services; require auth and TLS on exposed apps
+Apply defense in depth with security groups and network ACLs.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.19 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•C5-2025: OIS-05.03B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2 + +•NIST-CSF-2.0: ac_5 + +•SecNumCloud-3.2: 13.2 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have SSH port 22 open to the Internet.

Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment.

Apply least privilege to SSH:
+- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
+- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
+- Enforce key-based auth, disable passwords, rotate keys
+- Add network segmentation and monitoring for defense in depth

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6, cc_7_2 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.13 + +•ISO27001-2013: A.12.6.C, A.13.1.C + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•HIPAA: 164_308_a_1_ii_b, 164_312_e_1 + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 5.3, 5.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6 + +•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17 + +•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2 + +•CCC-v2025.10: CCC.Core.CN01.AR02 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3 + +•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft RDP port 3389 open to the Internet.

Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
+
+Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability).

Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
+
+Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring.

+•CIS-7.0: 6.3, 6.4 + +•SOC2: cc_6_6 + +•CIS-1.4: 5.2 + +•CIS-1.5: 5.2, 5.3 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•AWS-Foundational-Security-Best-Practices: EC2.14 + +•ISO27001-2013: A.12.6.B, A.13.1.B + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•CIS-2.0: 5.2, 5.3 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_3, ac_5 + +•CIS-5.0: 5.3, 5.4 + +•CIS-3.0: 5.2, 5.3 + +•CIS-6.0: 6.3, 6.4 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1 + +•SecNumCloud-3.2: 13.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.4, 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•CIS-4.0.1: 5.3, 5.4 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Casandra ports 7199, 8888 and 9160 open to the Internet.

Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
+- Unauthorized reads of data/metrics (confidentiality)
+- Schema and cluster changes (integrity)
+- Remote operations causing outages (availability)
+
+Public reachability also increases brute-force and exploit attempts.

Restrict ingress on 7199, 9160, 8888 to trusted sources:
+- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
+- Place nodes in private subnets; use VPN or a bastion for admin
+- Prefer strong auth and mTLS; bind management to internal interfaces
+- Apply defense in depth with segmentation (north-south and east-west)

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet.

Open Elasticsearch/Kibana ports to the Internet erode CIA:
+- Confidentiality: unauthorized queries and data exfiltration
+- Integrity: index tampering/deletion, cluster control via 9300
+- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force

Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have FTP ports 20 and 21 open to the Internet.

Exposed FTP weakens CIA:
+- Confidentiality: cleartext credentials/files enable interception and brute force.
+- Integrity: unauthorized uploads or tampering enable malware staging.
+- Availability: mass scans and login attempts can exhaust resources and disrupt services.

Apply least privilege and defense in depth:
+- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
+- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
+- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Kafka port 9092 open to the Internet.

Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC.

Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Memcached port 11211 open to the Internet.

Exposed Memcached enables unauthenticated access, impacting CIA:
+- Confidentiality: read cached data (sessions, secrets)
+- Integrity: modify or poison entries
+- Availability: flush or overload cache, degrading apps
+
+Open 11211 is widely scanned, enabling unauthorized access and lateral movement.

Apply least privilege and segmentation:
+- Restrict TCP 11211 to trusted CIDRs or security groups
+- Keep Memcached on private subnets; avoid public IPs
+- Add defense in depth with NACLs/firewalls; disable unused protocols
+- Use private connectivity (VPN/peering) and monitor access

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MongoDB ports 27017 and 27018 open to the Internet.

Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
+
+Exposure also enables enumeration and lateral movement, threatening availability.

Apply least privilege to MongoDB access:
+- Block 0.0.0.0/0 and ::/0
+- Allow only trusted IPs or private networks
+- Prefer private connectivity and SG-to-SG references
+- Enforce authentication and TLS
+- Segment east-west traffic and monitor access for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MySQL port 3306 open to the Internet.

Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
+- Confidentiality: data exfiltration
+- Integrity: unauthorized writes or schema changes
+- Availability: DoS from abuse or scans

Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Oracle ports 1521 and 2483 open to the Internet.

Public Oracle listener exposure enables attackers to:
+- Brute force credentials and enumerate services
+- Exploit listener flaws for remote access
+- Run unauthorized queries causing data exfiltration
+- Launch DoS on the listener
+
+This jeopardizes database confidentiality, integrity, and availability.

Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
+
+Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Postgres port 5432 open to the Internet.

Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability).

Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Redis port 6379 open to the Internet.

Public Redis access undermines confidentiality, integrity, and availability:
+- Read keys and secrets
+- Modify or flush data and configs
+- Exhaust memory for DoS
+Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC.

Restrict Redis to private connectivity and apply least privilege:
+- Allow 6379 only from required app hosts, security groups, or CIDRs
+- Prefer VPC/private networks or VPN over public IPs
+- Enforce Redis AUTH and TLS, bind to private interfaces
+- Use segmentation and monitoring for defense in depth

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet.

Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability.

Apply least privilege on network access:
+- Restrict SQL ingress to trusted IPs or via VPN/bastion
+- Place databases in private subnets; allow only app-tier sources
+- Avoid 0.0.0.0/0 and ::/0
+- Use defense in depth with network ACLs/firewalls
+- Monitor auth failures and rate-limit repeated attempts

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Telnet port 23 open to the Internet.

Public Telnet exposes cleartext credentials and remote shell access.
+- Brute-force and credential interception enable account takeover
+- Command execution enables data theft and lateral movement
+
+This threatens confidentiality and integrity and can degrade availability through misuse.

Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging.

+•SOC2: cc_6_6 + +•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•C5-2025: PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•CCC-v2025.10: CCC.Core.CN01.AR03 + +•ProwlerThreatScore-1.0: 2.1.7 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASShighec2us-east-2ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) has no potential wide-open non-RFC1918 address.

Over-broad public CIDRs expand exposure and enable:
+- Confidentiality loss via unauthorized access and exfiltration
+- Integrity compromise by exploiting exposed services
+- Availability impact from scanning and abuse
+
+Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs.

Apply least privilege on security groups:
+- Allow only known IPs (prefer /32 or tight CIDRs)
+- Use private connectivity (VPN, Direct Connect, private endpoints)
+- Restrict and log egress; deny by default
+- Segment with security group references and network ACLs for defense-in-depth

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•SecNumCloud-3.2: 12.14 + +•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791Security group default (sg-093604be72efb9791) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750Security group ec2-rds-2 (sg-0d87b03d9b2789750) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853Security group default (sg-0dbf3eea7e40c7853) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123Security group rds-ec2-3 (sg-058c35683b5b40123) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7Security group default (sg-0438e6794e0d9c0d7) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6Security group rds-ec2-1 (sg-0084c72426d93c9c6) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27fSecurity group ec2-rds-1 (sg-0f29b9425a85de27f) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9Security group rds-ec2-2 (sg-09fbc74b0b61042d9) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938bSecurity group ec2-rds-3 (sg-06728bf2249b5938b) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) was created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) was created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch Wizardarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) was not created using the EC2 Launch Wizard.

Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control.

Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•ENS-RD2022: mp.com.1.aws.sg.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750Security group ec2-rds-2 (sg-0d87b03d9b2789750) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123Security group rds-ec2-3 (sg-058c35683b5b40123) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6Security group rds-ec2-1 (sg-0084c72426d93c9c6) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27fSecurity group ec2-rds-1 (sg-0f29b9425a85de27f) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9Security group rds-ec2-2 (sg-09fbc74b0b61042d9) it is not being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938bSecurity group ec2-rds-3 (sg-06728bf2249b5938b) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSlowec2us-east-2ec2_securitygroup_not_usedNon-default EC2 security group is in usearn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) it is being used.

Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls.

Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups.

+•AWS-Foundational-Security-Best-Practices: EC2.22 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•NIST-CSF-2.0: ac_5, ip_1 + +•ENS-RD2022: mp.com.1.aws.sg.3 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791Security group default (sg-093604be72efb9791) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 +•Name=Ml_prod_sg +Security group ml_prod_sg (sg-0256d81b7afd54cf9) has 3 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750Security group ec2-rds-2 (sg-0d87b03d9b2789750) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853Security group default (sg-0dbf3eea7e40c7853) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123Security group rds-ec2-3 (sg-058c35683b5b40123) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 +•Name=Scrivas_Ml_dev +Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has 3 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7Security group default (sg-0438e6794e0d9c0d7) has 1 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 +•GuardDutyManaged=true +Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6Security group rds-ec2-1 (sg-0084c72426d93c9c6) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27fSecurity group ec2-rds-1 (sg-0f29b9425a85de27f) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 +•Name=scrivas_prod +Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9Security group rds-ec2-2 (sg-09fbc74b0b61042d9) has 1 inbound rules and 0 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938bSecurity group ec2-rds-3 (sg-06728bf2249b5938b) has 0 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 +•Name=sg-netbird +Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has 4 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 +•Name=scrivas-dev-env +Security group launch-wizard-1 (sg-0621cd7244c8006b3) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumec2us-east-2ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesarn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1Security group scrivas_stage_env (sg-0823502d51c886ab1) has 6 inbound rules and 1 outbound rules.

Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services.

Apply least privilege and segmentation:
+- Limit rules to required ports, protocols, and sources
+- Split workloads into dedicated security groups per role
+- Prefer SG-to-SG references over broad CIDRs
+- Regularly review, deduplicate, and remove stale rules
+- Layer controls (NACLs, private endpoints) for defense in depth

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03 + +•AWS-Foundational-Technical-Review: NETSEC-001 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

PASSmediumecrus-east-2ecr_registry_scan_images_on_push_enabledECR registry has image scanning on push enabled for all repositoriesarn:aws:ecr:us-east-2:716468089330:registry/716468089330ECR registry 716468089330 has ENHANCED scan with scan on push enabled.

Absent or filtered scan on push lets vulnerable images be pushed and deployed without timely detection, enabling exploitation of known CVEs (RCE, privilege escalation), supply chain compromise, and lateral movement - threatening workload integrity and data confidentiality.

Enable registry-wide scan on push and ensure rules apply to all repositories (no filters). Prefer enhanced scanning for broader coverage, and pair with continuous scans when available. Integrate findings into CI/CD gates and alerts to enforce defense in depth and block promotion of risky images.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.2 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.2 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•CCC-v2025.10: CCC.CntrReg.CN01.AR01 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASSlowecrus-east-2ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryserviceRepository scrivas/patientsummaryservice has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
+- Availability issues when quotas block pushes and CI/CD
+- Integrity risk from redeploying outdated, vulnerable images
+- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

+•AWS-Foundational-Security-Best-Practices: ECR.3 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: OPS-26.04B, OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 + +•NIS2: 12.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASSlowecrus-east-2ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparserRepository scrivas/patientdocumentparser has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
+- Availability issues when quotas block pushes and CI/CD
+- Integrity risk from redeploying outdated, vulnerable images
+- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

+•AWS-Foundational-Security-Best-Practices: ECR.3 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: OPS-26.04B, OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 + +•NIS2: 12.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASSlowecrus-east-2ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredarn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriberRepository scrivas/sonioxtranscriber has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
+- Availability issues when quotas block pushes and CI/CD
+- Integrity risk from redeploying outdated, vulnerable images
+- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

+•AWS-Foundational-Security-Best-Practices: ECR.3 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: OPS-26.04B, OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 + +•NIS2: 12.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASSlowecrus-east-2ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredarn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestionsRepository scrivas/saisuggestions has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
+- Availability issues when quotas block pushes and CI/CD
+- Integrity risk from redeploying outdated, vulnerable images
+- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

+•AWS-Foundational-Security-Best-Practices: ECR.3 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: OPS-26.04B, OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 + +•NIS2: 12.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASSlowecrus-east-2ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredarn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessorRepository scrivas/postprocessor has a lifecycle policy configured.

Without lifecycle policies, images accumulate indefinitely, leading to:
+- Availability issues when quotas block pushes and CI/CD
+- Integrity risk from redeploying outdated, vulnerable images
+- Cost growth from unnecessary storage

Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk.

+•AWS-Foundational-Security-Best-Practices: ECR.3 + +•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: OPS-26.04B, OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7 + +•NIS2: 12.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASScriticalecrus-east-2ecr_repositories_not_publicly_accessibleECR repository is not publicly accessiblearn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryserviceRepository scrivas/patientsummaryservice is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.
+
+Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
+- Avoid Principal:&#34;*&#34; and block anonymous access
+- Grant minimal actions to specific accounts/roles
+- Require authenticated pulls/pushes via IAM
+- Use private connectivity (e.g., VPC endpoints)
+- Add defense in depth with image scanning and signing

+•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1 + +•ProwlerThreatScore-1.0: 2.3.7 + +•ISO27001-2022: A.8.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASScriticalecrus-east-2ecr_repositories_not_publicly_accessibleECR repository is not publicly accessiblearn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparserRepository scrivas/patientdocumentparser is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.
+
+Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
+- Avoid Principal:&#34;*&#34; and block anonymous access
+- Grant minimal actions to specific accounts/roles
+- Require authenticated pulls/pushes via IAM
+- Use private connectivity (e.g., VPC endpoints)
+- Add defense in depth with image scanning and signing

+•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1 + +•ProwlerThreatScore-1.0: 2.3.7 + +•ISO27001-2022: A.8.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASScriticalecrus-east-2ecr_repositories_not_publicly_accessibleECR repository is not publicly accessiblearn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriberRepository scrivas/sonioxtranscriber is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.
+
+Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
+- Avoid Principal:&#34;*&#34; and block anonymous access
+- Grant minimal actions to specific accounts/roles
+- Require authenticated pulls/pushes via IAM
+- Use private connectivity (e.g., VPC endpoints)
+- Add defense in depth with image scanning and signing

+•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1 + +•ProwlerThreatScore-1.0: 2.3.7 + +•ISO27001-2022: A.8.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASScriticalecrus-east-2ecr_repositories_not_publicly_accessibleECR repository is not publicly accessiblearn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestionsRepository scrivas/saisuggestions is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.
+
+Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
+- Avoid Principal:&#34;*&#34; and block anonymous access
+- Grant minimal actions to specific accounts/roles
+- Require authenticated pulls/pushes via IAM
+- Use private connectivity (e.g., VPC endpoints)
+- Add defense in depth with image scanning and signing

+•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1 + +•ProwlerThreatScore-1.0: 2.3.7 + +•ISO27001-2022: A.8.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASScriticalecrus-east-2ecr_repositories_not_publicly_accessibleECR repository is not publicly accessiblearn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessorRepository scrivas/postprocessor is not publicly accessible.

Public access to ECR repositories weakens confidentiality and integrity.
+
+Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata.

Apply least privilege to repository policies:
+- Avoid Principal:&#34;*&#34; and block anonymous access
+- Grant minimal actions to specific accounts/roles
+- Require authenticated pulls/pushes via IAM
+- Use private connectivity (e.g., VPC endpoints)
+- Add defense in depth with image scanning and signing

+•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1 + +•ProwlerThreatScore-1.0: 2.3.7 + +•ISO27001-2022: A.8.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

FAILmediumecrus-east-2ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryserviceECR repository scrivas/patientsummaryservice has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

+•AWS-Foundational-Security-Best-Practices: ECR.1 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 + +•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•SecNumCloud-3.2: 12.11, 14.6 +

FAILmediumecrus-east-2ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparserECR repository scrivas/patientdocumentparser has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

+•AWS-Foundational-Security-Best-Practices: ECR.1 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 + +•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•SecNumCloud-3.2: 12.11, 14.6 +

FAILmediumecrus-east-2ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriberECR repository scrivas/sonioxtranscriber has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

+•AWS-Foundational-Security-Best-Practices: ECR.1 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 + +•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•SecNumCloud-3.2: 12.11, 14.6 +

FAILmediumecrus-east-2ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestionsECR repository scrivas/saisuggestions has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

+•AWS-Foundational-Security-Best-Practices: ECR.1 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 + +•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•SecNumCloud-3.2: 12.11, 14.6 +

FAILmediumecrus-east-2ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessorECR repository scrivas/postprocessor has scan on push disabled.

Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines.

Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management.

+•AWS-Foundational-Security-Best-Practices: ECR.1 + +•C5-2025: PSS-11.01B, PSS-11.01AC + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02 + +•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•SecNumCloud-3.2: 12.11, 14.6 +

FAILmediumecrus-east-2ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryserviceRepository scrivas/patientsummaryservice does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

+•AWS-Foundational-Security-Best-Practices: ECR.2 + +•C5-2025: AM-09.01B, OPS-26.03B + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

FAILmediumecrus-east-2ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparserRepository scrivas/patientdocumentparser does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

+•AWS-Foundational-Security-Best-Practices: ECR.2 + +•C5-2025: AM-09.01B, OPS-26.03B + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

FAILmediumecrus-east-2ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriberRepository scrivas/sonioxtranscriber does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

+•AWS-Foundational-Security-Best-Practices: ECR.2 + +•C5-2025: AM-09.01B, OPS-26.03B + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

FAILmediumecrus-east-2ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestionsRepository scrivas/saisuggestions does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

+•AWS-Foundational-Security-Best-Practices: ECR.2 + +•C5-2025: AM-09.01B, OPS-26.03B + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

FAILmediumecrus-east-2ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledarn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessorRepository scrivas/postprocessor does not have immutability configured.

Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality.

Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored.

+•AWS-Foundational-Security-Best-Practices: ECR.2 + +•C5-2025: AM-09.01B, OPS-26.03B + +•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr +

PASShighemrus-east-1emr_cluster_account_public_block_enabledEMR account has Block Public Access enabledarn:aws:elasticmapreduce:us-east-1:716468089330:clusterEMR Account has Block Public Access enabled.

Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.
+
+Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption.

Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.
+
+Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth.

+•AWS-Foundational-Security-Best-Practices: EMR.2 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8 + +•ProwlerThreatScore-1.0: 2.3.11 + +•ISO27001-2022: A.8.1 +

PASShighemrus-east-2emr_cluster_account_public_block_enabledEMR account has Block Public Access enabledarn:aws:elasticmapreduce:us-east-2:716468089330:clusterEMR Account has Block Public Access enabled.

Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.
+
+Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption.

Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.
+
+Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth.

+•AWS-Foundational-Security-Best-Practices: EMR.2 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8 + +•ProwlerThreatScore-1.0: 2.3.11 + +•ISO27001-2022: A.8.1 +

PASShigheventbridgeus-east-1eventbridge_bus_cross_account_accessAWS EventBridge event bus does not allow cross-account accessarn:aws:events:us-east-1:716468089330:event-bus/defaultEventBridge event bus default does not allow cross-account access.

Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods.

Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.
+
+Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_5, ac_4, dp_4 + +•CCC-v2025.10: CCC.Core.CN05.AR03 +

PASShigheventbridgeus-east-2eventbridge_bus_cross_account_accessAWS EventBridge event bus does not allow cross-account accessarn:aws:events:us-east-2:716468089330:event-bus/defaultEventBridge event bus default does not allow cross-account access.

Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods.

Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.
+
+Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_5, ac_4, dp_4 + +•CCC-v2025.10: CCC.Core.CN05.AR03 +

PASShigheventbridgeus-east-1eventbridge_bus_exposedAWS EventBridge event bus policy does not allow public accessarn:aws:events:us-east-1:716468089330:event-bus/defaultEventBridge event bus default is not exposed to everyone.

Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events.

Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: &#34;*&#34;.
+
+Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity.

+•CIS-7.0: 2.21 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_5, ac_4, dp_4 + +•ProwlerThreatScore-1.0: 2.3.13 +

PASShigheventbridgeus-east-2eventbridge_bus_exposedAWS EventBridge event bus policy does not allow public accessarn:aws:events:us-east-2:716468089330:event-bus/defaultEventBridge event bus default is not exposed to everyone.

Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events.

Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: &#34;*&#34;.
+
+Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity.

+•CIS-7.0: 2.21 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_5, ac_4, dp_4 + +•ProwlerThreatScore-1.0: 2.3.13 +

FAILmediumguarddutyus-east-1guardduty_centrally_managedGuardDuty detector is managed by an administrator account or is the administrator with member accountsarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c is not centrally managed.

Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability.

Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization + +•ENS-RD2022: op.mon.1.aws.gd.3 + +•ISO27001-2022: A.5.25, A.5.28, A.5.29 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

FAILmediumguarddutyus-east-2guardduty_centrally_managedGuardDuty detector is managed by an administrator account or is the administrator with member accountsarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc is not centrally managed.

Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability.

Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization + +•ENS-RD2022: op.mon.1.aws.gd.3 + +•ISO27001-2022: A.5.25, A.5.28, A.5.29 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

FAILhighguarddutyus-east-1guardduty_delegated_admin_enabled_all_regionsGuardDuty has delegated admin configured and is enabled in all regions with organization auto-enablearn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty in region us-east-1 has issues: no delegated administrator configured.

Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration.

Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization.

+•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 +

FAILhighguarddutyus-east-2guardduty_delegated_admin_enabled_all_regionsGuardDuty has delegated admin configured and is enabled in all regions with organization auto-enablearn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty in region us-east-2 has issues: no delegated administrator configured.

Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration.

Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization.

+•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 +

PASShighguarddutyus-east-1guardduty_ec2_malware_protection_enabledGuardDuty detector has Malware Protection for EC2 enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Malware Protection for EC2 enabled.

Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
+- Confidentiality loss via data exfiltration/credential theft
+- Integrity compromise through tampering and backdoors
+- Availability impact from ransomware/cryptominers
+
+Persistence increases lateral movement across the environment.

Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9 + +•C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9 + +•NIST-CSF-2.0: ip_7, cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_ec2_malware_protection_enabledGuardDuty detector has Malware Protection for EC2 enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Malware Protection for EC2 enabled.

Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
+- Confidentiality loss via data exfiltration/credential theft
+- Integrity compromise through tampering and backdoors
+- Availability impact from ransomware/cryptominers
+
+Persistence increases lateral movement across the environment.

Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9 + +•C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9 + +•NIST-CSF-2.0: ip_7, cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-1guardduty_eks_audit_log_enabledGuardDuty detector has EKS Audit Log Monitoring enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Audit Log Monitoring enabled.

Without it, Kubernetes API abuse may go undetected, impacting CIA:
+- Secret access and data exfiltration
+- RBAC changes enabling privilege escalation
+- Rogue deployments for persistence/cryptomining
+
+Attackers can laterally move to AWS using harvested credentials.

Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
+- Route findings to alerting/IR workflows
+- Enforce least privilege on access to findings and configs
+- Combine with defense-in-depth: hardened RBAC and runtime monitoring

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•SecNumCloud-3.2: 12.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•NIS2: 3.2.3.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_eks_audit_log_enabledGuardDuty detector has EKS Audit Log Monitoring enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Audit Log Monitoring enabled.

Without it, Kubernetes API abuse may go undetected, impacting CIA:
+- Secret access and data exfiltration
+- RBAC changes enabling privilege escalation
+- Rogue deployments for persistence/cryptomining
+
+Attackers can laterally move to AWS using harvested credentials.

Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
+- Route findings to alerting/IR workflows
+- Enforce least privilege on access to findings and configs
+- Combine with defense-in-depth: hardened RBAC and runtime monitoring

+•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3 + +•SecNumCloud-3.2: 12.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•NIS2: 3.2.3.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASSmediumguarddutyus-east-1guardduty_eks_runtime_monitoring_enabledGuardDuty detector has EKS Runtime Monitoring enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Runtime Monitoring enabled.

Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability).

    +
  • Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
  • +
  • Enforce least privilege for agents and segment cluster access
  • +
  • Integrate findings with response workflows and periodically verify runtime coverage
  • +

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_7, cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•NIS2: 3.2.3.h + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASSmediumguarddutyus-east-2guardduty_eks_runtime_monitoring_enabledGuardDuty detector has EKS Runtime Monitoring enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Runtime Monitoring enabled.

Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability).

    +
  • Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
  • +
  • Enforce least privilege for agents and segment cluster access
  • +
  • Integrate findings with response workflows and periodically verify runtime coverage
  • +

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: ip_7, cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•NIS2: 3.2.3.h + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-1guardduty_is_enabledGuardDuty detector is enabled and not suspendedarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c enabled.

Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions.

Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth.

+•CISA: your-systems-3, your-crisis-response-2 + +•SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 + +•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046 + +•AWS-Foundational-Security-Best-Practices: GuardDuty.1 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC + +•HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04 + +•NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7 + +•PCI-4.0: 11.5.1.1.2, 11.5.1.2 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4 + +•NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b + +•AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection + +•ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1 + +•AWS-Foundational-Technical-Review: IAM-002 + +•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5 + +•CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01 + +•SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2 + +•FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 + +•PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c + +•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_is_enabledGuardDuty detector is enabled and not suspendedarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc enabled.

Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions.

Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth.

+•CISA: your-systems-3, your-crisis-response-2 + +•SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 + +•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046 + +•AWS-Foundational-Security-Best-Practices: GuardDuty.1 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC + +•HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04 + +•NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7 + +•PCI-4.0: 11.5.1.1.2, 11.5.1.2 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4 + +•NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b + +•AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection + +•ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1 + +•AWS-Foundational-Technical-Review: IAM-002 + +•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5 + +•CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01 + +•SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2 + +•FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 + +•PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c + +•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-1guardduty_lambda_protection_enabledGuardDuty detector has Lambda Protection enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Lambda Protection enabled.

Without Lambda Protection, Lambda network traffic is uninspected, enabling:
+- C2 callbacks and data exfiltration (confidentiality)
+- Malicious code altering data or configs (integrity)
+- Lateral movement or abuse causing disruption (availability)

Enable Lambda Protection on all detectors in every active Region and account.
+
+Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_lambda_protection_enabledGuardDuty detector has Lambda Protection enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Lambda Protection enabled.

Without Lambda Protection, Lambda network traffic is uninspected, enabling:
+- C2 callbacks and data exfiltration (confidentiality)
+- Malicious code altering data or configs (integrity)
+- Lateral movement or abuse causing disruption (availability)

Enable Lambda Protection on all detectors in every active Region and account.
+
+Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-1guardduty_no_high_severity_findingsGuardDuty detector has no high severity findingsarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector 06cd01bd46fd95ae0932955e7606db6c does not have high severity findings.

Unresolved High findings often signal active compromise, enabling:
+- Data exfiltration and unauthorized access (confidentiality)
+- Privilege escalation and tampering (integrity)
+- Disruption via malware/crypto-mining (availability)
+
+Attackers can pivot laterally and persist if not contained.

Treat High findings as incidents. +

    +
  • Prioritize triage and containment; isolate affected resources, rotate secrets
  • +
  • Automate alerting and response with playbooks; integrate into IR
  • +
  • Enforce least privilege, network segmentation, and hardened baselines
  • +
  • Continuously tune detections and remove unused access to prevent recurrence
  • +

+•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B + +•HIPAA: 164_308_a_6_ii + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_2 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3 + +•NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4 + +•NIST-800-53-Revision-5: ir_4_a + +•AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection + +•ENS-RD2022: op.exp.7.aws.gd.1 + +•AWS-Foundational-Technical-Review: IAM-002, SECOPS-001 + +•NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3 + +•CCC-v2025.10: CCC.Core.CN07.AR01 + +•SecNumCloud-3.2: 12.4, 16.3 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d3-dc-an-b-1, d5-er-es-b-4 + +•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ir-4 + +•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr +

FAILhighguarddutyus-east-2guardduty_no_high_severity_findingsGuardDuty detector has no high severity findingsarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector 4acd016b4a01f41ab229556d98e12efc has 1 high severity findings.

Unresolved High findings often signal active compromise, enabling:
+- Data exfiltration and unauthorized access (confidentiality)
+- Privilege escalation and tampering (integrity)
+- Disruption via malware/crypto-mining (availability)
+
+Attackers can pivot laterally and persist if not contained.

Treat High findings as incidents. +

    +
  • Prioritize triage and containment; isolate affected resources, rotate secrets
  • +
  • Automate alerting and response with playbooks; integrate into IR
  • +
  • Enforce least privilege, network segmentation, and hardened baselines
  • +
  • Continuously tune detections and remove unused access to prevent recurrence
  • +

+•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B + +•HIPAA: 164_308_a_6_ii + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•NIST-CSF-2.0: ov_2 + +•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3 + +•NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4 + +•NIST-800-53-Revision-5: ir_4_a + +•AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection + +•ENS-RD2022: op.exp.7.aws.gd.1 + +•AWS-Foundational-Technical-Review: IAM-002, SECOPS-001 + +•NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3 + +•CCC-v2025.10: CCC.Core.CN07.AR01 + +•SecNumCloud-3.2: 12.4, 16.3 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d3-dc-an-b-1, d5-er-es-b-4 + +•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ir-4 + +•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr +

PASShighguarddutyus-east-1guardduty_rds_protection_enabledGuardDuty detector has RDS Protection enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector has RDS Protection enabled.

Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability.

Enable GuardDuty RDS Protection across all accounts and Regions.
+- Enforce least privilege for DB users and rotate credentials
+- Restrict network exposure to databases
+- Integrate findings with alerting and incident response for rapid containment

+•AWS-Foundational-Security-Best-Practices: GuardDuty.9 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_rds_protection_enabledGuardDuty detector has RDS Protection enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector has RDS Protection enabled.

Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability.

Enable GuardDuty RDS Protection across all accounts and Regions.
+- Enforce least privilege for DB users and rotate credentials
+- Restrict network exposure to databases
+- Integrate findings with alerting and incident response for rapid containment

+•AWS-Foundational-Security-Best-Practices: GuardDuty.9 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-1guardduty_s3_protection_enabledGuardDuty detector has S3 Protection enabledarn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6cGuardDuty detector has S3 Protection enabled.

Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
+- Exfiltration via mass reads/copies
+- Destructive deletes
+- Policy/ACL tampering
+
+Undetected actions degrade data confidentiality, integrity, and availability.

Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering.

+•AWS-Foundational-Security-Best-Practices: GuardDuty.10 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighguarddutyus-east-2guardduty_s3_protection_enabledGuardDuty detector has S3 Protection enabledarn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efcGuardDuty detector has S3 Protection enabled.

Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
+- Exfiltration via mass reads/copies
+- Destructive deletes
+- Policy/ACL tampering
+
+Undetected actions degrade data confidentiality, integrity, and availability.

Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering.

+•AWS-Foundational-Security-Best-Practices: GuardDuty.10 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: OPS-23.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: cm_7 + +•SecNumCloud-3.2: 12.4 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/AdminGroup Admin provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/devopsGroup devops provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/ecr-push-groupGroup ecr-push-group provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/otherpermissionGroup otherpermission provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/secertmanageraccessGroup secertmanageraccess provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledarn:aws:iam::716468089330:group/storage-accessGroup storage-access provides non-administrative access.

Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability.

Enforce MFA for all administrator identities.
+- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
+- Prefer hardware/FIDO2 devices
+- Apply least privilege and favor roles/SSO over users
+- Continuously monitor MFA status and remove unused admin access

+•MITRE-ATTACK: T1078, T1098, T1550 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rr_1, ac_4, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_avoid_root_usageAWS account root user has not been used in the last dayarn:aws:iam::716468089330:rootRoot user in the account wasn't accessed in the last 1 days.

Recent root usage expands blast radius:
+- Data exfiltration (confidentiality)
+- Policy/key tampering (integrity)
+- Resource deletion and billing changes (availability)
+Routine use reduces anomaly visibility and eases account takeover impact.

Minimize root usage by applying least privilege with admin roles or federated SSO and temporary credentials.
+- Enforce MFA on root
+- Avoid or remove root access keys
+- Require multi-person approval
+- Monitor and alert on any root sign-in
+- Use org guardrails for defense in depth

+•CIS-7.0: 2.7 + +•CIS-1.4: 1.7 + +•CIS-1.5: 1.7 + +•MITRE-ATTACK: T1078, T1098 + +•ISO27001-2013: A.9.2.H, A.9.4.H + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.10.2 + +•C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-06.04B + +•CIS-2.0: 1.7 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.6 + +•AWS-Account-Security-Onboarding: Block root user + +•CIS-3.0: 1.7 + +•ENS-RD2022: op.acc.2.aws.iam.4, op.acc.4.aws.iam.7 + +•CIS-6.0: 2.6 + +•CCC-v2025.10: CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.6 + +•ProwlerThreatScore-1.0: 1.2.5 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-04 + +•CIS-4.0.1: 1.7 + +•NIS2: 6.7.2.e, 11.3.2.b, 11.3.2.c, 11.4.2.a +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSOrganizationsServiceTrustPolicyAWS policy AWSOrganizationsServiceTrustPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/CloudWatchAgentServerPolicyAWS policy CloudWatchAgentServerPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AWSServiceCatalogAdminFullAccessAWS policy AWSServiceCatalogAdminFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/CloudwatchApplicationInsightsServiceLinkedRolePolicyAWS policy CloudwatchApplicationInsightsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonSSMManagedInstanceCoreAWS policy AmazonSSMManagedInstanceCore is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AutoScalingServiceRolePolicyAWS policy AutoScalingServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonRDSServiceRolePolicyAWS policy AmazonRDSServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSElasticLoadBalancingServiceRolePolicyAWS policy AWSElasticLoadBalancingServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyServiceRolePolicyAWS policy AmazonGuardDutyServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/CloudWatchReadOnlyAccessAWS policy CloudWatchReadOnlyAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSTrustedAdvisorServiceRolePolicyAWS policy AWSTrustedAdvisorServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSEC2SpotServiceRolePolicyAWS policy AWSEC2SpotServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubServiceRolePolicyAWS policy AWSSecurityHubServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILcriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AdministratorAccessAWS policy AdministratorAccess is attached and allows '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSSupportServiceRolePolicyAWS policy AWSSupportServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/CloudWatchLogsFullAccessAWS policy CloudWatchLogsFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/SecretsManagerReadWriteAWS policy SecretsManagerReadWrite is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/service-role/AmazonRDSEnhancedMonitoringRoleAWS policy AmazonRDSEnhancedMonitoringRole is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSClusterPolicyAWS policy AmazonEKSClusterPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonMacieServiceRolePolicyAWS policy AmazonMacieServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSConfigServiceRolePolicyAWS policy AWSConfigServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKS_CNI_PolicyAWS policy AmazonEKS_CNI_Policy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnlyAWS policy AmazonEC2ContainerRegistryReadOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/SecurityAuditAWS policy SecurityAudit is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/IAMUserChangePasswordAWS policy IAMUserChangePassword is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/CloudTrailServiceRolePolicyAWS policy CloudTrailServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicyAWS policy AmazonEKSWorkerNodePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonS3FullAccessAWS policy AmazonS3FullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalkAWS policy AdministratorAccess-AWSElasticBeanstalk is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonEKSServiceRolePolicyAWS policy AmazonEKSServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSWorkerNodeMinimalPolicyAWS policy AmazonEKSWorkerNodeMinimalPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/ServiceQuotasServiceRolePolicyAWS policy ServiceQuotasServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyMalwareProtectionServiceRolePolicyAWS policy AmazonGuardDutyMalwareProtectionServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSGlobalAcceleratorSLRPolicyAWS policy AWSGlobalAcceleratorSLRPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSDashboardConsoleReadOnlyAWS policy AmazonEKSDashboardConsoleReadOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonDevOpsGuruFullAccessAWS policy AmazonDevOpsGuruFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEC2ContainerRegistryPullOnlyAWS policy AmazonEC2ContainerRegistryPullOnly is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonSSMManagedEC2InstanceDefaultPolicyAWS policy AmazonSSMManagedEC2InstanceDefaultPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSNetworkingPolicyAWS policy AmazonEKSNetworkingPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSComputePolicyAWS policy AmazonEKSComputePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AWSQuickSetupDevOpsGuruPermissionsBoundaryAWS policy AWSQuickSetupDevOpsGuruPermissionsBoundary is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSResourceExplorerServiceRolePolicyAWS policy AWSResourceExplorerServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSServiceRoleForAmazonEKSNodegroupAWS policy AWSServiceRoleForAmazonEKSNodegroup is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSBlockStoragePolicyAWS policy AmazonEKSBlockStoragePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonDevOpsGuruOrganizationsAccessAWS policy AmazonDevOpsGuruOrganizationsAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonInspector2ServiceRolePolicyAWS policy AmazonInspector2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSLoadBalancingPolicyAWS policy AmazonEKSLoadBalancingPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonEKSVPCResourceControllerAWS policy AmazonEKSVPCResourceController is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AmazonInspector2AgentlessServiceRolePolicyAWS policy AmazonInspector2AgentlessServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSUserNotificationsServiceLinkedRolePolicyAWS policy AWSUserNotificationsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AdministratorAccess-AmplifyAWS policy AdministratorAccess-Amplify is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubV2ServiceRolePolicyAWS policy AWSSecurityHubV2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/service-role/AmazonEBSCSIDriverPolicyAWS policy AmazonEBSCSIDriverPolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonDevOpsGuruReadOnlyAccessAWS policy AmazonDevOpsGuruReadOnlyAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/AmazonDevOpsGuruConsoleFullAccessAWS policy AmazonDevOpsGuruConsoleFullAccess is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::aws:policy/aws-service-role/AccessAnalyzerServiceRolePolicyAWS policy AccessAnalyzerServiceRolePolicy is attached but does not allow '*:*' administrative privileges.

Unrestricted *:* access enables any action on any resource, risking:
+- Data exfiltration (confidentiality)
+- Unauthorized changes and policy tampering (integrity)
+- Service deletion or shutdown (availability)
+Attackers can disable logging, create backdoor principals, and expand lateral movement.

Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
+- Use customer-managed, scoped policies per role
+- Enforce separation of duties and permissions boundaries
+- Prefer temporary, time-bound elevation for emergencies with MFA
+- Regularly review access and use conditions to constrain context

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILlowiamus-east-2iam_check_saml_providers_stsIAM SAML provider exists in the accountarn:aws:iam::716468089330:rootNo SAML Providers found.

Without SAML federation, users rely on long-lived IAM keys. Compromised keys enable persistent API access, causing data exfiltration (C), unauthorized resource or policy changes (I), and difficult revocation. Lack of IdP controls (e.g., MFA, session limits) weakens accountability and access governance.

Adopt SAML federation to issue short-lived STS credentials. Map users to roles with least privilege, enforce MFA at the IdP, and set conservative session durations. Retire IAM user access keys for interactive use and monitor role sessions as defense in depth. If federation isn't possible, tightly scope, rotate, and audit keys.

+•CIS-7.0: 2.19 + +•CIS-1.4: 1.21 + +•CIS-1.5: 1.21 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•CIS-2.0: 1.21 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.20 + +•CIS-3.0: 1.21 + +•ENS-RD2022: op.acc.1.aws.iam.2 + +•CIS-6.0: 2.20 + +•CCC-v2025.10: CCC.Core.CN05.AR06, CCC.IAM.CN09.AR01 + +•ProwlerThreatScore-1.0: 1.2.7 + +•CIS-4.0.1: 1.21 +

PASShighiamus-east-2iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom policy VPCFlowLogs-CloudWatch-Policy-1781174377138 is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom policy scrivas-s3-storage-policy is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom policy gitlab-ci-ecr-push is attached but does not allow '*:*' administrative privileges.

Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account.

Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.14 + +•SOC2: cc_1_3, cc_6_3 + +•CIS-1.4: 1.16 + +•CIS-1.5: 1.16 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•CIS-2.0: 1.16 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6 + +•CIS-5.0: 1.15 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•CIS-3.0: 1.16 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.15 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.3.1 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_customer_unattached_policy_no_administrative_privilegesUnattached customer managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/saiCustom policy sai is unattached and does not allow '*:*' administrative privileges.

An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement.

Remove or redesign these policies to enforce least privilege:
+- Avoid * in actions/resources; scope precisely and use conditions
+- Apply permissions boundaries and SCPs as guardrails
+- Require peer review and policy validation before attachment
+- Use analysis tools to refine permissions and delete unused policies

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: po_1, ac_4, ac_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•ISO27001-2022: A.8.2 +

PASSmediumiamus-east-2iam_customer_unattached_policy_no_administrative_privilegesUnattached customer managed IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:policy/EnforceMFAdilbagCustom policy EnforceMFAdilbag is unattached and does not allow '*:*' administrative privileges.

An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement.

Remove or redesign these policies to enforce least privilege:
+- Avoid * in actions/resources; scope precisely and use conditions
+- Apply permissions boundaries and SCPs as guardrails
+- Require peer review and policy validation before attachment
+- Use analysis tools to refine permissions and delete unused policies

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04 + +•NIST-CSF-2.0: po_1, ac_4, ac_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01 + +•ISO27001-2022: A.8.2 +

FAILhighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/AdminIAM Group Admin has AdministratorAccess policy attached.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/devopsIAM Group devops does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/ecr-push-groupIAM Group ecr-push-group does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/otherpermissionIAM Group otherpermission does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/secertmanageraccessIAM Group secertmanageraccess does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:group/storage-accessIAM Group storage-access does not have AdministratorAccess policy.

Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
+- Read/exfiltrate sensitive data (C)
+- Modify or delete resources and configs (I/A)
+- Disable logging and weaken defenses, enabling persistence and lateral movement

Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:group/AdminInline policy sai-admin attached to group Admin does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:group/devopsInline policy kms attached to group devops does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:group/devopsInline policy sai-devops attached to group devops does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:group/otherpermissionInline policy custommfa attached to group otherpermission does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:group/otherpermissionInline policy loggingaccess attached to group otherpermission does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleInline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:role/FlowLogsToCloudWatchInline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASShighiamus-east-2iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow privilege escalation.

Excessive inline policy permissions let identities escalate to admin, compromising CIA:
+- Confidentiality: read secrets and data
+- Integrity: alter policies, code, and configs
+- Availability: delete or stop resources, disable logging
+Attackers can persist by creating keys/users or assuming powerful roles.

Apply least privilege and remove escalation paths:
+- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
+- Restrict by resource and Condition
+- Prefer managed, versioned policies; use permissions boundaries/SCPs
+- Require reviews and MFA for admins

+•SOC2: cc_3_3 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: SP-01.04B, AM-09.04AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•ProwlerThreatScore-1.0: 1.3.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:group/AdminInline policy sai-admin attached to group Admin does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:group/devopsInline policy kms attached to group devops does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:group/devopsInline policy sai-devops attached to group devops does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy custommfa attached to group otherpermission does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy loggingaccess attached to group otherpermission does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleInline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:role/FlowLogsToCloudWatchInline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow '*:*' administrative privilegesarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow '*:*' administrative privileges.

Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover.

Remove Action:&#34;*&#34; with Resource:&#34;*&#34; from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants.

+•CISA: your-systems-3, your-surroundings-3 + +•SOC2: cc_1_3, cc_6_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.1 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: rr_1, rr_2, po_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7 + +•ISO27001-2022: A.5.18, A.8.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:group/AdminInline policy sai-admin attached to group Admin does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:group/devopsInline policy kms attached to group devops does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:group/devopsInline policy sai-devops attached to group devops does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy custommfa attached to group otherpermission does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy loggingaccess attached to group otherpermission does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleInline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:role/FlowLogsToCloudWatchInline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASShighiamus-east-2iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow 'cloudtrail:*' privilegesarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'cloudtrail:*' privileges.

Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations.

Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: po_1, ac_7 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:group/AdminInline policy sai-admin attached to group Admin does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:group/devopsInline policy kms attached to group devops does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:group/devopsInline policy sai-devops attached to group devops does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy custommfa attached to group otherpermission does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:group/otherpermissionInline policy loggingaccess attached to group otherpermission does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleInline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:role/FlowLogsToCloudWatchInline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'kms:*' privileges.

Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
+
+Impacts:
+- Confidentiality via unauthorized decryption
+- Integrity through key/grant tampering
+- Availability if keys are disabled or deleted, breaking encrypted workloads

Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:group/AdminInline policy sai-admin attached to group Admin does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:group/devopsInline policy kms attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:group/devopsInline policy sai-devops attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:group/otherpermissionInline policy custommfa attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:group/otherpermissionInline policy loggingaccess attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleInline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:role/FlowLogsToCloudWatchInline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
+- Scope Resource to exact role ARNs
+- Require MFA and, for third parties, ExternalId
+- Enforce permissions boundaries and SCPs to block wildcards
+- Regularly remove unused role-assumption rights and separate duties

+•CISA: your-systems-3, your-surroundings-3 + +•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
+- Scope Resource to exact role ARNs
+- Require MFA and, for third parties, ExternalId
+- Enforce permissions boundaries and SCPs to block wildcards
+- Regularly remove unused role-assumption rights and separate duties

+•CISA: your-systems-3, your-surroundings-3 + +•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
+- Scope Resource to exact role ARNs
+- Require MFA and, for third parties, ExternalId
+- Enforce permissions boundaries and SCPs to block wildcards
+- Regularly remove unused role-assumption rights and separate duties

+•CISA: your-systems-3, your-surroundings-3 + +•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom Policy scrivas-s3-storage-policy does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
+- Scope Resource to exact role ARNs
+- Require MFA and, for third parties, ExternalId
+- Enforce permissions boundaries and SCPs to block wildcards
+- Regularly remove unused role-assumption rights and separate duties

+•CISA: your-systems-3, your-surroundings-3 + +•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom Policy gitlab-ci-ecr-push does not allow permissive STS Role assumption.

Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane.

Apply least privilege to sts:AssumeRole:
+- Scope Resource to exact role ARNs
+- Require MFA and, for third parties, ExternalId
+- Enforce permissions boundaries and SCPs to block wildcards
+- Regularly remove unused role-assumption rights and separate duties

+•CISA: your-systems-3, your-surroundings-3 + +•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_no_root_access_keyRoot account has no active access keysarn:aws:iam::716468089330:rootRoot account does not have access keys.

Root access keys provide unrestricted API access. If exposed or misused, attackers can:
+- Turn off logging and alter policies (integrity)
+- Read or export data (confidentiality)
+- Delete resources and lock out admins (availability)
+Long-lived keys can persist and may bypass console-only MFA.

Delete and prohibit root access keys. Use IAM roles and temporary credentials with least privilege for all automation. Enable MFA on root, limit root to break-glass use, and continuously monitor for any new root keys. Where applicable, apply organization-wide controls to enforce this.

+•CISA: your-systems-3, your-surroundings-3 + +•CIS-7.0: 2.4 + +•CIS-1.4: 1.4 + +•CIS-1.5: 1.4 + +•MITRE-ATTACK: T1078, T1550 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.4 + +•ISO27001-2013: A.9.2.N, A.9.4.N + +•KISA-ISMS-P-2023: 2.5.5, 2.7.2, 2.10.2 + +•C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_312_a_2_i + +•CIS-2.0: 1.4 + +•KISA-ISMS-P-2023-korean: 2.5.5, 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.3 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6 + +•PCI-4.0: 7.2.1.17, 7.2.2.17, 7.2.3.8, 8.2.1.4, 8.2.2.6, 8.2.4.4, 8.2.5.4, 8.3.11.4 + +•NIST-800-53-Revision-4: ac_2, ac_3, ac_6_10, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_2, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2, ia_4_b, ia_4_4, ia_4_8, ia_5_8, mp_2, sc_23_3, sc_25 + +•AWS-Account-Security-Onboarding: Block root user + +•CIS-3.0: 1.4 + +•ENS-RD2022: op.acc.4.aws.iam.7 + +•CIS-6.0: 2.3 + +•AWS-Foundational-Technical-Review: ARC-004 + +•NIST-CSF-1.1: ac_1, ac_4, pt_3 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.Core.CN05.AR06, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.6 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-am-b-3, d3-pc-am-b-8 + +•ProwlerThreatScore-1.0: 1.1.13 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-04 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, ia-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3, ia-2 + +•CIS-4.0.1: 1.4 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_password_policy_expires_passwords_within_90_days_or_lessIAM account password policy enforces password expiration within 90 days or lessarn:aws:iam:us-east-2:716468089330:password-policyPassword expiration is not set.

Without rotation, stale passwords persist, enabling credential stuffing, brute force, and password reuse attacks. A compromised IAM user can retain console access, enabling data exfiltration, privilege escalation, and loss of confidentiality and integrity.

Enforce password rotation at &lt;= 90 days and prevent reuse. Pair with MFA, strong length/complexity, and prefer federation/SSO to reduce static passwords. Apply least privilege, monitor sign-ins, and remove inactive console passwords to limit exposure.

+•MITRE-ATTACK: T1078, T1110 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.A, A.9.3.A, A.9.4.A + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-08.03B, IAM-08.05B, PSS-07.01B + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06 + +•NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 8.3.6.1, 8.6.3.2 + +•ENS-RD2022: op.acc.6.aws.iam.3 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5 + +•ProwlerThreatScore-1.0: 1.1.12 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•NIS2: 1.1.1.d, 1.1.2, 9.2.c.v, 11.6.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILlowiamus-east-2iam_password_policy_lowercaseIAM password policy requires at least one lowercase letterarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy does not require at least one lowercase letter.

Without a lowercase requirement, passwords have reduced entropy, making brute force and password spraying more effective. Compromised IAM users can enable unauthorized access and changes, risking confidentiality, integrity, and availability of AWS resources.

Adopt a strong password policy that:
+- Enables Require at least one lowercase letter plus uppercase, number, and symbol
+- Sets sufficient length and blocks reuse
+- Requires MFA for all users
+- Applies least privilege to limit blast radius

+•CISA: your-systems-3, your-surroundings-4 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.F, A.9.3.F, A.9.4.F + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-08.03B, PSS-07.01B + +•HIPAA: 164_308_a_5_ii_d + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-800-171-Revision-2: 3_5_7 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 + +•ProwlerThreatScore-1.0: 1.1.8 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•NIS2: 9.2.c.v, 11.6.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_password_policy_minimum_length_14IAM password policy requires passwords to be at least 14 characters longarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy does not require minimum length of 14 characters.

Low minimum length reduces entropy, easing brute force and credential stuffing. Compromised IAM users enable console access, unauthorized changes, and lateral movement, leading to data exposure (confidentiality) and tampering (integrity).

Set the minimum password length to &gt;= 14 (prefer 16+).
+- Require mixed character types and prevent reuse
+- Enforce MFA for all console users
+- Prefer SSO over local IAM users
+- Apply least privilege and monitor authentication events

+•CISA: your-systems-3, your-surroundings-4 + +•CIS-7.0: 2.8 + +•CIS-1.4: 1.8 + +•CIS-1.5: 1.8 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.C, A.9.3.C, A.9.4.C + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-08.03B, PSS-07.01B + +•HIPAA: 164_308_a_5_ii_d + +•CIS-2.0: 1.8 + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.7 + +•NIST-800-171-Revision-2: 3_5_7 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_d_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, cm_12_b, ia_4_d, ia_5, ia_5_b, ia_5_c, ia_5_d, ia_5_f, ia_5_h, ia_5_1_f, ia_5_1_g, ia_5_1_h, ia_5_1_h, ia_5_18_a, ia_5_18_b, ia_8_2_b, ma_4_c, sc_23_3 + +•CIS-3.0: 1.8 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•CIS-6.0: 2.7 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5, 10.3 + +•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 + +•ProwlerThreatScore-1.0: 1.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-5-c, ia-2, ia-5-1-a-d-e, ia-5-4 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.8 + +•NIS2: 9.2.c.v + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_password_policy_numberIAM password policy requires at least one numberarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy does not require at least one number.

Passwords without numbers have lower entropy, making brute-force and credential-stuffing more effective. A compromised IAM user can gain console access, enabling data exposure (confidentiality), configuration changes (integrity), and resource abuse or deletion (availability).

Enforce the password policy option to require at least one number. Combine with strong length, mixed case, and symbols, and prevent reuse. Enable MFA for all users and prefer federated access to limit static credentials, supporting defense in depth against guessing attacks.

+•CISA: your-systems-3, your-surroundings-4 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.D, A.9.3.D, A.9.4.D + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B + +•HIPAA: 164_308_a_5_ii_d + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-800-171-Revision-2: 3_5_7 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5, 10.3 + +•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 + +•ProwlerThreatScore-1.0: 1.1.6 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•NIS2: 9.2.c.v + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_password_policy_reuse_24IAM password policy prevents reuse of the last 24 passwordsarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy reuse prevention is less than 24 or not set.

If fewer than 24 passwords are remembered, users can cycle back to recent secrets, undermining rotation. Attackers with previously exposed passwords can regain console access after a change, reducing confidentiality and integrity and increasing success of credential-stuffing with known credentials.

Set the password policy to remember 24 previous passwords to block reuse. Combine with MFA, strong length and complexity, and avoid rotation practices that encourage predictable patterns. Apply least privilege and monitor authentication events as part of defense in depth.

+•CIS-7.0: 2.9 + +•CIS-1.4: 1.9 + +•CIS-1.5: 1.9 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.B, A.9.3.B, A.9.4.B + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-01.03B, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-08.03B, IAM-08.05B, IAM-08.07B, PSS-07.01B + +•HIPAA: 164_308_a_4_ii_c, 164_308_a_5_ii_d, 164_312_d + +•CIS-2.0: 1.9 + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.8 + +•NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2, ia_2, ia_5_1, ia_5_4 + +•CIS-3.0: 1.9 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•CIS-6.0: 2.8 + +•AWS-Foundational-Technical-Review: IAM-003 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5 + +•RBI-Cyber-Security-Framework: annex_i_7_2 + +•PCI-3.2.1: 8.1, 8.1.4, 8.2, 8.2.3, 8.2.3.a, 8.2.3.b, 8.2.4, 8.2.4.a, 8.2.4.b, 8.2.5, 8.2.5.a, 8.2.5.b + +•ProwlerThreatScore-1.0: 1.1.5 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•CIS-4.0.1: 1.9 + +•NIS2: 9.2.c.v + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_password_policy_symbolIAM password policy requires at least one symbolarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy does not require at least one symbol.

Missing a symbol requirement lowers password entropy, increasing success of brute force and credential stuffing against console logins. A compromised IAM user can gain unauthorized access and modify resources, threatening confidentiality and integrity across the account.

Enforce the Require at least one non-alphanumeric character rule in the IAM password policy, alongside strong minimum length, mixed character sets, and password reuse prevention. Apply MFA for all human users and uphold least privilege to limit impact. Consider periodic rotation based on risk.

+•CISA: your-systems-3, your-surroundings-4 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.E, A.9.3.E, A.9.4.E + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-08.03B, PSS-07.01B + +•HIPAA: 164_308_a_5_ii_d + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-800-171-Revision-2: 3_5_7 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5, 10.3 + +•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 + +•ProwlerThreatScore-1.0: 1.1.7 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•NIS2: 9.2.c.v + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_password_policy_uppercaseIAM password policy requires at least one uppercase letterarn:aws:iam:us-east-2:716468089330:password-policyIAM password policy does not require at least one uppercase letter.

Without an uppercase requirement, passwords have lower entropy, enabling brute force, credential stuffing, and offline cracking. Compromised IAM users can access the console, threatening confidentiality (data exposure), integrity (unauthorized changes), and availability (resource deletion).

Enable the uppercase rule within a strong password policy that also requires length, lowercase, numbers, and symbols. Pair with MFA and least privilege to reduce blast radius. Regularly review policy effectiveness and prefer federated SSO to minimize long-lived IAM passwords.

+•CISA: your-systems-3, your-surroundings-4 + +•MITRE-ATTACK: T1078, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10 + +•ISO27001-2013: A.9.2.G, A.9.3.G, A.9.4.G + +•KISA-ISMS-P-2023: 2.5.4, 2.10.2 + +•C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B + +•HIPAA: 164_308_a_5_ii_d + +•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-800-171-Revision-2: 3_5_7 + +•ENS-RD2022: op.acc.6.r1.aws.iam.1 + +•AWS-Foundational-Technical-Review: IAM-003 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7 + +•ProwlerThreatScore-1.0: 1.1.9 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-06 + +•NIS2: 9.2.c.v + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom Policy arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
+- Confidentiality via unauthorized data access/exfiltration
+- Integrity by modifying policies, configs, or logs
+- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
+- Avoid wildcards in Action and Resource
+- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
+- Use conditions like iam:PassedToService and tags to constrain use
+- Enforce permissions boundaries and SCPs
+- Separate duties with change review

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 11.2.2.a +

PASShighiamus-east-2iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom Policy arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
+- Confidentiality via unauthorized data access/exfiltration
+- Integrity by modifying policies, configs, or logs
+- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
+- Avoid wildcards in Action and Resource
+- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
+- Use conditions like iam:PassedToService and tags to constrain use
+- Enforce permissions boundaries and SCPs
+- Separate duties with change review

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 11.2.2.a +

PASShighiamus-east-2iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom Policy arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
+- Confidentiality via unauthorized data access/exfiltration
+- Integrity by modifying policies, configs, or logs
+- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
+- Avoid wildcards in Action and Resource
+- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
+- Use conditions like iam:PassedToService and tags to constrain use
+- Enforce permissions boundaries and SCPs
+- Separate duties with change review

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 11.2.2.a +

PASShighiamus-east-2iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom Policy arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
+- Confidentiality via unauthorized data access/exfiltration
+- Integrity by modifying policies, configs, or logs
+- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
+- Avoid wildcards in Action and Resource
+- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
+- Use conditions like iam:PassedToService and tags to constrain use
+- Enforce permissions boundaries and SCPs
+- Separate duties with change review

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 11.2.2.a +

PASShighiamus-east-2iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom Policy arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push does not allow privilege escalation.

Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
+- Confidentiality via unauthorized data access/exfiltration
+- Integrity by modifying policies, configs, or logs
+- Availability through resource deletion or disabling controls

Apply least privilege to customer policies:
+- Avoid wildcards in Action and Resource
+- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
+- Use conditions like iam:PassedToService and tags to constrain use
+- Enforce permissions boundaries and SCPs
+- Separate duties with change review

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-06.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 11.2.2.a +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/aksinyaUser aksinya has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/AzamatUser Azamat has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/DilbagUser Dilbag has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/VasiliiUser Vasilii has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesarn:aws:iam::716468089330:user/YegorUser Yegor has no inline or attached policies.

Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability.

Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access.

+•CIS-7.0: 2.13 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.15 + +•CIS-1.5: 1.15 + +•ISO27001-2013: A.9.2.I, A.9.4.I + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC + +•CIS-2.0: 1.15 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.14 + +•NIST-800-171-Revision-2: 3_4_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.15 + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•CIS-6.0: 2.14 + +•AWS-Foundational-Technical-Review: IAM-006, IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.1 + +•RBI-Cyber-Security-Framework: annex_i_7_1 + +•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7 + +•ProwlerThreatScore-1.0: 1.2.1, 1.2.2 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.15 + +•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_policy_cloudshell_admin_not_attachedNo IAM users, groups, or roles have the AWSCloudShellFullAccess policy attachedarn:aws:iam::aws:policy/AWSCloudShellFullAccessAWS CloudShellFullAccess policy is not attached to any IAM entity.

Granting cloudshell:* enables an interactive shell with Internet egress and file upload/download, degrading confidentiality and integrity.
+
+Compromised principals can exfiltrate data, stage tooling with sudo, persist artifacts in CloudShell, and operate from AWS IP space to bypass endpoint controls.

Detach AWSCloudShellFullAccess from identities.
+
+Apply least privilege: permit CloudShell only when necessary via narrowly scoped permissions, restricted roles, short-lived sessions, and approvals. Prefer controlled alternatives (local CLI, bastion, or Session Manager). Enforce separation of duties and monitor usage.

+•CIS-7.0: 2.20 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-02.01B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B + +•CIS-2.0: 1.22 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•CIS-5.0: 1.21 + +•PCI-4.0: 7.2.1.14, 7.2.1.15, 7.2.1.16, 7.2.2.14, 7.2.2.15, 7.2.2.16, 7.2.3.7, 7.2.5.10, 7.2.5.11, 7.2.5.12, 7.3.1.10, 7.3.1.11, 7.3.1.12, 7.3.2.10, 7.3.2.11, 7.3.2.12, 7.3.3.10, 7.3.3.11, 7.3.3.12, 8.2.7.10, 8.2.7.11, 8.2.7.12, 8.2.8.12, 8.2.8.13, 8.2.8.14, 8.3.4.10, 8.3.4.11, 8.3.4.12 + +•CIS-6.0: 2.21 + +•ProwlerThreatScore-1.0: 1.3.2 + +•CIS-4.0.1: 1.22 + +•NIS2: 1.2.1 +

PASSmediumiamus-east-2iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
+
+This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.
+
+Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

+•SOC2: cc_3_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
+
+This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.
+
+Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

+•SOC2: cc_3_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
+
+This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.
+
+Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

+•SOC2: cc_3_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom Policy scrivas-s3-storage-policy does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
+
+This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.
+
+Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

+•SOC2: cc_3_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom Policy gitlab-ci-ecr-push does not allow 'cloudtrail:*' privileges.

Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
+
+This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection.

Apply least privilege: avoid cloudtrail:* and allow only required actions.
+
+Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes.

+•SOC2: cc_3_3 + +•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: IAM-10.01B, SIM-03.07B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•ENS-RD2022: op.exp.8.r4.aws.ct.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_kmsCustom IAM policy does not allow 'kms:*' privilegesarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
+- Replace kms:* with only needed actions scoped to specific key ARNs
+- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
+- Monitor KMS usage and refine access based on activity

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 + +•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_kmsCustom IAM policy does not allow 'kms:*' privilegesarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
+- Replace kms:* with only needed actions scoped to specific key ARNs
+- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
+- Monitor KMS usage and refine access based on activity

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 + +•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_kmsCustom IAM policy does not allow 'kms:*' privilegesarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
+- Replace kms:* with only needed actions scoped to specific key ARNs
+- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
+- Monitor KMS usage and refine access based on activity

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 + +•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_kmsCustom IAM policy does not allow 'kms:*' privilegesarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom Policy scrivas-s3-storage-policy does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
+- Replace kms:* with only needed actions scoped to specific key ARNs
+- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
+- Monitor KMS usage and refine access based on activity

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 + +•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_full_access_to_kmsCustom IAM policy does not allow 'kms:*' privilegesarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom Policy gitlab-ci-ecr-push does not allow 'kms:*' privileges.

Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation.

Adopt least privilege and separation of duties:
+- Replace kms:* with only needed actions scoped to specific key ARNs
+- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
+- Monitor KMS usage and refine access based on activity

+•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5 + +•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01 + +•NIS2: 11.2.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:policy/scrivas-s3-storage-policyCustom Policy scrivas-s3-storage-policy does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow 'aws-marketplace:Subscribe' on all resourcesarn:aws:iam::716468089330:policy/gitlab-ci-ecr-pushCustom Policy gitlab-ci-ecr-push does not allow 'aws-marketplace:Subscribe' on all resources.

Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments.

Replace Resource: &#34;*&#34; with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products.

+•CISA: your-surroundings-3 + +•SOC2: cc_6_3 + +•KISA-ISMS-P-2023: 2.5.5 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•HIPAA: 164_308_a_4_ii_b + +•KISA-ISMS-P-2023-korean: 2.5.5 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02 + +•NIST-CSF-2.0: ac_4 + +•NIST-800-171-Revision-2: 3_1_5 + +•NIST-800-53-Revision-4: ac_6 + +•NIST-800-53-Revision-5: ac_6 + +•NIST-CSF-1.1: ac_4 + +•FFIEC: d3-pc-am-b-1 + +•ISO27001-2022: A.5.18, A.8.2 + +•FedRamp-Moderate-Revision-4: ac-6 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsarn:aws:iam::716468089330:role/aws-service-role/config.amazonaws.com/AWSServiceRoleForConfigIAM Role AWSServiceRoleForConfig accessed Bedrock 0 days ago (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsarn:aws:iam::716468089330:role/aws-service-role/resource-explorer-2.amazonaws.com/AWSServiceRoleForResourceExplorerIAM Role AWSServiceRoleForResourceExplorer accessed Bedrock 1 days ago (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsarn:aws:iam::716468089330:role/aws-service-role/support.amazonaws.com/AWSServiceRoleForSupportIAM Role AWSServiceRoleForSupport has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsarn:aws:iam::716468089330:role/IntruderReadOnlyRoleIAM Role IntruderReadOnlyRole has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008IAM Role SecureframeRole-f983f1e89008 has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASShighiamus-east-2iam_role_administratoraccess_policyIAM role does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRoleIAM Role AmazonEKS_EBS_CSI_DriverRole does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
+
+Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 1.2.1, 11.3.1 +

PASShighiamus-east-2iam_role_administratoraccess_policyIAM role does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:role/IntruderReadOnlyRoleIAM Role IntruderReadOnlyRole does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
+
+Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 1.2.1, 11.3.1 +

PASShighiamus-east-2iam_role_administratoraccess_policyIAM role does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008IAM Role SecureframeRole-f983f1e89008 does not have AdministratorAccess policy.

Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover.

Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
+
+Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 + +•NIS2: 1.2.1, 11.3.1 +

PASShighiamus-east-2iam_role_cross_account_readonlyaccess_policyIAM role does not grant ReadOnlyAccess to external AWS accountsarn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRoleIAM Role AmazonEKS_EBS_CSI_DriverRole does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_2, am_6, ac_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 +

PASShighiamus-east-2iam_role_cross_account_readonlyaccess_policyIAM role does not grant ReadOnlyAccess to external AWS accountsarn:aws:iam::716468089330:role/IntruderReadOnlyRoleIAM Role IntruderReadOnlyRole does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_2, am_6, ac_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 +

PASShighiamus-east-2iam_role_cross_account_readonlyaccess_policyIAM role does not grant ReadOnlyAccess to external AWS accountsarn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008IAM Role SecureframeRole-f983f1e89008 does not have ReadOnlyAccess policy.

Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths.

Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_2, am_6, ac_6 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 +

PASShighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/AmazonEKSAutoClusterRoleIAM Service Role AmazonEKSAutoClusterRole prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/AmazonEKSAutoNodeRoleIAM Service Role AmazonEKSAutoNodeRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonEBSCSIDriverRoleIAM Service Role AmazonEKSPodIdentityAmazonEBSCSIDriverRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonVPCCNIRoleIAM Service Role AmazonEKSPodIdentityAmazonVPCCNIRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/applications-eks-node-group-20251007184911320300000008 +•Environment=scrivas-staging + +•Architecture=x64 + +•ManagedBy=terraform + +•Repository=devops-terraform + +•Service=applications + +•Purpose=workloads +IAM Service Role applications-eks-node-group-20251007184911320300000008 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/service-role/AWSSystemsManagerDefaultEC2InstanceManagementRoleIAM Service Role AWSSystemsManagerDefaultEC2InstanceManagementRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

PASShighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/service-role/CloudTrailRoleForCloudWatchLogs_MainTrailIAM Service Role CloudTrailRoleForCloudWatchLogs_MainTrail prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/EC2-CloudWatchAgent-RoleIAM Service Role EC2-CloudWatchAgent-Role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/EC2-SSM-AccessIAM Service Role EC2-SSM-Access does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/EC2SSMRole +•scrivas= +IAM Service Role EC2SSMRole does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/FlowLogsToCloudWatchIAM Service Role FlowLogsToCloudWatch does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/gpu-eks-node-group-20251007184911320100000007 +•Architecture=x64 + +•Service=gpu + +•Environment=scrivas-staging + +•ManagedBy=terraform + +•Repository=devops-terraform + +•Purpose=ml-workloads +IAM Service Role gpu-eks-node-group-20251007184911320100000007 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/infrastructure-eks-node-group-20251007184911319500000006 +•Environment=scrivas-staging + +•Service=infrastructure + +•ManagedBy=terraform + +•Repository=devops-terraform + +•Architecture=x64 + +•Purpose=infrastructure +IAM Service Role infrastructure-eks-node-group-20251007184911319500000006 does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/rds-monitoring-roleIAM Service Role rds-monitoring-role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

PASShighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001IAM Service Role scrivas-staging-cluster-20251007184855668200000001 prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/vpc-flow-logs-roleIAM Service Role vpc-flow-logs-role does not prevent against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

PASShighiamus-east-2iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackarn:aws:iam::716468089330:role/service-role/VPCFlowLogs-Cloudwatch-1781174191538IAM Service Role VPCFlowLogs-Cloudwatch-1781174191538 prevents against a cross-service confused deputy attack.

Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
+This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity.

Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly.

+•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04 + +•ASD-Essential-Eight-Nov 2023: E8-4.4 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1 + +•AWS-Foundational-Technical-Review: IAM-0012 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•NIS2: 3.1.2.c, 6.8.2.a +

FAILhighiamus-east-2iam_root_credentials_management_enabledAWS Organization has centralized root credentials management enabledarn:aws:iam::716468089330:rootRoot credentials management is not enabled.

Without central control, member accounts can retain or recover long-term root credentials, weakening confidentiality and integrity.
+
+Threats include:
+- Account takeover via root email recovery
+- Persistent access through root keys
+- Unfixable lockouts from misconfigured policies
+- Bypass of separation of duties

Enable centralized root access with root credentials management and assign a delegated administrator.
+
+Apply least privilege and separation of duties by deleting long-term root credentials in members, limiting privileged tasks to short-lived sessions, enforcing MFA, and auditing root-related activity for defense in depth.

+•CIS-7.0: 2.1.1 + +•C5-2025: IAM-03.01B, IAM-08.02B + +•NIST-CSF-2.0: rr_1, rr_2, po_4, ac_1 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN05.AR06 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-04 +

FAILcriticaliamus-east-2iam_root_hardware_mfa_enabledRoot account has a hardware MFA device enabledarn:aws:iam::716468089330:mfaRoot account has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA on the root user:
+- No MFA: stolen password/keys enable full account takeover.
+- Virtual MFA: device compromise or backup restoration weakens second-factor assurance.
+An attacker could delete resources, change policies, and disable logging, harming confidentiality, integrity, and availability.

Require a hardware MFA token for the root user and remove any virtual MFA. Apply least privilege: avoid using root, disable access keys, and eliminate long-term credentials. In organizations, centralize root management. Keep a controlled break-glass process with strict recovery checks and continuous monitoring.

+•CISA: your-systems-3, your-surroundings-2 + +•CIS-7.0: 2.6 + +•CIS-1.4: 1.6 + +•CIS-1.5: 1.6 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.6 + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_d + +•CIS-2.0: 1.6 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 + +•CIS-5.0: 1.5 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•PCI-4.0: 8.4.1.3, 8.4.2.3, 8.4.3.3 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•AWS-Account-Security-Onboarding: Root user - distribution email + MFA + +•CIS-3.0: 1.6 + +•ENS-RD2022: op.acc.6.r4.aws.iam.1 + +•CIS-6.0: 2.5 + +•AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.2 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.6 + +•NIS2: 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASScriticaliamus-east-2iam_root_mfa_enabledRoot account has MFA enabledarn:aws:iam::716468089330:rootMFA is enabled for root account.

Without MFA, compromise of the root password or access keys can lead to full account takeover. An attacker with root can disable protections, steal or delete data, change billing, and create persistent admins, undermining confidentiality, integrity, and availability.

Enable MFA for the root user, preferably hardware-based or a dedicated, managed device. Remove root access keys and avoid using root for daily tasks. Apply least privilege with IAM Identity Center for admins, and use Organizations to centralize root access and eliminate long-lived root credentials.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.5 + +•CIS-1.4: 1.5 + +•CIS-1.5: 1.5 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•GDPR: article_25 + +•ISO27001-2013: A.9.2.K, A.9.4.K + +•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-05.02B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_d + +•CIS-2.0: 1.5 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02 + +•NIST-CSF-2.0: rr_1, po_4, ac_1, ac_6, ac_7, ip_1 + +•CIS-5.0: 1.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.4, 8.4.2.4, 8.4.3.4 + +•NIST-800-53-Revision-4: ac_2, ia_2_1, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•AWS-Account-Security-Onboarding: Root user - distribution email + MFA + +•CIS-3.0: 1.5 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1 + +•CIS-6.0: 2.4 + +•AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.1 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.5 + +•NIS2: 11.3.2.a, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:rootUser <root_account> does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has not rotated access key 1 in over 90 days (322 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has not rotated access key 2 in over 90 days (319 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/aksinyaUser aksinya does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/AzamatUser Azamat does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/DilbagUser Dilbag does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have access keys older than 90 days.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has not rotated access key 1 in over 90 days (316 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis does not have access keys older than 90 days.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user has not rotated access key 1 in over 90 days (161 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/VasiliiUser Vasilii has not rotated access key 1 in over 90 days (147 days).

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysarn:aws:iam::716468089330:user/YegorUser Yegor does not have access keys.

Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations.

Apply least privilege and limit static credentials:
+- Rotate active access keys at or before 90 days
+- Prefer IAM roles with short-lived tokens
+- Maintain only one active key during rotation; delete the old one
+- Monitor last_used and remove dormant keys
+- Automate alerts and periodic reviews of key age

+•CISA: your-systems-3 + +•CIS-7.0: 2.12 + +•CIS-1.4: 1.14 + +•CIS-1.5: 1.14 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.3 + +•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B + +•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.14 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05 + +•NIST-CSF-2.0: ac_6 + +•CIS-5.0: 1.13 + +•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1 + +•NIST-800-53-Revision-4: ac_2_1, ac_2 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3 + +•CIS-3.0: 1.14 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3 + +•CIS-6.0: 2.13 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.IAM.CN06.AR01 + +•SecNumCloud-3.2: 9.4 + +•FFIEC: d3-pc-am-b-6 + +•ProwlerThreatScore-1.0: 1.1.11 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j + +•FedRAMP-Low-Revision-4: ac-2 + +•CIS-4.0.1: 1.14 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSlowiamus-east-2iam_securityaudit_role_createdAt least one IAM role has the SecurityAudit AWS managed policy attachedarn:aws:iam::aws:policy/SecurityAuditSecurityAudit policy attached to role IntruderReadOnlyRole.

Without a dedicated read-only audit role, security teams lack safe visibility into configs and logs, enabling undetected misconfigurations, slower incident triage, and reliance on over-privileged access. This erodes confidentiality and integrity by letting exposure persist unnoticed.

Establish a dedicated audit role and attach the AWS managed SecurityAudit policy. Enforce least privilege and separation of duties: restrict who can assume it, require MFA, monitor usage, and avoid write permissions. Prefer federated access and regularly review and rotate access.

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-02.01B, OIS-02.02B, OIS-04.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-05.02B, IAM-06.06B, DEV-15.01B, SIM-01.02B, SIM-01.03B, COM-02.02B, COM-03.02B, INQ-02.01B, PSS-09.01AC + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•ENS-RD2022: op.acc.3.r2.aws.iam.1 + +•ISO27001-2022: A.5.3 + +•NIS2: 1.2.4, 2.1.1, 2.1.2.a, 2.1.2.e, 2.1.2.f, 2.2.1, 2.3.1, 3.1.2.c, 3.1.3, 6.2.2.a, 7.2.d, 7.2.e, 7.2.f +

FAILlowiamus-east-2iam_support_role_createdAt least one IAM role has the AWSSupportAccess managed policy attachedarn:aws:iam::aws:policy/AWSSupportAccessAWS Support Access policy is not attached to any role.

Without a dedicated support role:
+- Case creation and escalation can be delayed, prolonging outages (availability)
+- Teams may use admin/root, increasing blast radius (confidentiality/integrity)
+- Audit trails of support actions are weaker, hindering investigations

Create a dedicated IAM role for AWS Support with AWSSupportAccess and:
+- Restrict who can assume it; require MFA and time-bound access
+- Enforce least privilege and separation of duties
+- Monitor usage via audit logs and review assignments regularly

+•CIS-7.0: 2.15 + +•CIS-1.4: 1.17 + +•CIS-1.5: 1.17 + +•GDPR: article_25 + +•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1 + +•C5-2025: OIS-02.01B, OIS-02.02B, HR-04.01B, OPS-13.02B, OPS-13.03AC, OPS-17.02B, OPS-24.01B, OPS-24.02B, IAM-01.01B, IAM-01.04B, IAM-06.06B, DEV-15.01B, SSO-05.06B, SIM-01.02B, SIM-01.03B + +•CIS-2.0: 1.17 + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC10-BP01 + +•CIS-5.0: 1.16 + +•AWS-Account-Security-Onboarding: Predefine IAM Roles + +•CIS-3.0: 1.17 + +•ENS-RD2022: op.acc.3.r1.aws.iam.1 + +•CIS-6.0: 2.16 + +•ProwlerThreatScore-1.0: 1.2.3 + +•CIS-4.0.1: 1.17 + +•NIS2: 2.1.1, 2.1.2.a, 2.2.1, 3.1.2.d, 4.3.2.a, 5.1.7.b +

FAILmediumiamus-east-2iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +IAM User admin has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsarn:aws:iam::716468089330:user/aksinyaIAM User aksinya has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsarn:aws:iam::716468089330:user/DilbagIAM User Dilbag has not accessed Bedrock in 106 days (threshold: 60 days).

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +IAM User igor@devteamspace.com has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +IAM User louis has Bedrock permissions but has never used them.

Stale Bedrock permissions widen the blast radius of a credential compromise.
+
+An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns.

Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
+
+Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface.

+•MITRE-ATTACK: T1078 + +•ISO27001-2013: A.9.2.M + +•C5-2025: IAM-03.02B, IAM-10.01B + +•NIST-CSF-2.0: ac_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6 + +•ENS-RD2022: op.acc.6.r7.aws.iam.1 + +•NIST-CSF-1.1: ac_1, ac_4 + +•SecNumCloud-3.2: 9.2, 9.4 + +•PCI-3.2.1: 8.1.4 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-05 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:rootUser <root_account> does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has not used access key 1 in the last 45 days (294 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has not used access key 2 in the last 45 days (318 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/aksinyaUser aksinya does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/AzamatUser Azamat does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/DilbagUser Dilbag does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has not used access key 1 in the last 45 days (292 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user has not used access key 1 in the last 45 days (154 days).

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/VasiliiUser Vasilii does not have unused access keys for 45 days.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysarn:aws:iam::716468089330:user/YegorUser Yegor does not have access keys.

Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes.

Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +IAM User admin does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/aksinyaIAM User aksinya does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/AzamatIAM User Azamat does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/DilbagIAM User Dilbag does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +IAM User gitlab-ci-ecr-push does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +IAM User igor@devteamspace.com does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +IAM User louis does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +IAM User scrivas-storage-user does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/VasiliiIAM User Vasilii does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

PASScriticaliamus-east-2iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedarn:aws:iam::716468089330:user/YegorIAM User Yegor does not have AdministratorAccess policy.

Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
+- Confidentiality: read/export all data
+- Integrity: change configs, policies, code
+- Availability: delete resources, disrupt services
+Also enables persistence and uncontrolled spend.

Remove direct AdministratorAccess from users.
+- Apply least privilege with scoped policies
+- Use federation and roles for temporary admin access
+- Enforce separation of duties and approvals
+- Add guardrails (SCPs, permissions boundaries)
+- Require MFA and rotate any remaining long-lived credentials

+•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B + +•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2 + +•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-02 +

FAILmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has not logged in to the console in the past 45 days (113 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/aksinyaUser aksinya has not logged in to the console in the past 45 days (98 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/AzamatUser Azamat has logged in to the console in the past 45 days (2 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/DilbagUser Dilbag has logged in to the console in the past 45 days (2 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have console access enabled or is unused.

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has not logged in to the console in the past 45 days (289 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis has logged in to the console in the past 45 days (-1 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user does not have console access enabled or is unused.

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/VasiliiUser Vasilii has logged in to the console in the past 45 days (0 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

PASSmediumiamus-east-2iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedarn:aws:iam::716468089330:user/YegorUser Yegor has logged in to the console in the past 45 days (1 days).

Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability.

Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials.

+•CISA: your-systems-3 + +•CIS-7.0: 2.11 + +•SOC2: cc_1_3 + +•CIS-1.4: 1.12 + +•CIS-1.5: 1.12 + +•MITRE-ATTACK: T1078, T1550, T1110 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26 + +•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B + +•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d + +•CIS-2.0: 1.12 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•NIST-CSF-2.0: ac_1 + +•CIS-5.0: 1.11 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6 + +•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3 + +•CIS-3.0: 1.12 + +•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1 + +•CIS-6.0: 2.11 + +•NIST-CSF-1.1: ac_1, ac_4 + +•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01 + +•SecNumCloud-3.2: 9.2, 9.4 + +•FFIEC: d3-pc-am-b-6 + +•PCI-3.2.1: 8.1, 8.1.4 + +•ProwlerThreatScore-1.0: 1.1.10 + +•ISO27001-2022: A.5.15 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6 + +•FedRAMP-Low-Revision-4: ac-2, ac-3 + +•CIS-4.0.1: 1.12 + +•NIS2: 11.3.2.d, 11.5.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07 +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/aksinyaUser aksinya has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/AzamatUser Azamat has hardware MFA enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/DilbagUser Dilbag has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have any type of MFA enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user does not have any type of MFA enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/VasiliiUser Vasilii has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledarn:aws:iam::716468089330:user/YegorUser Yegor has a virtual MFA instead of a hardware MFA device enabled.

Without hardware MFA, authentication is weaker:
+- SIM-swap can bypass SMS
+- Phishing can steal TOTP from virtual apps
+- No MFA allows password-only takeover
+This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A).

Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity.

+•CISA: booting-up-thing-to-do-first-2 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.6 + +•ISO27001-2022: A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRAMP-Low-Revision-4: ac-2 + +•NIS2: 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/aksinyaUser aksinya has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/AzamatUser Azamat has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/DilbagUser Dilbag has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have Console Password enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user does not have Console Password enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/VasiliiUser Vasilii has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASShighiamus-east-2iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setarn:aws:iam::716468089330:user/YegorUser Yegor has Console Password enabled and MFA enabled.

Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability.

Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes.

+•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2 + +•CIS-7.0: 2.10 + +•CIS-1.4: 1.10 + +•CIS-1.5: 1.10 + +•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538 + +•GDPR: article_25 + +•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19 + +•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B + +•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d + +•CIS-2.0: 1.10 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_7 + +•CIS-5.0: 1.9 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3 + +•ASD-Essential-Eight-Nov 2023: E8-3.1 + +•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2 + +•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3 + +•CIS-3.0: 1.10 + +•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1 + +•CIS-6.0: 2.9 + +•AWS-Foundational-Technical-Review: IAM-001, IAM-0012 + +•NIST-CSF-1.1: ac_3, ac_7 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3 + +•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06 + +•SecNumCloud-3.2: 9.5 + +•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6 + +•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c + +•ProwlerThreatScore-1.0: 1.1.3 + +•ISO27001-2022: A.5.15, A.5.17, A.8.5 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-01 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1 + +•FedRAMP-Low-Revision-4: ac-2, ia-2 + +•CIS-4.0.1: 1.10 + +•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:rootUser <root_account> does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/aksinyaUser aksinya does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/AzamatUser Azamat does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/DilbagUser Dilbag does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/VasiliiUser Vasilii does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedarn:aws:iam::716468089330:user/YegorUser Yegor does not have access keys or uses the access keys configured.

Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation.

Apply least privilege to programmatic access:
+- Do not provision access keys by default for console users
+- Prefer IAM roles and temporary credentials
+- Require justification and time-bounded key creation
+- Regularly review usage and disable/delete unused keys
+- Limit to one active key per user and enforce rotation with monitoring

+•CIS-1.4: 1.11 + +•CIS-1.5: 1.11 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B + +•CIS-2.0: 1.11 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•CIS-5.0: 1.1 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.11 + +•ENS-RD2022: op.acc.6.aws.iam.4 + +•CIS-6.0: 2.10 + +•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.11 + +•NIS2: 9.2.c, 9.2.c.iii +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:rootUser <root_account> does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/aksinyaUser aksinya does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/AzamatUser Azamat does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/DilbagUser Dilbag does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/VasiliiUser Vasilii does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

PASSmediumiamus-east-2iam_user_two_active_access_keyIAM user has at most one active access keyarn:aws:iam::716468089330:user/YegorUser Yegor does not have 2 active access keys.

Two active keys per user widen exposure and weaken credential governance.
+- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
+- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed

Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys.

+•CIS-1.4: 1.13 + +•CIS-1.5: 1.13 + +•MITRE-ATTACK: T1078, T1550 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-10.01B, CRY-03.01B + +•CIS-2.0: 1.13 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01 + +•NIST-CSF-2.0: ac_1, ac_6 + +•CIS-5.0: 1.12 + +•ASD-Essential-Eight-Nov 2023: E8-4.2 + +•CIS-3.0: 1.13 + +•ENS-RD2022: op.acc.6.aws.iam.1 + +•CIS-6.0: 2.12 + +•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02 + +•SecNumCloud-3.2: 9.3 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 + +•CIS-4.0.1: 1.13 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/admin +•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation + +•AKIA2NUGTOHZBDLCH7XN=sai + +•AKIA2NUGTOHZO45UBFNB=aksinya +User admin has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

PASShighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/aksinyaUser aksinya doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

PASShighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/AzamatUser Azamat doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

PASShighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/DilbagUser Dilbag doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/gitlab-ci-ecr-push +•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr +User gitlab-ci-ecr-push has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/igor@devteamspace.com +•AKIA2NUGTOHZPMTQ6YNU=LocalComputer +User igor@devteamspace.com has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/louis +•AKIA2NUGTOHZGJX4RESB=Review Key +User louis has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/scrivas-storage-user +•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access +User scrivas-storage-user has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

FAILhighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/VasiliiUser Vasilii has long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

PASShighiamus-east-2iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSarn:aws:iam::716468089330:user/YegorUser Yegor doesn't have long lived credentials with access to other services than IAM or STS.

Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder.

Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius.

+•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•NIST-CSF-2.0: ac_6 + +•AWS-Foundational-Technical-Review: IAM-002, IAM-0012 + +•AWS-AI-Security-Framework-1.0: AISF-IAM-03 +

PASShighinspector2us-east-1inspector2_active_findings_existInspector2 is enabled with no active findingsarn:aws:inspector2:us-east-1:716468089330:inspector2Inspector2 is enabled with no active findings.

Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.
+
+This enables:
+- Unauthorized access and data exfiltration (C)
+- Code tampering and privilege escalation (I)
+- Service disruption via exploitation or malware (A)

Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.
+
+Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention.

+•MITRE-ATTACK: T1190, T1562, T1110, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: AM-09.04AC, OPS-04.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ov_2, ip_7, ip_12 + +•ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 + +•AWS-Foundational-Technical-Review: SECOPS-001 + +•SecNumCloud-3.2: 12.11 + +•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr +

FAILhighinspector2us-east-2inspector2_active_findings_existInspector2 is enabled with no active findingsarn:aws:inspector2:us-east-2:716468089330:inspector2There are active Inspector2 findings.

Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.
+
+This enables:
+- Unauthorized access and data exfiltration (C)
+- Code tampering and privilege escalation (I)
+- Service disruption via exploitation or malware (A)

Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.
+
+Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention.

+•MITRE-ATTACK: T1190, T1562, T1110, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: AM-09.04AC, OPS-04.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•NIST-CSF-2.0: ov_2, ip_7, ip_12 + +•ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5 + +•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR + +•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 + +•AWS-Foundational-Technical-Review: SECOPS-001 + +•SecNumCloud-3.2: 12.11 + +•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr +

PASSmediuminspector2us-east-1inspector2_is_enabledInspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda codearn:aws:inspector2:us-east-1:716468089330:inspector2Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code.

Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.
+
+Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability.

Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.
+
+Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings.

+•MITRE-ATTACK: T1190, T1562, T1110, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2 + +•C5-2025: OPS-32.01B, PSS-11.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2 + +•NIST-CSF-2.0: ip_7, ip_12, cm_1 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4 + +•AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR + +•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 + +•AWS-Foundational-Technical-Review: SECOPS-001 + +•SecNumCloud-3.2: 12.11, 14.6, 18.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07 +

PASSmediuminspector2us-east-2inspector2_is_enabledInspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda codearn:aws:inspector2:us-east-2:716468089330:inspector2Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code.

Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.
+
+Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability.

Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.
+
+Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings.

+•MITRE-ATTACK: T1190, T1562, T1110, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2 + +•C5-2025: OPS-32.01B, PSS-11.01B + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2 + +•NIST-CSF-2.0: ip_7, ip_12, cm_1 + +•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4 + +•AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR + +•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1 + +•AWS-Foundational-Technical-Review: SECOPS-001 + +•SecNumCloud-3.2: 12.11, 14.6, 18.4 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07 +

PASSlowkmsus-east-2kms_cmk_are_usedKMS customer managed key is enabled or scheduled for deletionarn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6dKMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is being used.

Keeping unused CMKs increases attack surface and cost.
+
+If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability.

Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.
+
+Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01 + +•CCC-v2025.10: CCC.Core.CN11.AR03 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.5, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 +

PASSlowkmsus-east-2kms_cmk_are_usedKMS customer managed key is enabled or scheduled for deletionarn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is being used.

Keeping unused CMKs increases attack surface and cost.
+
+If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability.

Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.
+
+Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01 + +•CCC-v2025.10: CCC.Core.CN11.AR03 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.5, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 +

PASScriticalkmsus-east-2kms_cmk_not_deleted_unintentionallyAWS KMS customer managed key is not scheduled for deletionarn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6dKMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not scheduled for deletion.

A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window.

Prevent unintended deletion:
+- Enforce least privilege and separation of duties for key admins
+- Require change approvals and alerts on deletion events
+- Prefer disabling unused keys over deleting
+- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization

+•AWS-Foundational-Security-Best-Practices: KMS.3 + +•KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1 + +•C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1 + +•NIST-CSF-2.0: ra_1, ds_3 + +•PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 +

PASScriticalkmsus-east-2kms_cmk_not_deleted_unintentionallyAWS KMS customer managed key is not scheduled for deletionarn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not scheduled for deletion.

A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window.

Prevent unintended deletion:
+- Enforce least privilege and separation of duties for key admins
+- Require change approvals and alerts on deletion events
+- Prefer disabling unused keys over deleting
+- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization

+•AWS-Foundational-Security-Best-Practices: KMS.3 + +•KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1 + +•C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1 + +•NIST-CSF-2.0: ra_1, ds_3 + +•PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22 + +•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 +

PASSmediumkmsus-east-2kms_cmk_not_multi_regionAWS KMS customer managed key is single-Regionarn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6dKMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is a single-region key.

Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability.

Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary.

+•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC + +•NIST-CSF-2.0: ra_1 + +•ISO27001-2022: A.8.11, A.8.24 +

PASSmediumkmsus-east-2kms_cmk_not_multi_regionAWS KMS customer managed key is single-Regionarn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is a single-region key.

Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability.

Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary.

+•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC + +•NIST-CSF-2.0: ra_1 + +•ISO27001-2022: A.8.11, A.8.24 +

FAILhighkmsus-east-2kms_cmk_rotation_enabledKMS customer-managed symmetric CMK has automatic rotation enabledarn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6dKMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d has automatic rotation disabled.

Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies.

Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected.

+•CISA: your-systems-3 + +•CIS-7.0: 4.6 + +•SOC2: pi_1_5 + +•CIS-1.4: 3.8 + +•CIS-1.5: 3.8 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: KMS.4 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B + +•HIPAA: 164_312_a_2_iv + +•CIS-2.0: 3.8 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•CIS-5.0: 3.6 + +•PCI-4.0: 3.7.4.5, 3.7.5.2 + +•NIST-800-53-Revision-4: sc_12 + +•NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6 + +•CIS-3.0: 3.6 + +•ENS-RD2022: op.exp.10.aws.cmk.3 + +•CIS-6.0: 4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01 + +•SecNumCloud-3.2: 10.5 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 3.2.1 + +•ISO27001-2022: A.8.5, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 + +•FedRamp-Moderate-Revision-4: sc-12 + +•FedRAMP-Low-Revision-4: sc-12 + +•CIS-4.0.1: 3.6 + +•NIS2: 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILhighkmsus-east-2kms_cmk_rotation_enabledKMS customer-managed symmetric CMK has automatic rotation enabledarn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 has automatic rotation disabled.

Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies.

Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected.

+•CISA: your-systems-3 + +•CIS-7.0: 4.6 + +•SOC2: pi_1_5 + +•CIS-1.4: 3.8 + +•CIS-1.5: 3.8 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: KMS.4 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B + +•HIPAA: 164_312_a_2_iv + +•CIS-2.0: 3.8 + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•CIS-5.0: 3.6 + +•PCI-4.0: 3.7.4.5, 3.7.5.2 + +•NIST-800-53-Revision-4: sc_12 + +•NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6 + +•CIS-3.0: 3.6 + +•ENS-RD2022: op.exp.10.aws.cmk.3 + +•CIS-6.0: 4.6 + +•CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01 + +•SecNumCloud-3.2: 10.5 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ProwlerThreatScore-1.0: 3.2.1 + +•ISO27001-2022: A.8.5, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 + +•FedRamp-Moderate-Revision-4: sc-12 + +•FedRAMP-Low-Revision-4: sc-12 + +•CIS-4.0.1: 3.6 + +•NIS2: 11.6.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

MANUALmediumkmsus-east-2kms_key_enclave_attestation_unknown_imageNo enclave with an unknown image identity has called this KMS keyarn:aws:kms:us-east-2:716468089330:enclave-debug-attestationCannot verify unknown-image attestation activity: no 'enclave_golden_pcr_values' configured. Set a golden PCR list in audit_config and re-run this check.

An attestation event whose PCRs cannot be traced back to a known-good enclave build indicates either a stale golden list, a policy broad enough to accept unaudited images, or a compromise scenario in which an unknown image is being executed with legitimate KMS access. Materiality depends on the operator's threat model.

Treat the enclave_golden_pcr_values list as a live registry of trusted enclave images. Any runtime attestation from a PCR outside that list is either a documentation gap (extend the list) or a suspected incident (investigate).

+•SOC2: cc_7_2 + +•MITRE-ATTACK: T1078 + +•HIPAA: 164_312_c_2 + +•NIST-CSF-2.0: cm_1 + +•PCI-4.0: 10.4.1.7 + +•NIST-800-53-Revision-5: si_4_2 + +•ISO27001-2022: A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-03 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

MANUALhighkmsus-east-2kms_key_enclave_debug_attestation_detectedNo Nitro Enclave debug-mode attestation observed against this KMS keyarn:aws:kms:us-east-2:716468089330:enclave-debug-attestationNo KMS-from-enclave attestation events found in the last 2160h. Debug-mode status cannot be determined from available data; enclaves that never call KMS in the window are not observable via this check.

Debug mode zeros the image, kernel and application PCRs (PCR0/1/2) in the attestation document, so PCR-bound key policies release material to enclaves whose measurement cannot be trusted. A debug enclave calling this KMS key is functionally equivalent to no enclave at all.

Never run production Nitro Enclaves with --debug-mode. Enforce non-debug launch flags in the enclave orchestration pipeline and pair with strict PCR bindings on KMS policies so debug enclaves are rejected at the key-policy layer.

+•SOC2: cc_7_2 + +•MITRE-ATTACK: T1562 + +•HIPAA: 164_308_a_1_ii_d, 164_312_b + +•NIST-CSF-2.0: cm_1 + +•PCI-4.0: 3.5.1.36 + +•NIST-800-53-Revision-5: sc_28_1, si_4_2 + +•PCI-3.2.1: 10.2 + +•ISO27001-2022: A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-03 + +•FedRamp-Moderate-Revision-4: sc-28, si-4-2 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASScriticalkmsus-east-2kms_key_not_publicly_accessibleCloud KMS key does not grant access to allUsers or allAuthenticatedUsersarn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6dKMS key 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not exposed to Public.

Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key.

Apply least privilege to KMS keys:
+- Restrict principals to specific roles and accounts
+- Prefer narrow, time-bound grants
+- Separate key administration from usage
+- Use conditions to limit context
+- Review regularly and remove wildcard or cross-account exposure

+•CIS-7.0: 2.21 + +•AWS-Foundational-Security-Best-Practices: KMS.5 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.5 + +•ProwlerThreatScore-1.0: 2.2.14 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASScriticalkmsus-east-2kms_key_not_publicly_accessibleCloud KMS key does not grant access to allUsers or allAuthenticatedUsersarn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72KMS key 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not exposed to Public.

Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key.

Apply least privilege to KMS keys:
+- Restrict principals to specific roles and accounts
+- Prefer narrow, time-bound grants
+- Separate key administration from usage
+- Use conditions to limit context
+- Review regularly and remove wildcard or cross-account exposure

+•CIS-7.0: 2.21 + +•AWS-Foundational-Security-Best-Practices: KMS.5 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2 + +•C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.5 + +•ProwlerThreatScore-1.0: 2.2.14 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-07 + +•NIS2: 9.2.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASShighmacieus-east-2macie_automated_sensitive_data_discovery_enabledMacie automated sensitive data discovery is enabledarn:aws:macie:us-east-2:716468089330:sessionMacie has automated sensitive data discovery enabled.

Without continuous discovery, sensitive S3 objects remain unclassified and unnoticed, weakening confidentiality. Over-permissive or public access can persist undetected, enabling data exfiltration and delaying containment and forensic response.

Enable and maintain automated sensitive data discovery for the Macie administrator across required Regions. Include relevant buckets, tune identifiers and allow lists to reduce noise, and route findings to monitoring. Complement with least privilege on S3 and defense in depth for data protection.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•PCI-4.0: A3.2.5.1.1, A3.2.5.1.3 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-01 +

FAILmediummacieus-east-1macie_is_enabledAmazon Macie is enabledarn:aws:macie:us-east-1:716468089330:sessionMacie is not enabled.

Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides.

Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls.

+•CIS-7.0: 3.1.3 + +•CIS-1.4: 2.1.4 + +•CIS-1.5: 2.1.4 + +•MITRE-ATTACK: T1552, T1537, T1530 + +•AWS-Foundational-Security-Best-Practices: Macie.1 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•CIS-2.0: 2.1.3 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•CIS-5.0: 2.1.3 + +•PCI-4.0: A3.2.5.1.2, A3.2.5.1.4 + +•AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only + +•CIS-3.0: 2.1.3 + +•CIS-6.0: 3.1.3 + +•ProwlerThreatScore-1.0: 2.2.2 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-01 + +•CIS-4.0.1: 2.1.3 +

PASSmediummacieus-east-2macie_is_enabledAmazon Macie is enabledarn:aws:macie:us-east-2:716468089330:sessionMacie is enabled.

Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides.

Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls.

+•CIS-7.0: 3.1.3 + +•CIS-1.4: 2.1.4 + +•CIS-1.5: 2.1.4 + +•MITRE-ATTACK: T1552, T1537, T1530 + +•AWS-Foundational-Security-Best-Practices: Macie.1 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•CIS-2.0: 2.1.3 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•CIS-5.0: 2.1.3 + +•PCI-4.0: A3.2.5.1.2, A3.2.5.1.4 + +•AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only + +•CIS-3.0: 2.1.3 + +•CIS-6.0: 3.1.3 + +•ProwlerThreatScore-1.0: 2.2.2 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-01 + +•CIS-4.0.1: 2.1.3 +

FAILmediumnetworkfirewallus-east-2networkfirewall_in_all_vpcVPC has Network Firewall enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361VPC vpc-027f26d26f17ab361 does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
+
+Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

+•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•ENS-RD2022: mp.com.1.aws.nfw.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-02 + +•NIS2: 6.2.1, 6.7.2.b +

FAILmediumnetworkfirewallus-east-2networkfirewall_in_all_vpcVPC has Network Firewall enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c +•Name=Scrivas_prod_vpc +VPC Scrivas_prod_vpc does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
+
+Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

+•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•ENS-RD2022: mp.com.1.aws.nfw.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-02 + +•NIS2: 6.2.1, 6.7.2.b +

FAILmediumnetworkfirewallus-east-2networkfirewall_in_all_vpcVPC has Network Firewall enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 +•Name=Scrivas_vpc +VPC Scrivas_vpc does not have Network Firewall enabled.

Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic.

Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
+
+Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies.

+•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•ENS-RD2022: mp.com.1.aws.nfw.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-02 + +•NIS2: 6.2.1, 6.7.2.b +

PASSmediumorganizationsus-east-2organizations_account_part_of_organizationsAWS account is a member of an active AWS Organizationarn:aws:organizations::716468089330:organization/o-qfj0pvhhv7AWS Organization o-qfj0pvhhv7 contains this AWS account.

Absence of AWS Organizations weakens governance across accounts. Without SCP guardrails and centralized policy, excessive permissions, unsafe network settings, or risky services may be enabled, threatening confidentiality and integrity. Fragmented logging and response slow containment, impacting availability and increasing cost exposure.

Operate all accounts under AWS Organizations (preferably with all features). Structure OUs, enforce SCPs for least privilege, and apply separation of duties between management and member accounts. Centralize logging and billing to support defense-in-depth, and routinely review org membership and policies.

+•MITRE-ATTACK: T1078, T1087, T1580, T1538 + +•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP01, SEC03-BP05, SEC08-BP04 + +•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, am_6 + +•PCI-4.0: 7.2.1.1, 7.2.2.1, 7.2.5.1, 7.3.1.1, 7.3.2.1, 7.3.3.1, 8.2.7.1, 8.2.8.1, 8.3.4.1 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8 + +•SecNumCloud-3.2: 9.6, 12.3, 14.4 + +•RBI-Cyber-Security-Framework: annex_i_1_1 + +•ISO27001-2022: A.8.3 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-piy +

PASScriticalorganizationsus-east-2organizations_delegated_administratorsAWS Organization has only trusted delegated administratorsarn:aws:organizations::716468089330:organization/o-qfj0pvhhv7AWS Organization o-qfj0pvhhv7 has no Delegated Administrators.

Unapproved delegated administrators can alter SCPs, invite/move accounts, and create privileged roles, enabling privilege escalation. This undermines guardrails, risking loss of integrity, exposure of confidentiality across accounts, and impacts availability through organization-wide policy changes.

Restrict delegation to vetted accounts using least privilege and separation of duties. Maintain a centrally governed approved allowlist, review it regularly, and remove unused delegations. Enforce strong authentication for admin roles and monitor Organizations policy changes for defense in depth.

+•CIS-7.0: 2.1.5, 2.1.6 + +•MITRE-ATTACK: T1078 + +•KISA-ISMS-P-2023: 2.5.5, 2.10.2 + +•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B + +•KISA-ISMS-P-2023-korean: 2.5.5, 2.10.2 + +•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, ov_3, am_6 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-iam-07 +

FAILmediumorganizationsus-east-2organizations_opt_out_ai_services_policyAWS Organization has opted out of all AI services and child accounts cannot override the policyarn:aws:organizations::716468089330:organization/o-qfj0pvhhv7AWS Organization o-qfj0pvhhv7 has no opt-out policy for AI services.

Without an enforced opt-out, AI services may store and use your content for model training, weakening confidentiality and data sovereignty. If child accounts can override, they can re-enable data use, risking unintended cross-Region retention and exposure of logs, documents, or code processed by these services.

Establish an org-wide AI services opt-out: set the default to optOut and prohibit child policy overrides (@@none). Apply at the highest scope, gate exceptions through change control, and review periodically. Align with least privilege and data minimization to prevent unintended content sharing with managed AI services.

+•KISA-ISMS-P-2023: 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-06 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam +

FAILhighorganizationsus-east-2organizations_scp_check_deny_regionsAWS Organization restricts operations to only the configured AWS Regions with SCP policiesarn:aws:organizations::716468089330:organization/o-qfj0pvhhv7AWS Organization o-qfj0pvhhv7 has SCP policies but don't restrict AWS Regions.

Without comprehensive Region limits, users or attackers can deploy resources in ungoverned locations, bypassing monitoring and guardrails.
+
+Impacts:
+- Data outside approved jurisdictions (confidentiality)
+- Policy gaps and drift (integrity)
+- IR blind spots and unexpected cost (availability)

Enforce Region governance with SCPs that allow only approved regions via aws:RequestedRegion conditions (deny-by-default).
+
+Apply across relevant OUs and accounts, with narrow exceptions for required global services. Review often; align to least privilege, data residency, and continuous monitoring.

+•MITRE-ATTACK: T1078, T1535 + +•KISA-ISMS-P-2023: 2.10.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS, PSS-12.02AC + +•KISA-ISMS-P-2023-korean: 2.10.2 + +•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, ov_3 + +•AWS-Account-Security-Onboarding: Block unused regions + +•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8 + +•CCC-v2025.10: CCC.Core.CN06.AR01, CCC.Core.CN06.AR02 + +•SecNumCloud-3.2: 9.1, 19.2 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-02 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-piy +

FAILloworganizationsus-east-2organizations_tags_policies_enabled_and_attachedAWS Organization has tag policies enabled and attachedarn:aws:organizations::716468089330:organization/o-qfj0pvhhv7AWS Organizations o-qfj0pvhhv7 does not have tag policies.

Absent or unattached tag policies cause inconsistent or missing tags, undermining:
+- Confidentiality via bypassed tag-based access conditions
+- Integrity through misclassified resources and drift
+- Availability when automation, cost routing, or incident scoping that rely on tags break

Enable tag policies and attach them to relevant roots/OUs/accounts. Define mandatory keys (e.g., Environment, CostCenter) with allowed values. Apply defense in depth by using tags in IAM conditions and SCPs. Start with validation-only, then enforce, and continuously monitor compliance across accounts.

+•KISA-ISMS-P-2023: 2.1.3 + +•C5-2025: AM-09.01B + +•KISA-ISMS-P-2023-korean: 2.1.3 + +•NIST-CSF-2.0: rm_1, po_3, ov_3 + +•ENS-RD2022: op.exp.1.aws.sys.2, op.exp.1.aws.tag.1, op.exp.10.aws.tag.1, mp.info.6.aws.tag.1 + +•ISO27001-2022: A.5.13 + +•AWS-AI-Security-Framework-1.0: AISF-GOV-02 + +•NIS2: 11.5.2.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-piy +

PASShighrdsus-east-2rds_snapshots_encryptedRDS DB instance snapshot or DB cluster snapshot is encryptedarn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frameRDS Instance Snapshot for-secure-frame is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

+•AWS-Foundational-Security-Best-Practices: RDS.4 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: ds_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•PCI-4.0: 3.5.1.26, 8.3.2.43 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl +

PASShighrdsus-east-2rds_snapshots_encryptedRDS DB instance snapshot or DB cluster snapshot is encryptedarn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshotRDS Instance Snapshot scrivas-encounter-dev-snapshot is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

+•AWS-Foundational-Security-Best-Practices: RDS.4 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: ds_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•PCI-4.0: 3.5.1.26, 8.3.2.43 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl +

PASShighrdsus-east-2rds_snapshots_encryptedRDS DB instance snapshot or DB cluster snapshot is encryptedarn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot +•Owner=DevTeamSpace + +•Purpose=BackupRestoreTest + +•Date=2025-10-20 +RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is encrypted.

Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances.

Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted.

+•AWS-Foundational-Security-Best-Practices: RDS.4 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: ds_1 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•PCI-4.0: 3.5.1.26, 8.3.2.43 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl +

PASScriticalrdsus-east-2rds_snapshots_public_accessRDS snapshot is not publicly sharedarn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frameRDS Instance Snapshot for-secure-frame is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
+- Loss of confidentiality via data exfiltration (PII, secrets)
+- Offline cracking of hashes and schema reconnaissance
+- Credential harvesting from dumps enabling lateral movement
+This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
+
+Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

+•CISA: your-systems-3, your-data-2 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: RDS.1 + +•ISO27001-2013: A.12.6.H, A.13.1.G + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 + +•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 + +•CCC-v2025.10: CCC.RDMS.CN05.AR01 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticalrdsus-east-2rds_snapshots_public_accessRDS snapshot is not publicly sharedarn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshotRDS Instance Snapshot scrivas-encounter-dev-snapshot is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
+- Loss of confidentiality via data exfiltration (PII, secrets)
+- Offline cracking of hashes and schema reconnaissance
+- Credential harvesting from dumps enabling lateral movement
+This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
+
+Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

+•CISA: your-systems-3, your-data-2 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: RDS.1 + +•ISO27001-2013: A.12.6.H, A.13.1.G + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 + +•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 + +•CCC-v2025.10: CCC.RDMS.CN05.AR01 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticalrdsus-east-2rds_snapshots_public_accessRDS snapshot is not publicly sharedarn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot +•Owner=DevTeamSpace + +•Purpose=BackupRestoreTest + +•Date=2025-10-20 +RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is not shared.

Public RDS snapshots expose full database copies to all AWS accounts, risking:
+- Loss of confidentiality via data exfiltration (PII, secrets)
+- Offline cracking of hashes and schema reconnaissance
+- Credential harvesting from dumps enabling lateral movement
+This directly compromises confidentiality and fuels targeted attacks.

Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
+
+Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data.

+•CISA: your-systems-3, your-data-2 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: RDS.1 + +•ISO27001-2013: A.12.6.H, A.13.1.G + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5 + +•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2 + +•CCC-v2025.10: CCC.RDMS.CN05.AR01 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASSlowresourceexplorer2ap-northeast-1resourceexplorer2_indexes_foundResource Explorer indexes existarn:aws:resource-explorer-2:ap-northeast-1:716468089330:index/d4aa7318-d5e6-473d-b3c0-8328855a8bdcResource Explorer Indexes found: 12.

Absent indexes reduce asset visibility, creating blind spots where misconfigured or orphaned resources go unnoticed. This degrades confidentiality (unseen public exposure), integrity (unauthorized changes undetected), and availability (slower containment and recovery), prolonging incident response and enabling lateral movement.

Create Resource Explorer indexes in all active Regions and designate an aggregator index for cross-Region search. Apply least-privilege access to views, align with tagging standards, and routinely verify indexing status. This improves inventory accuracy, supports defense-in-depth, and speeds detection and remediation.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ENS-RD2022: op.exp.1.aws.re.1 +

FAILhighs3us-east-2s3_account_level_public_access_blocksS3 account-level Block Public Access ignores public ACLs and restricts public bucketsarn:aws:s3:us-east-2:716468089330:accountBlock Public Access is not configured for the account 716468089330.

Absent these settings, public ACLs and broad bucket policies may grant internet or cross-account access. This risks:
+- Confidentiality: bulk data exfiltration
+- Integrity: object overwrite/tampering
+- Availability: malicious deletions or malware hosting, triggering takedowns

Turn on account-level Block Public Access (prefer enabling all four: block_public_acls, ignore_public_acls, block_public_policy, restrict_public_buckets) to enforce least privilege. For legitimate access, use private buckets with CloudFront, VPC endpoints, or presigned URLs. Regularly review policies with IAM Access Analyzer.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.1 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.31, 1.2.8.32, 1.3.1.35, 1.3.1.36, 1.3.2.35, 1.3.2.36, 1.4.2.33, 1.4.2.34, 1.5.1.31, 1.5.1.32, 10.3.2.19, 10.3.2.20, 3.5.1.3.24, 3.5.1.3.25, A1.1.2.15, A1.1.2.16, A1.1.3.31, A1.1.3.32, A3.4.1.17, A3.4.1.18 + +•NIST-800-53-Revision-4: sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 + +•CIS-4.0.1: 2.1.4 +

PASSmediums3us-east-1s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASSmediums3us-east-2s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has bucket ACLs disabled.

With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
+- Unintended public or cross-account reads/writes
+- Object-writer ownership blocking bucket-owner governance
+- Per-object grants hinder auditing, enabling data exfiltration or tampering

Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change.

+•CISA: your-data-2 + +•AWS-Foundational-Security-Best-Practices: S3.12 + +•KISA-ISMS-P-2023: 2.6.2, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•NIST-CSF-2.0: ds_5 + +•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-1s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

FAILhighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has a bucket policy allowing cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

FAILhighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has a bucket policy allowing cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have a bucket policy.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

PASShighs3us-east-2s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has a bucket policy but it does not allow cross account access.

Cross-account grants can let external principals read, write, or administer the bucket, impacting:
+- Confidentiality: unauthorized object access/exfiltration
+- Integrity: object tampering, policy or encryption changes
+- Availability: deletions, versioning changes, or lockouts causing data loss and downtime

Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
+
+Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access.

+•AWS-Foundational-Security-Best-Practices: S3.6, S3.7 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: IAM-10.01B, IAM-10.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5, ip_1 + +•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 +

FAILlows3us-east-1s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

FAILlows3us-east-2s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas does not have correct cross region replication configuration.

Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
+
+Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion.

Enable CRR to a different Region with versioning and least-privilege roles. +

    +
  • Replicate needed prefixes and metadata
  • +
  • Consider S3 Replication Time Control for tighter RPO
  • +
  • Protect deletes via delete marker strategy and Object Lock
  • +
  • Monitor replication metrics and test DR regularly
  • +
+Align with defense in depth and availability by design.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ds_4, pt_5 + +•ASD-Essential-Eight-Nov 2023: E8-8.3 + +•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01 + +•SecNumCloud-3.2: 12.5 + +•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3 + +•ISO27001-2022: A.8.14 +

PASSmediums3us-east-1s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_default_encryption[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has Server Side Encryption with AES256.

Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths.

Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•CIS-1.4: 2.1.1 + +•CIS-1.5: 2.1.1 + +•MITRE-ATTACK: T1119, T1530 + +•GDPR: article_32 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: ds_1, ds_3 + +•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.30, 8.3.2.48 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4 + +•ENS-RD2022: mp.si.2.aws.s3.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILlows3us-east-1s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILlows3us-east-2s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas does not have event notifications enabled.

Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer.

Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
+
+Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.3 + +•C5-2025: OPS-13.01AC, OPS-13.03AC + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3 + +•NIST-CSF-2.0: dp_4 + +•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8 +

FAILmediums3us-east-1s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::config-bucket-716468089330Server Side Encryption is not configured with kms for S3 Bucket config-bucket-716468089330.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88Server Side Encryption is not configured with kms for S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::maciedata1902Server Side Encryption is not configured with kms for S3 Bucket maciedata1902.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::scrivas-access-logsServer Side Encryption is not configured with kms for S3 Bucket scrivas-access-logs.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +Server Side Encryption is not configured with kms for S3 Bucket scrivas-tf-statefile.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +Server Side Encryption is not configured with kms for S3 Bucket scrivasbackendstorage.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::scrivasbackupsdbServer Side Encryption is not configured with kms for S3 Bucket scrivasbackupsdb.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::scrivasloggsbucketServer Side Encryption is not configured with kms for S3 Bucket scrivasloggsbucket.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

FAILmediums3us-east-2s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSarn:aws:s3:::vulnerability-reports-scrivasServer Side Encryption is not configured with kms for S3 Bucket vulnerability-reports-scrivas.

Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth.

Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost.

+•SOC2: pi_1_4 + +•AWS-Foundational-Security-Best-Practices: S3.17 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4 + +•PCI-4.0: 3.5.1.31, 8.3.2.50 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04 + +•SecNumCloud-3.2: 10.1 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04 +

PASShighs3us-east-1s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::config-bucket-716468089330Block Public Access is configured for the S3 Bucket config-bucket-716468089330.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88Block Public Access is configured for the S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::maciedata1902Block Public Access is configured for the S3 Bucket maciedata1902.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::scrivas-access-logsBlock Public Access is configured for the S3 Bucket scrivas-access-logs.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +Block Public Access is configured for the S3 Bucket scrivas-tf-statefile.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +Block Public Access is configured for the S3 Bucket scrivasbackendstorage.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::scrivasbackupsdbBlock Public Access is configured for the S3 Bucket scrivasbackupsdb.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::scrivasloggsbucketBlock Public Access is configured for the S3 Bucket scrivasloggsbucket.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

PASShighs3us-east-2s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account levelarn:aws:s3:::vulnerability-reports-scrivasBlock Public Access is configured for the S3 Bucket vulnerability-reports-scrivas.

Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
+- Data disclosure (confidentiality)
+- Object overwrite or uploads (integrity)
+- Deletion or outages from misuse (availability)

Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions.

+•CIS-7.0: 3.1.4 + +•CIS-1.4: 2.1.5 + +•CIS-1.5: 2.1.5 + +•MITRE-ATTACK: T1530 + +•AWS-Foundational-Security-Best-Practices: S3.8 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•CIS-2.0: 2.1.4 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ac_3 + +•CIS-5.0: 2.1.4 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•CIS-3.0: 2.1.4 + +•CIS-6.0: 3.1.4 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Logging.CN05.AR01 + +•SecNumCloud-3.2: 9.7 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•CIS-4.0.1: 2.1.4 +

FAILlows3us-east-1s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILlows3us-east-2s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas does not have a lifecycle configuration enabled.

Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability.

Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties.

+•AWS-Foundational-Security-Best-Practices: S3.13 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-32.02B + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•NIST-CSF-2.0: ds_3, ds_4 + +•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9 + +•CCC-v2025.10: CCC.AuditLog.CN06.AR01 + +•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a + +•ISO27001-2022: A.8.10 + +•NIS2: 12.2.2.a +

FAILmediums3us-east-1s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILmediums3us-east-2s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has MFA Delete disabled.

Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
+
+This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware.

Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth.

+•CIS-7.0: 3.1.2 + +•CIS-1.4: 2.1.3 + +•CIS-1.5: 2.1.3 + +•MITRE-ATTACK: T1485 + +•AWS-Foundational-Security-Best-Practices: S3.20 + +•KISA-ISMS-P-2023: 2.5.3, 2.10.2 + +•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B + +•CIS-2.0: 2.1.2 + +•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02 + +•CIS-5.0: 2.1.2 + +•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20 + +•CIS-3.0: 2.1.2 + +•CIS-6.0: 3.1.2 + +•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03 + +•ProwlerThreatScore-1.0: 2.2.1 + +•CIS-4.0.1: 2.1.2 + +•NIS2: 11.7.2 +

FAILlows3us-east-1s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILlows3us-east-2s3_bucket_object_lockS3 bucket has Object Lock enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has Object Lock disabled.

Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
+
+Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps.

Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
+
+Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements.

+•SOC2: pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.15 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•PCI-4.0: 10.3.4.7 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02 +

FAILmediums3us-east-1s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

PASSmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has versioning enabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

FAILmediums3us-east-2s3_bucket_object_versioningS3 bucket has object versioning enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has versioning disabled.

Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
+- Compromised identities or buggy apps can mass-delete/corrupt data
+- No historical versions means limited rollback and irrecoverable loss

Enable S3 versioning for buckets holding important or shared data.
+- Enforce least privilege to limit delete/overwrite
+- Use Object Lock and/or MFA Delete for stronger protection
+- Apply lifecycle rules to manage noncurrent versions and costs
+- Layer with backups/replication for defense in depth

+•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1 + +•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.14 + +•KISA-ISMS-P-2023: 2.9.3, 2.12.1 + +•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2 + +•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-c + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer + +•NIST-800-171-Revision-2: 3_3_8 + +•ASD-Essential-Eight-Nov 2023: E8-8.2 + +•PCI-4.0: 10.3.4.9 + +•NIST-800-53-Revision-4: cp_10, si_12 + +•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5 + +•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1 + +•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04 + +•SecNumCloud-3.2: 12.5, 17.6 + +•RBI-Cyber-Security-Framework: annex_i_12 + +•FFIEC: d5-ir-pl-b-6 + +•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5 + +•ISO27001-2022: A.8.3, A.8.10 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12 + +•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5 +

PASScriticals3us-east-1s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::config-bucket-716468089330S3 public access blocked at bucket level for config-bucket-716468089330.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 public access blocked at bucket level for aws-cloudtrail-logs-716468089330-fb4a4f88.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::maciedata1902S3 public access blocked at bucket level for maciedata1902.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::scrivas-access-logsS3 public access blocked at bucket level for scrivas-access-logs.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 public access blocked at bucket level for scrivas-tf-statefile.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 public access blocked at bucket level for scrivasbackendstorage.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have a bucket policy.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::scrivasloggsbucketS3 public access blocked at bucket level for scrivasloggsbucket.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessarn:aws:s3:::vulnerability-reports-scrivasS3 public access blocked at bucket level for vulnerability-reports-scrivas.

Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting.

Restrict writes to trusted principals using least privilege; avoid Principal: &#34;*&#34;. Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 2.21 + +•MITRE-ATTACK: T1485, T1486 + +•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1 + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2 + +•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.15 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-1s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-2s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated Usersarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas is not public.

Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects.

Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_6_1 + +•MITRE-ATTACK: T1530 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1 + +•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5 + +•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21 + +•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7 + +•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25 + +•AWS-Account-Security-Onboarding: S3 Block Public Access + +•ENS-RD2022: op.exp.8.r4.aws.ct.2 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-im-b-1 + +•ISO27001-2022: A.8.1 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7 + +•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7 +

PASScriticals3us-east-1s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-2s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas is not publicly listable.

Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability.

Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
+- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
+- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership.

+•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ds_5 + +•AWS-Foundational-Technical-Review: S3-001 + +•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•ProwlerThreatScore-1.0: 2.2.16 +

PASScriticals3us-east-1s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

PASScriticals3us-east-2s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas is not publicly writable.

Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding.

Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth.

+•AWS-Foundational-Security-Best-Practices: S3.3 + +•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2 + +•NIST-CSF-2.0: ra_1, ds_5 + +•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22 + +•AWS-Foundational-Technical-Review: S3-001 + +•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02 + +•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1 + +•ProwlerThreatScore-1.0: 2.2.17 +

FAILmediums3us-east-1s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has a bucket policy to deny requests over insecure transport.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb does not have a bucket policy, thus it allows HTTP requests.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

FAILmediums3us-east-2s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas allows requests over insecure transport in the bucket policy.

HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content.

Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
+
+Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts.

+•CISA: your-systems-3, your-data-2 + +•CIS-7.0: 3.1.1 + +•CIS-1.4: 2.1.2 + +•CIS-1.5: 2.1.2 + +•MITRE-ATTACK: T1040 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: S3.5 + +•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii + +•CIS-2.0: 2.1.1 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-c, 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02 + +•NIST-CSF-2.0: ds_2, pt_4 + +•CIS-5.0: 2.1.1 + +•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16 + +•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49 + +•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8 + +•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2 + +•CIS-3.0: 2.1.1 + +•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1 + +•CIS-6.0: 3.1.1 + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ds_2 + +•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03 + +•SecNumCloud-3.2: 10.2 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15 + +•ProwlerThreatScore-1.0: 4.1.1 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23 + +•FedRAMP-Low-Revision-4: ac-17, sc-7 + +•CIS-4.0.1: 2.1.1 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-svc +

PASSmediums3us-east-1s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::config-bucket-716468089330S3 Bucket config-bucket-716468089330 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::maciedata1902S3 Bucket maciedata1902 has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::scrivas-access-logsS3 Bucket scrivas-access-logs has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::scrivas-tf-statefile +•Purpose=terraform-backend + +•ManagedBy=terraform +S3 Bucket scrivas-tf-statefile has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::scrivasbackendstorage +•Project = =scrivas Service +S3 Bucket scrivasbackendstorage has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::scrivasbackupsdbS3 Bucket scrivasbackupsdb has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::scrivasloggsbucketS3 Bucket scrivasloggsbucket has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediums3us-east-2s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledarn:aws:s3:::vulnerability-reports-scrivasS3 Bucket vulnerability-reports-scrivas has server access logging enabled.

Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity.

Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering.

+•CISA: your-systems-3, your-data-2 + +•SOC2: cc_7_2, cc_7_3, cc_a_1_1 + +•AWS-Foundational-Security-Best-Practices: S3.9 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e, 11.10-k + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32 + +•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c + +•AWS-Foundational-Technical-Review: S3-001 + +•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01 + +•SecNumCloud-3.2: 12.6 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3 + +•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4 + +•ISO27001-2022: A.8.15 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-04 + +•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: ac-2, au-2 + +•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

FAILlowsagemakerus-east-1sagemaker_clarify_existsAmazon SageMaker Clarify processing jobs exist in the regionarn:aws:sagemaker:us-east-1:716468089330:processing-jobNo SageMaker Clarify processing jobs found in region us-east-1.

Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
+- Regulatory non-compliance with AI governance frameworks
+- Undetected bias in model predictions affecting protected groups
+- Lack of accountability for ML model decisions in production

Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices.

FAILlowsagemakerus-east-2sagemaker_clarify_existsAmazon SageMaker Clarify processing jobs exist in the regionarn:aws:sagemaker:us-east-2:716468089330:processing-jobNo SageMaker Clarify processing jobs found in region us-east-2.

Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
+- Regulatory non-compliance with AI governance frameworks
+- Undetected bias in model predictions affecting protected groups
+- Lack of accountability for ML model decisions in production

Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices.

FAILlowsagemakerus-east-1sagemaker_models_monitor_enabledAmazon SageMaker has a monitoring schedule scheduledarn:aws:sagemaker:us-east-1:716468089330:monitoring-schedule/unknownNo SageMaker monitoring schedules found in region us-east-1.

Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model.

Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline.

FAILlowsagemakerus-east-2sagemaker_models_monitor_enabledAmazon SageMaker has a monitoring schedule scheduledarn:aws:sagemaker:us-east-2:716468089330:monitoring-schedule/unknownNo SageMaker monitoring schedules found in region us-east-2.

Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model.

Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline.

FAILlowsagemakerus-east-1sagemaker_models_registry_in_useAmazon SageMaker Model Registry should have at least one approved model packagearn:aws:sagemaker:us-east-1:716468089330:model-registry/unknownSageMaker Model Registry in region us-east-1 has no Model Package Groups.

An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows.

Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration.

+•AWS-AI-Security-Framework-1.0: AISF-ML-04 +

FAILlowsagemakerus-east-2sagemaker_models_registry_in_useAmazon SageMaker Model Registry should have at least one approved model packagearn:aws:sagemaker:us-east-2:716468089330:model-registry/unknownSageMaker Model Registry in region us-east-2 has no Model Package Groups.

An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows.

Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration.

+•AWS-AI-Security-Framework-1.0: AISF-ML-04 +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEzSecretsManager secret ScrivasML_post_processor_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJcSecretsManager secret ScrivasML_post_processor_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpCSecretsManager secret ScrivasML_post_processor_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4SecretsManager secret ScrivasML_patient_summary_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8aSecretsManager secret ScrivasML_patient_summary_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFFSecretsManager secret ScrivasML_patient_summary_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkjSecretsManager secret ScrivasML_patient_document_parser_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUODSecretsManager secret ScrivasML_patient_document_parser_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0PibSecretsManager secret ScrivasML_patient_document_parser_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UFSecretsManager secret ScrivasML_sai_suggestions_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJlSecretsManager secret ScrivasML_soniox_transcriber_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mDSecretsManager secret ScrivasML_sai_suggestions_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSqSecretsManager secret ScrivasML_sai_suggestions_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYXSecretsManager secret ScrivasML_soniox_transcriber_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmTSecretsManager secret ScrivasML_soniox_transcriber_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWwSecretsManager secret ScrivasML_Monitoring_Dev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqUSecretsManager secret ScrivasML_Monitoring_Stage has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4SecretsManager secret ScrivasML_Monitoring_Prod has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9SecretsManager secret ScrivasBKPatientDev has rotation disabled.

Absent rotation, long-lived secrets widen the attack window:
+- Valid after leakage in code, images, or logs
+- Enable unauthorized access and lateral movement
+- Complicate incident response and recovery
+This impacts confidentiality and integrity, and can threaten availability if revocation lags.

Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates.

+•CISA: your-systems-3 + +•MITRE-ATTACK: T1552 + +•AWS-Foundational-Security-Best-Practices: SecretsManager.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B + +•HIPAA: 164_308_a_4_ii_c + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b + +•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05 + +•NIST-CSF-2.0: ip_7 + +•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5 + +•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3 + +•NIST-CSF-1.1: ac_1 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv, 11.6.2.c +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEzSecretsManager secret 'ScrivasML_post_processor_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJcSecretsManager secret 'ScrivasML_post_processor_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpCSecretsManager secret 'ScrivasML_post_processor_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4SecretsManager secret 'ScrivasML_patient_summary_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8aSecretsManager secret 'ScrivasML_patient_summary_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFFSecretsManager secret 'ScrivasML_patient_summary_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkjSecretsManager secret 'ScrivasML_patient_document_parser_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUODSecretsManager secret 'ScrivasML_patient_document_parser_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0PibSecretsManager secret 'ScrivasML_patient_document_parser_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UFSecretsManager secret 'ScrivasML_sai_suggestions_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJlSecretsManager secret 'ScrivasML_soniox_transcriber_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mDSecretsManager secret 'ScrivasML_sai_suggestions_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSqSecretsManager secret 'ScrivasML_sai_suggestions_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYXSecretsManager secret 'ScrivasML_soniox_transcriber_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmTSecretsManager secret 'ScrivasML_soniox_transcriber_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWwSecretsManager secret 'ScrivasML_Monitoring_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqUSecretsManager secret 'ScrivasML_Monitoring_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4SecretsManager secret 'ScrivasML_Monitoring_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILhighsecretsmanagerus-east-2secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9SecretsManager secret 'ScrivasBKPatientDev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis'

Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials.

Apply deny-by-default resource policies to every secret:
+- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
+- Deny access from outside the AWS Organization via aws:PrincipalOrgID
+- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
+- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth)

+•AWS-AI-Security-Framework-1.0: AISF-DATA-03 +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEzSecret ScrivasML_post_processor_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJcSecret ScrivasML_post_processor_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpCSecret ScrivasML_post_processor_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4Secret ScrivasML_patient_summary_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8aSecret ScrivasML_patient_summary_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFFSecret ScrivasML_patient_summary_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkjSecret ScrivasML_patient_document_parser_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUODSecret ScrivasML_patient_document_parser_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0PibSecret ScrivasML_patient_document_parser_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UFSecret ScrivasML_sai_suggestions_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJlSecret ScrivasML_soniox_transcriber_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mDSecret ScrivasML_sai_suggestions_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSqSecret ScrivasML_sai_suggestions_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYXSecret ScrivasML_soniox_transcriber_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmTSecret ScrivasML_soniox_transcriber_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWwSecret ScrivasML_Monitoring_Dev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqUSecret ScrivasML_Monitoring_Stage has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4Secret ScrivasML_Monitoring_Prod has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

FAILmediumsecretsmanagerus-east-2secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9Secret ScrivasBKPatientDev has never been rotated.

Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity.

Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets.

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•NIST-CSF-2.0: ip_7 + +•CCC-v2025.10: CCC.SecMgmt.CN01.AR01 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEzSecret ScrivasML_post_processor_Dev has been accessed recently, last accessed on August 17, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJcSecret ScrivasML_post_processor_Stage has been accessed recently, last accessed on August 16, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpCSecret ScrivasML_post_processor_Prod has been accessed recently, last accessed on August 16, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4Secret ScrivasML_patient_summary_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8aSecret ScrivasML_patient_summary_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFFSecret ScrivasML_patient_summary_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkjSecret ScrivasML_patient_document_parser_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUODSecret ScrivasML_patient_document_parser_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0PibSecret ScrivasML_patient_document_parser_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UFSecret ScrivasML_sai_suggestions_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJlSecret ScrivasML_soniox_transcriber_Dev has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mDSecret ScrivasML_sai_suggestions_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSqSecret ScrivasML_sai_suggestions_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYXSecret ScrivasML_soniox_transcriber_Stage has been accessed recently, last accessed on August 12, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmTSecret ScrivasML_soniox_transcriber_Prod has been accessed recently, last accessed on August 13, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWwSecret ScrivasML_Monitoring_Dev has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqUSecret ScrivasML_Monitoring_Stage has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4Secret ScrivasML_Monitoring_Prod has been accessed recently, last accessed on July 19, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

PASSmediumsecretsmanagerus-east-2secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysarn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9Secret ScrivasBKPatientDev has been accessed recently, last accessed on July 29, 2026.

Unused yet valid secrets jeopardize confidentiality and integrity:
+- Reuse by ex-users or leaked code enables unauthorized access
+- Limited rotation/revocation increases stealth persistence and data exfiltration
+- Secret sprawl adds operational risk and extra cost

Apply a lifecycle policy for secrets:
+- Require ownership tags and periodic reviews
+- Rotate or disable, then retire secrets unused beyond policy
+- Enforce least privilege and monitor retrievals with alerts
+- Automate cleanup using recovery windows to prevent accidental loss

+•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24 + +•SecNumCloud-3.2: 10.5 + +•AWS-AI-Security-Framework-1.0: AISF-DATA-03 + +•NIS2: 9.2.c.iv +

FAILhighsecurityhubus-east-1securityhub_delegated_admin_enabled_all_regionsSecurity Hub has delegated admin configured and is enabled in all regions with organization auto-enablearn:aws:securityhub:us-east-1:716468089330:hub/defaultSecurity Hub in region us-east-1 has issues: no delegated administrator configured.

Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization.

Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization.

FAILhighsecurityhubus-east-2securityhub_delegated_admin_enabled_all_regionsSecurity Hub has delegated admin configured and is enabled in all regions with organization auto-enablearn:aws:securityhub:us-east-2:716468089330:hub/defaultSecurity Hub in region us-east-2 has issues: no delegated administrator configured.

Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization.

Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization.

PASShighsecurityhubus-east-1securityhub_enabledSecurity Hub is enabled with standards or integrations configuredarn:aws:securityhub:us-east-1:716468089330:hub/defaultSecurity Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices .

Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions.

    +
  • Enable in all required accounts/Regions
  • +
  • Turn on relevant standards (AWS FSBP, CIS)
  • +
  • Connect AWS and third-party integrations
  • +
  • Use central configuration and least privilege
  • +
  • Automate triage and monitor continuously for defense in depth
  • +

+•CISA: your-systems-3, your-crisis-response-2 + +•CIS-7.0: 5.16 + +•SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.5: 4.16 + +•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 4.16 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•GxP-EU-Annex-11: 1-risk-management + +•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3 + +•CIS-5.0: 4.16 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31 + +•AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account + +•CIS-3.0: 4.16 + +•ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1 + +•CIS-6.0: 5.16 + +•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8 + +•SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.17 + +•ISO27001-2022: A.5.1, A.8.23 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-04 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4 + +•CIS-4.0.1: 4.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighsecurityhubus-east-2securityhub_enabledSecurity Hub is enabled with standards or integrations configuredarn:aws:securityhub:us-east-2:716468089330:hub/defaultSecurity Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices .

Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions.

    +
  • Enable in all required accounts/Regions
  • +
  • Turn on relevant standards (AWS FSBP, CIS)
  • +
  • Connect AWS and third-party integrations
  • +
  • Use central configuration and least privilege
  • +
  • Automate triage and monitor continuously for defense in depth
  • +

+•CISA: your-systems-3, your-crisis-response-2 + +•CIS-7.0: 5.16 + +•SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4 + +•CIS-1.5: 4.16 + +•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580 + +•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i + +•CIS-2.0: 4.16 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•GxP-21-CFR-Part-11: 11.300-d + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04 + +•GxP-EU-Annex-11: 1-risk-management + +•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3 + +•CIS-5.0: 4.16 + +•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9 + +•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4 + +•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31 + +•AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account + +•CIS-3.0: 4.16 + +•ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1 + +•CIS-6.0: 5.16 + +•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8 + +•SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3 + +•ProwlerThreatScore-1.0: 3.3.17 + +•ISO27001-2022: A.5.1, A.8.23 + +•AWS-AI-Security-Framework-1.0: AISF-DETECT-04 + +•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c + +•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4 + +•CIS-4.0.1: 4.16 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr +

PASShighsnsus-east-2sns_subscription_not_using_http_endpointsSNS subscription uses an HTTPS endpointarn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8 is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

+•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: dp_4 + +•CCC-v2025.10: CCC.Core.CN01.AR01 +

PASShighsnsus-east-2sns_subscription_not_using_http_endpointsSNS subscription uses an HTTPS endpointarn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93 is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

+•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: dp_4 + +•CCC-v2025.10: CCC.Core.CN01.AR01 +

PASShighsnsus-east-2sns_subscription_not_using_http_endpointsSNS subscription uses an HTTPS endpointarn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769abSubscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769ab is using an HTTPS endpoint.

Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions.

Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth.

+•KISA-ISMS-P-2023: 2.7.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2 + +•NIST-CSF-2.0: dp_4 + +•CCC-v2025.10: CCC.Core.CN01.AR01 +

FAILhighsnsus-east-2sns_topics_kms_encryption_at_rest_enabledSNS topic is encrypted at rest with KMSarn:aws:sns:us-east-2:716468089330:scrivas-alertsSNS topic scrivas-alerts is not encrypted.

Without KMS-backed SSE, SNS stores message bodies unencrypted at rest, undermining confidentiality.
+
+Privileged insiders or compromised service components could access plaintext during persistence windows, causing data exposure. You also lose KMS controls such as key policies, rotation, and detailed audit trails.

Enable server-side encryption on all SNS topics with AWS KMS; prefer customer-managed keys for control.
+
+Apply least privilege on key use, enforce rotation, and monitor key/access logs. Minimize sensitive data in messages and use end-to-end encryption where feasible to add defense in depth.

+•CISA: your-systems-3, your-data-1, your-data-2 + +•SOC2: pi_1_4 + +•MITRE-ATTACK: T1530 + +•GDPR: article_32 + +•AWS-Foundational-Security-Best-Practices: SNS.1 + +•KISA-ISMS-P-2023: 2.7.2, 2.10.2 + +•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01B, CRY-05.02B, CRY-05.01AC, PSS-10.01B, PSS-12.02B + +•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii + +•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2 + +•GxP-21-CFR-Part-11: 11.30 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04 + +•GxP-EU-Annex-11: 7.1-data-storage-damage-protection + +•NIST-CSF-2.0: be_5 + +•NIST-800-171-Revision-2: 3_13_11, 3_13_16 + +•PCI-4.0: 3.5.1.35, 8.3.2.54 + +•NIST-800-53-Revision-4: sc_28 + +•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1 + +•AWS-Foundational-Technical-Review: SDAT-002 + +•NIST-CSF-1.1: ds_1 + +•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.Message.CN01.AR01 + +•SecNumCloud-3.2: 10.1 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a + +•ISO27001-2022: A.8.3, A.8.11, A.8.24 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-05 + +•FedRamp-Moderate-Revision-4: sc-13, sc-28 + +•FedRAMP-Low-Revision-4: sc-13 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-svc +

PASShighsnsus-east-2sns_topics_not_publicly_accessibleSNS topic is not publicly accessiblearn:aws:sns:us-east-2:716468089330:scrivas-alertsSNS topic scrivas-alerts is not public because its policy only allows access from the account 716468089330.

Public SNS topics allow anyone or unknown accounts to:
+- Subscribe and siphon messages (confidentiality)
+- Publish spoofed payloads that alter workflows (integrity)
+- Flood messages causing outages and costs (availability)
+They also enable cross-account abuse and bypass expected trust boundaries.

Restrict the topic policy to specific principals and minimal actions:
+- Avoid Principal:*
+- Allow only needed actions (e.g., sns:Publish)
+- Add conditions like aws:SourceArn, aws:SourceAccount, aws:PrincipalOrgID, or sns:Endpoint
+Apply least privilege, separate duties, and review policies regularly.

+•CIS-7.0: 2.21 + +•ISO27001-2013: A.12.6.F, A.13.1.E + +•KISA-ISMS-P-2023: 2.5.6, 2.10.2 + +•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B + +•KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•ProwlerThreatScore-1.0: 2.3.1 + +•ISO27001-2022: A.8.1 +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 +•Name=Ml_prod +EC2 managed instance i-0055a6b877ba156e7 is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e +•Name=Scrivas_dev_env +EC2 managed instance i-010066e6c9027aa6e is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

FAILhighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db +•Name=Netbird_scrivas +EC2 managed instance i-02754e7ae419cd5db is non-compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 +•Name=ML_stage +EC2 managed instance i-046e7fc4677eaa796 is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb +•Name=Scrivas_stage_env +EC2 managed instance i-067bdb5e3e09fa4bb is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd +•Name=scrivas_prod_env +EC2 managed instance i-073154fb4fa773bbd is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

PASShighssmus-east-2ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsarn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b +•Name=ML_dev +EC2 managed instance i-095bd68aff22b103b is compliant.

Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
+
+This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages).

Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
+
+Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting.

+•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3 + +•SOC2: cc_3_2, cc_7_1 + +•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3 + +•KISA-ISMS-P-2023: 2.10.2, 2.10.8 + +•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B + +•HIPAA: 164_308_a_5_ii_b + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8 + +•GxP-21-CFR-Part-11: 11.10-a, 11.10-h + +•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01 + +•NIST-CSF-2.0: ac_3 + +•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3 + +•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7 + +•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2 + +•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1 + +•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2 + +•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2 + +•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12 + +•SecNumCloud-3.2: 12.10 + +•RBI-Cyber-Security-Framework: annex_i_6 + +•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5 + +•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b + +•ISO27001-2022: A.8.27 + +•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1 + +•FedRAMP-Low-Revision-4: cm-2, cm-8 + +•NIS2: 6.6.1.a + +•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr +

FAILmediumssmincidentsus-east-2ssmincidents_enabled_with_plansSSM Incidents replication set is ACTIVE and has at least one response planarn:aws:ssm-incidents:us-east-2:716468089330:replication-setNo SSM Incidents replication set exists.

Without an ACTIVE replication set or response plans, incidents lack coordinated engagement and automation, raising MTTR and impacting availability and integrity.
+
+Threats include prolonged outages, lateral movement, and data exfiltration from delayed containment and misrouted escalation.

Establish an ACTIVE replication set and create response plans that define engagement, escalation, runbooks, severity, and communication.
+
+Apply least privilege to automation roles, test plans regularly, integrate with monitoring to trigger them, and use defense in depth with redundant contacts and Regions.

+•KISA-ISMS-P-2023: 2.10.2, 2.11.1 + +•C5-2025: OIS-03.02B, OIS-03.05B, OIS-03.06B, OIS-05.03B, OIS-08.01B, OIS-08.09B, OPS-13.02B, OPS-13.03AC, OPS-22.08B, DEV-15.01B, SIM-01.02AC, SIM-02.01B, SIM-03.01B, SIM-03.04B, SIM-04.01B, SIM-06.01B, BCM-01.05B + +•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.1 + +•NIST-CSF-2.0: ip_9, rp_1 + +•ENS-RD2022: op.exp.9.aws.img.1 + +•NIS2: 2.1.1, 2.1.2.a, 2.1.2.i, 3.1.1, 3.1.2.a, 3.1.2.c, 3.1.2.d, 3.5.1, 3.6.1, 3.6.2, 3.6.3, 4.3.1, 5.1.7.b, 12.1.2.c, 12.2.2.b +

MANUALmediumtrustedadvisorus-east-1trustedadvisor_errors_and_warningsTrusted Advisor check has no errors or warningsarn:aws:trusted-advisor:us-east-1:716468089330:accountAmazon Web Services Premium Support Subscription is required to use this service.

Unaddressed warnings/errors can leave misconfigurations that impact CIA:
+- Confidentiality: public access or weak auth exposes data
+- Integrity: overly permissive settings allow unwanted changes
+- Availability: limit exhaustion or poor resilience triggers outages
+They can also increase unnecessary cost.

Adopt a continuous process to remediate Trusted Advisor findings:
+- Prioritize error then warning
+- Assign ownership and SLAs
+- Integrate alerts with workflows
+- Enforce least privilege, segmentation, encryption, MFA, and tested backups
+- Reassess regularly to confirm fixes and prevent regression

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3 + +•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3 +

FAILlowtrustedadvisorus-east-1trustedadvisor_premium_support_plan_subscribedAWS account is subscribed to an AWS Premium Support planarn:aws:trusted-advisor:us-east-1:716468089330:accountAmazon Web Services Premium Support Plan isn't subscribed.

Without Premium Support, critical incidents face slower response, reducing availability and delaying containment of security events. Limited Trusted Advisor coverage lets misconfigurations persist, risking data exposure and privilege misuse. Lack of expert guidance increases change risk during production impacts.

Adopt Business or higher for production and mission-critical accounts.
+- Integrate Support into IR with defined contacts/severity
+- Enforce least privilege for case access
+- Use Trusted Advisor for proactive hardening
+- If opting out, ensure an equivalent 24/7 support and escalation path

+•C5-2025: SSO-05.06B + +•NIST-CSF-2.0: rm_1, po_3, po_4, ov_3 + +•FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-tpr +

FAILmediumvpcus-east-2vpc_different_regionsVPCs are present in more than one regionarn:aws:ec2:us-east-2:716468089330:vpcVPCs found only in one region.

Single-region VPC deployment weakens availability and resilience. A regional outage, service disruption, or network control misconfiguration can cause broad downtime, hinder recovery, and increase the blast radius of incidents impacting business continuity.

Adopt a multi-region network design:
+- Create VPCs in at least two regions for critical workloads
+- Replicate routing, security controls, and endpoints consistently
+- Apply fault tolerance and defense in depth with data replication and resilient DNS/failover to avoid single-region dependency

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 +

FAILhighvpcus-east-2vpc_endpoint_connections_trust_boundariesVPC endpoint policy allows access only from trusted AWS accountsarn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d +•GuardDutyManaged=true +VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c can be accessed from non-trusted accounts.

Non-trusted principals using your endpoint can access AWS services as if from your VPC, weakening segmentation. This enables unauthorized reads/writes and data exfiltration from resources tied to the endpoint, harming confidentiality and integrity, and potentially increasing costs.

Apply least privilege: restrict endpoint policies to your account and an explicit allowlist of trusted accounts. Avoid * principals unless coupled with strict conditions. Prevent transitive trust across network links, and use resource policies and monitoring as defense in depth to limit endpoint use.

+•CISA: your-systems-3 + +•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2 + +•C5-2025: COS-03.01B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2 + +•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP01 + +•NIST-CSF-2.0: rr_1, po_3, ov_3, ra_5, ac_5, ae_1 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•CCC-v2025.10: CCC.Core.CN05.AR03, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.Core.CN05.AR06, CCC.LB.CN09.AR01 + +•SecNumCloud-3.2: 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 + +•NIS2: 6.8.2.a +

FAILmediumvpcus-east-2vpc_endpoint_for_ec2_enabledVPC has an Amazon EC2 VPC endpointarn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361VPC vpc-027f26d26f17ab361 has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
+- Enable private DNS to keep calls on the AWS network
+- Apply restrictive endpoint policies (least privilege)
+- Reduce reliance on public egress and layer controls for defense in depth

+•AWS-Foundational-Security-Best-Practices: EC2.10 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: ra_5, ae_1 + +•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumvpcus-east-2vpc_endpoint_for_ec2_enabledVPC has an Amazon EC2 VPC endpointarn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c +•Name=Scrivas_prod_vpc +VPC vpc-074cd9d22ca5c317c has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
+- Enable private DNS to keep calls on the AWS network
+- Apply restrictive endpoint policies (least privilege)
+- Reduce reliance on public egress and layer controls for defense in depth

+•AWS-Foundational-Security-Best-Practices: EC2.10 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: ra_5, ae_1 + +•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumvpcus-east-2vpc_endpoint_for_ec2_enabledVPC has an Amazon EC2 VPC endpointarn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 +•Name=Scrivas_vpc +VPC vpc-03b6368ab9a21d2c7 has no EC2 endpoint.

Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail.

Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
+- Enable private DNS to keep calls on the AWS network
+- Apply restrictive endpoint policies (least privilege)
+- Reduce reliance on public egress and layer controls for defense in depth

+•AWS-Foundational-Security-Best-Practices: EC2.10 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: ra_5, ae_1 + +•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38 + +•CCC-v2025.10: CCC.Core.CN05.AR05 + +•PCI-3.2.1: 1.3, 2.2, 2.2.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

PASSmediumvpcus-east-2vpc_endpoint_multi_az_enabledAmazon VPC interface endpoint has subnets in multiple Availability Zonesarn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d +•GuardDutyManaged=true +VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c has subnets in different AZs.

A single-subnet endpoint creates a single-AZ dependency. An AZ outage or routing issue can cut access to the service, reducing availability. Workloads may revert to public endpoints, exposing traffic to the Internet and risking confidentiality through interception or tampering.

Place interface endpoints in multiple subnets across distinct AZs to remove single-AZ reliance. Prefer zone-local routing so clients use the nearest endpoint, and combine with private DNS and restrictive security groups to limit exposure-supporting defense in depth and resilient connectivity.

+•KISA-ISMS-P-2023: 2.9.2 + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, pt_5 + +•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22 +

PASSmediumvpcus-east-2vpc_flow_logs_enabledVPC flow logs are enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361VPC vpc-027f26d26f17ab361 Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
+Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

+•CISA: your-surroundings-1, your-data-2 + +•CIS-7.0: 4.7 + +•SOC2: cc_7_2, cc_7_3 + +•CIS-1.4: 3.9 + +•CIS-1.5: 3.9 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: EC2.6 + +•ISO27001-2013: A.12.4.R + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 + +•CIS-2.0: 3.9 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 + +•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 + +•CIS-5.0: 3.7 + +•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 + +•NIST-800-53-Revision-4: au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 + +•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket + +•CIS-3.0: 3.7 + +•ENS-RD2022: op.mon.1.aws.flow.1 + +•CIS-6.0: 4.7 + +•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 + +•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 + +•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 + +•ProwlerThreatScore-1.0: 3.1.4 + +•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 + +•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: au-2 + +•CIS-4.0.1: 3.7 + +•NIS2: 3.2.3.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediumvpcus-east-2vpc_flow_logs_enabledVPC flow logs are enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c +•Name=Scrivas_prod_vpc +VPC Scrivas_prod_vpc Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
+Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

+•CISA: your-surroundings-1, your-data-2 + +•CIS-7.0: 4.7 + +•SOC2: cc_7_2, cc_7_3 + +•CIS-1.4: 3.9 + +•CIS-1.5: 3.9 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: EC2.6 + +•ISO27001-2013: A.12.4.R + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 + +•CIS-2.0: 3.9 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 + +•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 + +•CIS-5.0: 3.7 + +•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 + +•NIST-800-53-Revision-4: au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 + +•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket + +•CIS-3.0: 3.7 + +•ENS-RD2022: op.mon.1.aws.flow.1 + +•CIS-6.0: 4.7 + +•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 + +•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 + +•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 + +•ProwlerThreatScore-1.0: 3.1.4 + +•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 + +•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: au-2 + +•CIS-4.0.1: 3.7 + +•NIS2: 3.2.3.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediumvpcus-east-2vpc_flow_logs_enabledVPC flow logs are enabledarn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 +•Name=Scrivas_vpc +VPC Scrivas_vpc Flow logs are enabled.

Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability.

Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
+Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth.

+•CISA: your-surroundings-1, your-data-2 + +•CIS-7.0: 4.7 + +•SOC2: cc_7_2, cc_7_3 + +•CIS-1.4: 3.9 + +•CIS-1.5: 3.9 + +•GDPR: article_25, article_30 + +•AWS-Foundational-Security-Best-Practices: EC2.6 + +•ISO27001-2013: A.12.4.R + +•KISA-ISMS-P-2023: 2.9.4, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS + +•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2 + +•CIS-2.0: 3.9 + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2 + +•GxP-21-CFR-Part-11: 11.10-e + +•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04 + +•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1 + +•CIS-5.0: 3.7 + +•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7 + +•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34 + +•NIST-800-53-Revision-4: au_2, au_3, au_12 + +•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8 + +•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket + +•CIS-3.0: 3.7 + +•ENS-RD2022: op.mon.1.aws.flow.1 + +•CIS-6.0: 4.7 + +•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1 + +•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01 + +•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3 + +•RBI-Cyber-Security-Framework: annex_i_7_4 + +•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3 + +•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1 + +•ProwlerThreatScore-1.0: 3.1.4 + +•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 + +•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c + +•FedRAMP-Low-Revision-4: au-2 + +•CIS-4.0.1: 3.7 + +•NIS2: 3.2.3.c + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediumvpcus-east-2vpc_subnet_different_azVPC has subnets in more than one Availability Zonearn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361VPC vpc-027f26d26f17ab361 has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 + +•SecNumCloud-3.2: 17.2 + +•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22 +

PASSmediumvpcus-east-2vpc_subnet_different_azVPC has subnets in more than one Availability Zonearn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c +•Name=Scrivas_prod_vpc +VPC Scrivas_prod_vpc has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 + +•SecNumCloud-3.2: 17.2 + +•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22 +

PASSmediumvpcus-east-2vpc_subnet_different_azVPC has subnets in more than one Availability Zonearn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 +•Name=Scrivas_vpc +VPC Scrivas_vpc has subnets in more than one availability zone.

Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives.

Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience.

+•KISA-ISMS-P-2023: 2.9.2 + +•C5-2025: PS-02.01B, PS-02.02AS + +•KISA-ISMS-P-2023-korean: 2.9.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1 + +•SecNumCloud-3.2: 17.2 + +•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22 +

FAILhighvpcus-east-2vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultarn:aws:ec2:us-east-2:716468089330:subnet/subnet-028925e3b66ac3546VPC subnet subnet-028925e3b66ac3546 assigns public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
+
+When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.15 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILhighvpcus-east-2vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultarn:aws:ec2:us-east-2:716468089330:subnet/subnet-05e591b90cc4ce834VPC subnet subnet-05e591b90cc4ce834 assigns public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
+
+When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.15 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

PASShighvpcus-east-2vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultarn:aws:ec2:us-east-2:716468089330:subnet/subnet-029a31cc702e7daaa +•Name=prod-public-1b +VPC subnet prod-public-1b does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
+
+When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.15 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

PASShighvpcus-east-2vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultarn:aws:ec2:us-east-2:716468089330:subnet/subnet-0cd1dad930562f3cd +•Name=prod-public-1a +VPC subnet prod-public-1a does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
+
+When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.15 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

PASShighvpcus-east-2vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultarn:aws:ec2:us-east-2:716468089330:subnet/subnet-04082d4e496af0c4c +•Name=Scrivas_subnet1 +VPC subnet Scrivas_subnet1 does NOT assign public IP by default.

Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS.

Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
+
+When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth.

+•SOC2: cc_6_6 + +•AWS-Foundational-Security-Best-Practices: EC2.15 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 9.7 + +•RBI-Cyber-Security-Framework: annex_i_1_3 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumvpcus-east-2vpc_subnet_separate_private_publicVPC has both public and private subnetsarn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361VPC vpc-027f26d26f17ab361 has only public subnets.

Missing subnet separation erodes segmentation.
+- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
+- Only private: no controlled egress can break patching and dependencies, impacting availability.
+- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumvpcus-east-2vpc_subnet_separate_private_publicVPC has both public and private subnetsarn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c +•Name=Scrivas_prod_vpc +VPC Scrivas_prod_vpc has only public subnets.

Missing subnet separation erodes segmentation.
+- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
+- Only private: no controlled egress can break patching and dependencies, impacting availability.
+- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumvpcus-east-2vpc_subnet_separate_private_publicVPC has both public and private subnetsarn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 +•Name=Scrivas_vpc +VPC Scrivas_vpc has only public subnets.

Missing subnet separation erodes segmentation.
+- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
+- Only private: no controlled egress can break patching and dependencies, impacting availability.
+- No subnets: misconfiguration leaves services unreachable.

Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns.

+•SOC2: cc_6_6 + +•KISA-ISMS-P-2023: 2.6.1, 2.10.2 + +•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B + +•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2 + +•NIST-CSF-2.0: be_5, ac_5 + +•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1 + +•AWS-Foundational-Technical-Review: NETSEC-002 + +•SecNumCloud-3.2: 13.2 + +•ISO27001-2022: A.8.20, A.8.21, A.8.22 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-08 +

FAILmediumwafv2us-east-2wafv2_webacl_logging_enabledAWS WAFv2 Web ACL has logging enabledarn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8dAWS WAFv2 Web ACL acl-alb-ec2-general does not have logging enabled.

Without WAF logging, visibility into allowed/blocked requests is lost, degrading detection and response. SQLi, credential stuffing, and bot/DDoS probes can go unnoticed, risking data exposure (C), undetected rule misuse (I), and service instability from unseen abuse (A).

Enable logging on all WAFv2 Web ACLs to a centralized destination. Apply least privilege for log delivery, redact sensitive fields, and filter to retain high-value events. Integrate with monitoring/SIEM for alerting and correlation, and review routinely as part of defense in depth.

+•SOC2: cc_a_1_1, pi_1_2 + +•AWS-Foundational-Security-Best-Practices: WAF.11 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•PCI-4.0: 10.2.1.1.35, 10.2.1.2.30, 10.2.1.3.30, 10.2.1.4.30, 10.2.1.5.30, 10.2.1.6.30, 10.2.1.7.30, 10.2.1.30, 10.2.2.30, 10.3.1.30, 10.6.3.40, 5.3.4.35, A1.2.1.35 + +•AWS-Account-Security-Onboarding: Export metrics in centralized collector + +•CCC-v2025.10: CCC.LB.CN01.AR02 + +•SecNumCloud-3.2: 12.6 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-03 + +•NIS2: 3.2.3.c, 11.2.2.f + +•FedRAMP-20x-KSI-Low-25.05C: ksi-mla +

PASSmediumwafv2us-east-2wafv2_webacl_rule_logging_enabledAWS WAFv2 Web ACL has Amazon CloudWatch metrics enabled for all rules and rule groupsarn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8dAWS WAFv2 Web ACL acl-alb-ec2-general does have CloudWatch Metrics enabled in all its rules.

Absent CloudWatch metrics, WAF telemetry is lost, masking spikes, rule bypasses, and misconfigurations. This delays detection of SQLi/XSS probes and bot floods, risking data confidentiality, request integrity, and application availability.

Enable CloudWatch metrics for all WAF rules and rule groups (including managed rule groups). Use consistent metric names, centralize dashboards and alerts, and review trends to validate rule efficacy. Integrate with a SIEM for defense in depth and tune rules based on telemetry.

+•SOC2: cc_a_1_1 + +•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2 + +•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B + +•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2 + +•PCI-4.0: 10.2.1.1.36, 10.4.1.1.7, 10.4.1.6, 10.4.2.7, 10.6.3.41, 10.7.1.8, 10.7.2.8, A3.3.1.11, A3.5.1.11 + +•ISO27001-2022: A.8.15, A.8.16 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-03 + +•NIS2: 3.2.3.c +

PASShighwafv2us-east-2wafv2_webacl_with_rulesAWS WAFv2 Web ACL has at least one rule or rule group attachedarn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8dAWS WAFv2 Web ACL acl-alb-ec2-general does have rules or rule groups attached.

Without rules, traffic is governed only by the web ACL DefaultAction, often allowing requests without inspection. This increases risks to confidentiality (data exfiltration via injection), integrity (XSS/parameter tampering), and availability (layer-7 DDoS, bot abuse).

Populate each web ACL with targeted rules or managed rule groups to enforce least-privilege web access: cover common exploits (SQLi/XSS), IP reputation, and rate limits, scoped to your apps. Use a conservative DefaultAction, monitor metrics/logs, and continually tune-supporting defense in depth and zero trust.

+•KISA-ISMS-P-2023: 2.10.1, 2.10.2 + +•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2 + +•PCI-4.0: 6.4.1.8, 6.4.2.8 + +•CCC-v2025.10: CCC.LB.CN01.AR01 + +•SecNumCloud-3.2: 13.2 + +•AWS-AI-Security-Framework-1.0: AISF-INFRA-03 +

+
+
+ + + + + + + + + + + diff --git a/index.html b/index.html new file mode 100644 index 0000000..4f429aa --- /dev/null +++ b/index.html @@ -0,0 +1,101 @@ + + + + + +Scrivas — AWS Discovery Reports + + + +
+
Dasnuve · Cloud Discovery
+

Scrivas — AWS Discovery Reports

+

Read-only assessment of the Scrivas AWS Organization (o-qfj0pvhhv7) — footprint, + security posture, cost, and Organizations governance. Prepared to inform a proposal.

+
2 accounts · us-east-2 primary · generated 2026-08-19 · CONFIDENTIAL
+ + + +
+

Written report & raw evidence

+
    +
  • discovery_report.md — narrative writeup (renders on GitHub)
  • +
  • findings/org_assessment_report.json — org / trust / delegated-admin raw data
  • +
  • findings/fast_discovery.json — footprint, security, cost raw data
  • +
  • findings/member_lazka_547868853286.json — member account raw data
  • +
+
+ +
+ Confidential — private repo only. These reports contain AWS account IDs, role ARNs, external IDs, and live + security findings for a prospective client. The large raw Prowler scans (*.ocsf.json, *.csv) + are intentionally git-ignored; regenerate them with pipenv run prowler aws … if needed. +
+ + +
+ + diff --git a/scripts/assess_member_account.py b/scripts/assess_member_account.py new file mode 100644 index 0000000..8a9ee2a --- /dev/null +++ b/scripts/assess_member_account.py @@ -0,0 +1,157 @@ +#!/usr/bin/env python3 +""" +Member-Account Trust Assessment +================================ +Extends the org assessment into a member account by assuming a cross-account +role from the management-account profile, then evaluating that account's +IAM role trust relationships and any delegated services it is aware of. + +Delegated administrators & trusted-access services are ORG-LEVEL and can only +be read from the management account, so this focuses on what is meaningful +from inside a member account: IAM role trust policies (service / cross-account +/ federated) and account-level org context. + +Usage: + python3 assess_member_account.py --account 547868853286 [--name Lazka] + [--role OrganizationAccountAccessRole] [--profile PROFILE] +""" +import argparse +import json +import os +import sys +from datetime import datetime, date, timezone + +import boto3 +from botocore.exceptions import ClientError, BotoCoreError + +DEFAULT_PROFILE = "dasnuve-scrivas-louis-impersonation" +FINDINGS_DIR = os.path.join( + os.path.dirname(os.path.dirname(os.path.abspath(__file__))), "findings") + +VENDOR_ACCOUNTS = { + "123311413059": "Intruder.io (external vulnerability scanning)", + "728997465891": "Secureframe (SOC 2 / compliance automation)", +} + + +def _default(o): + if isinstance(o, (datetime, date)): + return o.isoformat() + return str(o) + + +def paginate(client, op, key, **kwargs): + out = [] + try: + for page in client.get_paginator(op).paginate(**kwargs): + out.extend(page.get(key, [])) + except (ClientError, BotoCoreError) as e: + return out, str(e) + return out, None + + +def assume(session, account_id, role_name, candidate_roles): + """Try the primary role, then fall back through candidate role names.""" + sts = session.client("sts") + tried = [role_name] + [r for r in candidate_roles if r != role_name] + errors = {} + for rn in tried: + arn = f"arn:aws:iam::{account_id}:role/{rn}" + try: + creds = sts.assume_role( + RoleArn=arn, RoleSessionName="scrivas-discovery")["Credentials"] + print(f"[+] Assumed {arn}") + return boto3.Session( + aws_access_key_id=creds["AccessKeyId"], + aws_secret_access_key=creds["SecretAccessKey"], + aws_session_token=creds["SessionToken"], + ), rn, None + except (ClientError, BotoCoreError) as e: + errors[rn] = str(e) + print(f"[-] {rn}: {e}") + return None, None, errors + + +def assess_iam_trust(member_session): + iam = member_session.client("iam") + roles, err = paginate(iam, "list_roles", "Roles") + if err: + return {"error": err} + trust = [] + for r in roles: + doc = r.get("AssumeRolePolicyDocument", {}) + flat = json.dumps(doc) + kind = [] + if '"Service"' in flat: + kind.append("service") + if '"AWS"' in flat: + kind.append("cross-account/aws") + if '"Federated"' in flat: + kind.append("federated") + vendor = None + for stmt in doc.get("Statement", []): + p = stmt.get("Principal", {}) + aws_p = p.get("AWS") if isinstance(p, dict) else None + for acct, name in VENDOR_ACCOUNTS.items(): + if aws_p and acct in json.dumps(aws_p): + vendor = name + trust.append({ + "RoleName": r["RoleName"], + "Path": r.get("Path"), + "Kind": kind, + "Vendor": vendor, + "AssumeRolePolicyDocument": doc, + }) + return trust + + +def main(): + ap = argparse.ArgumentParser() + ap.add_argument("--account", required=True) + ap.add_argument("--name", default="member") + ap.add_argument("--role", default="OrganizationAccountAccessRole") + ap.add_argument("--profile", default=DEFAULT_PROFILE) + args = ap.parse_args() + + session = boto3.Session(profile_name=args.profile) + + candidates = ["OrganizationAccountAccessRole", "AWSControlTowerExecution", + "OrganizationAccountAccessRole", "AdministratorAccess"] + member, role_used, err = assume(session, args.account, args.role, candidates) + + result = { + "generated": datetime.now(timezone.utc).isoformat(), + "account_id": args.account, + "account_name": args.name, + } + + if member is None: + result["access"] = {"assumed": False, "errors": err} + print("\n[!] Could not assume any cross-account role into " + f"{args.name} ({args.account}). This itself is a finding: no " + "management-account access path exists into the member account.") + else: + ident = member.client("sts").get_caller_identity() + result["access"] = {"assumed": True, "role_used": role_used, + "assumed_arn": ident["Arn"]} + result["iam_role_trust_policies"] = assess_iam_trust(member) + + roles = result["iam_role_trust_policies"] + if isinstance(roles, list): + xacct = [r for r in roles if "cross-account/aws" in r["Kind"]] + fed = [r for r in roles if "federated" in r["Kind"]] + print(f"\n[{args.name} / {args.account}] IAM roles: {len(roles)} | " + f"{len(xacct)} cross-account | {len(fed)} federated") + for r in xacct: + tag = f" [{r['Vendor']}]" if r.get("Vendor") else "" + print(f" - {r['RoleName']}{tag}") + + out = os.path.join(FINDINGS_DIR, f"member_{args.name.lower()}_{args.account}.json") + os.makedirs(FINDINGS_DIR, exist_ok=True) + with open(out, "w") as f: + json.dump(result, f, indent=2, default=_default) + print(f"\nWritten to: {out}") + + +if __name__ == "__main__": + sys.exit(main()) diff --git a/scripts/fast_discovery.py b/scripts/fast_discovery.py new file mode 100644 index 0000000..f57e395 --- /dev/null +++ b/scripts/fast_discovery.py @@ -0,0 +1,294 @@ +#!/usr/bin/env python3 +""" +Scrivas — Fast-Track Discovery (hours, not days) +================================================ +Read-only. Prioritizes the four highest-leverage phases: + - Cost baseline (Cost Explorer, payer account) + - Resource census (active regions only) + - Security exposure (public S3, open SGs, GuardDuty/SecurityHub/CloudTrail) + - IAM quick hits (users, MFA, key age, root usage, password policy) + +Runs across the whole org: management account directly, members via assume-role. +Profile is passed into the boto3 Session object. + +Usage: python3 fast_discovery.py [--profile PROFILE] +Output: findings/fast_discovery.json +""" +import argparse +import json +import os +import sys +from datetime import datetime, date, timezone, timedelta + +import boto3 +from botocore.exceptions import ClientError, BotoCoreError + +DEFAULT_PROFILE = "dasnuve-scrivas-louis-impersonation" +FINDINGS = os.path.join(os.path.dirname(os.path.dirname(os.path.abspath(__file__))), "findings") +MEMBER_ROLE = "OrganizationAccountAccessRole" + + +def _default(o): + return o.isoformat() if isinstance(o, (datetime, date)) else str(o) + + +def safe(fn, *a, **k): + try: + return fn(*a, **k), None + except (ClientError, BotoCoreError) as e: + return None, str(e) + + +def pg(client, op, key, **k): + out = [] + try: + for page in client.get_paginator(op).paginate(**k): + out.extend(page.get(key, [])) + except (ClientError, BotoCoreError) as e: + return out, str(e) + return out, None + + +# ---------------------------------------------------------------- regions +def active_regions(session): + """Enabled regions that actually contain EC2 instances or EBS volumes, + plus us-east-1 (global services). Keeps the scan fast.""" + ec2 = session.client("ec2", region_name="us-east-1") + regs, err = safe(ec2.describe_regions, AllRegions=False) + enabled = [r["RegionName"] for r in regs["Regions"]] if regs else ["us-east-1", "us-east-2"] + active = set(["us-east-1"]) + for r in enabled: + c = session.client("ec2", region_name=r) + insts, _ = safe(c.describe_instances, MaxResults=5) + if insts and any(res.get("Instances") for res in insts.get("Reservations", [])): + active.add(r); continue + vols, _ = safe(c.describe_volumes, MaxResults=5) + if vols and vols.get("Volumes"): + active.add(r) + return sorted(active), enabled + + +# ---------------------------------------------------------------- IAM +def iam_quickhits(session): + iam = session.client("iam") + out = {} + users, err = pg(iam, "list_users", "Users") + if err: + return {"error": err} + detail = [] + no_mfa = 0 + stale_keys = [] + for u in users: + name = u["UserName"] + mfa, _ = safe(iam.list_mfa_devices, UserName=name) + has_mfa = bool(mfa and mfa.get("MFADevices")) + if not has_mfa: + no_mfa += 1 + keys, _ = safe(iam.list_access_keys, UserName=name) + kinfo = [] + for k in (keys or {}).get("AccessKeyMetadata", []): + age = (datetime.now(timezone.utc) - k["CreateDate"]).days + lu, _ = safe(iam.get_access_key_last_used, AccessKeyId=k["AccessKeyId"]) + last = (lu or {}).get("AccessKeyLastUsed", {}).get("LastUsedDate") + kinfo.append({"id": k["AccessKeyId"][-4:], "status": k["Status"], + "age_days": age, "last_used": last}) + if age > 90: + stale_keys.append(f"{name}:***{k['AccessKeyId'][-4:]} ({age}d)") + detail.append({"user": name, "mfa": has_mfa, "keys": kinfo}) + pw, _ = safe(iam.get_account_password_policy) + summ, _ = safe(iam.get_account_summary) + out = { + "user_count": len(users), + "users_without_mfa": no_mfa, + "stale_keys_over_90d": stale_keys, + "password_policy": (pw or {}).get("PasswordPolicy", "none set"), + "account_summary": (summ or {}).get("SummaryMap", {}), + "users": detail, + } + return out + + +# ---------------------------------------------------------------- census + exposure +def census_and_exposure(session, regions): + census = {} + exposure = {"public_buckets": [], "open_security_groups": [], "public_rds": []} + + # S3 (global list, per-bucket public-access) + s3 = session.client("s3") + buckets, err = safe(s3.list_buckets) + blist = (buckets or {}).get("Buckets", []) + census["s3_buckets"] = len(blist) + for b in blist: + name = b["Name"] + pab, _ = safe(s3.get_public_access_block, Bucket=name) + cfg = (pab or {}).get("PublicAccessBlockConfiguration", {}) + blocked = all([cfg.get("BlockPublicAcls"), cfg.get("IgnorePublicAcls"), + cfg.get("BlockPublicPolicy"), cfg.get("RestrictPublicBuckets")]) + if not blocked: + exposure["public_buckets"].append( + {"bucket": name, "public_access_block": cfg or "none"}) + + # per-region compute/db/net + per_region = {} + for r in regions: + rr = {} + ec2 = session.client("ec2", region_name=r) + insts, _ = pg(ec2, "describe_instances", "Reservations") + rr["ec2_instances"] = sum(len(x.get("Instances", [])) for x in insts) + vols, _ = pg(ec2, "describe_volumes", "Volumes") + rr["ebs_volumes"] = len(vols) + rr["ebs_unattached"] = sum(1 for v in vols if not v.get("Attachments")) + eips, _ = safe(ec2.describe_addresses) + addrs = (eips or {}).get("Addresses", []) + rr["eips"] = len(addrs) + rr["eips_unassociated"] = sum(1 for a in addrs if not a.get("AssociationId")) + sgs, _ = pg(ec2, "describe_security_groups", "SecurityGroups") + for sg in sgs: + for perm in sg.get("IpPermissions", []): + for ipr in perm.get("IpRanges", []): + if ipr.get("CidrIp") == "0.0.0.0/0": + exposure["open_security_groups"].append({ + "region": r, "group": sg["GroupId"], + "from_port": perm.get("FromPort"), "to_port": perm.get("ToPort"), + "proto": perm.get("IpProtocol")}) + rds = session.client("rds", region_name=r) + dbs, _ = pg(rds, "describe_db_instances", "DBInstances") + rr["rds_instances"] = len(dbs) + for d in dbs: + if d.get("PubliclyAccessible"): + exposure["public_rds"].append({"region": r, "db": d["DBInstanceIdentifier"]}) + lam = session.client("lambda", region_name=r) + fns, _ = pg(lam, "list_functions", "Functions") + rr["lambda_functions"] = len(fns) + eks = session.client("eks", region_name=r) + clusters, _ = pg(eks, "list_clusters", "clusters") + rr["eks_clusters"] = len(clusters) + rr["eks_cluster_names"] = clusters + elbv2 = session.client("elbv2", region_name=r) + lbs, _ = pg(elbv2, "describe_load_balancers", "LoadBalancers") + rr["load_balancers"] = len(lbs) + per_region[r] = {k: v for k, v in rr.items() if v not in (0, [], None)} or {"(empty)": True} + census["by_region"] = per_region + return census, exposure + + +# ---------------------------------------------------------------- security services +def security_services(session, regions): + out = {} + # CloudTrail (any region lists org+shadow trails) + ct = session.client("cloudtrail", region_name="us-east-1") + trails, _ = safe(ct.describe_trails, includeShadowTrails=True) + tl = (trails or {}).get("trailList", []) + out["cloudtrail"] = [{"name": t["Name"], "multi_region": t.get("IsMultiRegionTrail"), + "org_trail": t.get("IsOrganizationTrail"), + "log_validation": t.get("LogFileValidationEnabled")} for t in tl] + # GuardDuty / SecurityHub per active region + gd_findings = {} + shub = {} + for r in regions: + g = session.client("guardduty", region_name=r) + dets, _ = safe(g.list_detectors) + for d in (dets or {}).get("DetectorIds", []): + stats, _ = safe(g.get_findings_statistics, DetectorId=d, + FindingCriteria={}, FindingStatisticTypes=["COUNT_BY_SEVERITY"]) + gd_findings[r] = (stats or {}).get("FindingStatistics", {}).get("CountBySeverity", {}) + s = session.client("securityhub", region_name=r) + desc, err = safe(s.describe_hub) + shub[r] = "enabled" if desc else "not enabled" + out["guardduty_findings_by_severity"] = gd_findings + out["securityhub"] = shub + return out + + +# ---------------------------------------------------------------- cost +def cost_baseline(session): + ce = session.client("ce", region_name="us-east-1") + end = date.today().replace(day=1) + start = (end - timedelta(days=185)).replace(day=1) + res, err = safe(ce.get_cost_and_usage, + TimePeriod={"Start": start.isoformat(), "End": end.isoformat()}, + Granularity="MONTHLY", Metrics=["UnblendedCost"], + GroupBy=[{"Type": "DIMENSION", "Key": "SERVICE"}]) + if err: + return {"error": err} + months = [] + service_totals = {} + for period in res["ResultsByTime"]: + m = period["TimePeriod"]["Start"] + total = 0.0 + for g in period["Groups"]: + amt = float(g["Metrics"]["UnblendedCost"]["Amount"]) + svc = g["Keys"][0] + service_totals[svc] = service_totals.get(svc, 0.0) + amt + total += amt + months.append({"month": m, "total": round(total, 2)}) + top = sorted(service_totals.items(), key=lambda x: -x[1])[:12] + return {"monthly_total": months, + "top_services_6mo": [{"service": s, "cost": round(v, 2)} for s, v in top]} + + +# ---------------------------------------------------------------- driver +def assess_account(session, account_id, name, is_payer): + print(f"\n=== {name} ({account_id}) ===") + regions, enabled = active_regions(session) + print(f" active regions: {regions} (of {len(enabled)} enabled)") + census, exposure = census_and_exposure(session, regions) + result = { + "account_id": account_id, "name": name, + "active_regions": regions, "enabled_region_count": len(enabled), + "iam": iam_quickhits(session), + "census": census, + "exposure": exposure, + "security_services": security_services(session, regions), + } + if is_payer: + result["cost"] = cost_baseline(session) + print(f" ec2/eks/rds/lambda scanned | public buckets: {len(exposure['public_buckets'])}" + f" | open SGs: {len(exposure['open_security_groups'])}" + f" | users w/o MFA: {result['iam'].get('users_without_mfa')}") + return result + + +def main(): + ap = argparse.ArgumentParser() + ap.add_argument("--profile", default=DEFAULT_PROFILE) + args = ap.parse_args() + + base = boto3.Session(profile_name=args.profile) + payer = base.client("sts").get_caller_identity()["Account"] + org = base.client("organizations") + accounts, _ = pg(org, "list_accounts", "Accounts") + + report = {"generated": datetime.now(timezone.utc).isoformat(), + "payer_account": payer, "accounts": []} + + for a in accounts: + if a["Status"] != "ACTIVE": + continue + aid, name = a["Id"], a["Name"] + if aid == payer: + sess = base + else: + sts = base.client("sts") + creds, err = safe(sts.assume_role, + RoleArn=f"arn:aws:iam::{aid}:role/{MEMBER_ROLE}", + RoleSessionName="scrivas-fast-discovery") + if err: + report["accounts"].append({"account_id": aid, "name": name, + "error": f"assume-role failed: {err}"}) + continue + c = creds["Credentials"] + sess = boto3.Session(aws_access_key_id=c["AccessKeyId"], + aws_secret_access_key=c["SecretAccessKey"], + aws_session_token=c["SessionToken"]) + report["accounts"].append(assess_account(sess, aid, name, aid == payer)) + + out = os.path.join(FINDINGS, "fast_discovery.json") + os.makedirs(FINDINGS, exist_ok=True) + with open(out, "w") as f: + json.dump(report, f, indent=2, default=_default) + print(f"\nWritten to: {out}") + + +if __name__ == "__main__": + sys.exit(main()) diff --git a/scripts/org_assessment.py b/scripts/org_assessment.py new file mode 100644 index 0000000..4d278a0 --- /dev/null +++ b/scripts/org_assessment.py @@ -0,0 +1,210 @@ +#!/usr/bin/env python3 +""" +Account Assessment for AWS Organizations +========================================= +Read-only discovery of an AWS Organization's governance posture. + +Scope: + 1. Trusted access services (org-enabled service principals) + 2. Delegated administrators (+ delegated services per admin) + 3. Trust policies (org resource policy + IAM role trust relationships) + +The AWS profile is passed into the boto3 Session object (never hard-coded creds). + +Usage: + python3 org_assessment.py [--profile PROFILE] [--out PATH.json] + +Client: Scrivas | Engagement: cloud footprint discovery +""" +import argparse +import json +import os +import sys +from datetime import datetime, date, timezone + +import boto3 +from botocore.exceptions import ClientError, BotoCoreError + +DEFAULT_PROFILE = "dasnuve-scrivas-louis-impersonation" +DEFAULT_OUT = os.path.join( + os.path.dirname(os.path.dirname(os.path.abspath(__file__))), + "findings", "org_assessment_report.json", +) + +# Known third-party vendor account IDs, for annotating cross-account trusts. +VENDOR_ACCOUNTS = { + "123311413059": "Intruder.io (external vulnerability scanning)", + "728997465891": "Secureframe (SOC 2 / compliance automation)", +} + + +def _default(o): + if isinstance(o, (datetime, date)): + return o.isoformat() + return str(o) + + +def dump(label, obj): + print(f"\n{'=' * 70}\n{label}\n{'=' * 70}") + print(json.dumps(obj, indent=2, default=_default)) + + +def safe(fn, *args, **kwargs): + """Call an API, returning (data, error_string).""" + try: + return fn(*args, **kwargs), None + except (ClientError, BotoCoreError) as e: + return None, str(e) + + +def paginate(client, op, key, **kwargs): + out = [] + try: + for page in client.get_paginator(op).paginate(**kwargs): + out.extend(page.get(key, [])) + except (ClientError, BotoCoreError) as e: + return out, str(e) + return out, None + + +def assess(session): + ident = session.client("sts").get_caller_identity() + org = session.client("organizations") + + report = { + "generated": datetime.now(timezone.utc).isoformat(), + "caller": {"Account": ident["Account"], "Arn": ident["Arn"]}, + } + + # Organization overview + o, err = safe(org.describe_organization) + report["organization"] = o.get("Organization") if o else {"error": err} + + # 1. Trusted access services + svcs, err = paginate(org, "list_aws_service_access_for_organization", + "EnabledServicePrincipals") + report["trusted_access_services"] = {"error": err} if err else svcs + + # 2. Delegated administrators (+ their delegated services) + admins, err = paginate(org, "list_delegated_administrators", + "DelegatedAdministrators") + if err: + report["delegated_administrators"] = {"error": err} + else: + for a in admins: + svc, serr = paginate(org, "list_delegated_services_for_account", + "DelegatedServices", AccountId=a["Id"]) + a["DelegatedServices"] = {"error": serr} if serr else svc + report["delegated_administrators"] = admins + + # 3a. Trust policies: organization resource-based policy + rp, err = safe(org.describe_resource_policy) + if err: + report["org_resource_policy"] = {"error": err} + else: + content = rp["ResourcePolicy"]["Content"] + report["org_resource_policy"] = json.loads(content) if content else None + + # 3b. Trust policies: IAM role assume-role (trust) policies + iam = session.client("iam") + roles, err = paginate(iam, "list_roles", "Roles") + if err: + report["iam_role_trust_policies"] = {"error": err} + else: + trust = [] + for r in roles: + doc = r.get("AssumeRolePolicyDocument", {}) + flat = json.dumps(doc) + kind = [] + if '"Service"' in flat: + kind.append("service") + if '"AWS"' in flat: + kind.append("cross-account/aws") + if '"Federated"' in flat: + kind.append("federated") + + statements = [] + vendor = None + for stmt in doc.get("Statement", []): + principal = stmt.get("Principal", {}) + aws_p = principal.get("AWS") if isinstance(principal, dict) else None + for acct, name in VENDOR_ACCOUNTS.items(): + if aws_p and acct in json.dumps(aws_p): + vendor = name + statements.append({ + "Effect": stmt.get("Effect"), + "Action": stmt.get("Action"), + "Principal": principal, + "Condition": stmt.get("Condition"), + }) + trust.append({ + "RoleName": r["RoleName"], + "Path": r.get("Path"), + "Arn": r["Arn"], + "Kind": kind, + "Vendor": vendor, + "Statements": statements, + }) + report["iam_role_trust_policies"] = trust + + return report + + +def summarize(report): + """One-line-per-item human summary of the key governance signals.""" + print(f"\n{'#' * 70}\n# SUMMARY\n{'#' * 70}") + org = report.get("organization", {}) + print(f"Org: {org.get('Id')} | mgmt acct {org.get('MasterAccountId')} " + f"({org.get('MasterAccountEmail')}) | FeatureSet {org.get('FeatureSet')}") + + svcs = report.get("trusted_access_services", []) + if isinstance(svcs, list): + print(f"Trusted access services: {len(svcs)} -> " + + ", ".join(s["ServicePrincipal"] for s in svcs)) + + admins = report.get("delegated_administrators", []) + if isinstance(admins, list): + flag = " <-- GAP: none set" if not admins else "" + print(f"Delegated administrators: {len(admins)}{flag}") + + roles = report.get("iam_role_trust_policies", []) + if isinstance(roles, list): + xacct = [r for r in roles if "cross-account/aws" in r["Kind"]] + fed = [r for r in roles if "federated" in r["Kind"]] + print(f"IAM roles: {len(roles)} total | {len(xacct)} cross-account | " + f"{len(fed)} federated") + for r in xacct: + tag = f" [{r['Vendor']}]" if r.get("Vendor") else "" + print(f" - {r['RoleName']}{tag}") + + +def main(): + ap = argparse.ArgumentParser(description=__doc__, + formatter_class=argparse.RawDescriptionHelpFormatter) + ap.add_argument("--profile", default=DEFAULT_PROFILE) + ap.add_argument("--out", default=DEFAULT_OUT) + ap.add_argument("--quiet", action="store_true", + help="skip verbose section dumps, print summary only") + args = ap.parse_args() + + session = boto3.Session(profile_name=args.profile) + report = assess(session) + + if not args.quiet: + dump("CALLER / ORG", + {"caller": report["caller"], "organization": report["organization"]}) + dump("1. TRUSTED ACCESS SERVICES", report["trusted_access_services"]) + dump("2. DELEGATED ADMINISTRATORS", report["delegated_administrators"]) + dump("3a. ORG RESOURCE POLICY", report["org_resource_policy"]) + dump("3b. IAM ROLE TRUST POLICIES", report["iam_role_trust_policies"]) + + summarize(report) + + os.makedirs(os.path.dirname(args.out), exist_ok=True) + with open(args.out, "w") as f: + json.dump(report, f, indent=2, default=_default) + print(f"\nFull JSON written to: {args.out}") + + +if __name__ == "__main__": + sys.exit(main())