Update proposal levers with Prowler benchmark findings #1

Merged
adelvalle merged 1 commits from update-proposal-levers into main 2026-08-19 15:23:08 -06:00
Owner

Expand the levers table from 5 to 8 workstreams, grounding each driver in
verified counts from the Prowler run:

  • Add backup & resilience (0 of 9 EBS volumes have snapshots or a backup plan)
  • Add secrets & key management (19 secrets without rotation or resource policy,
    2 KMS keys without auto-rotation, unencrypted log groups)
  • Add compliance acceleration (363 failures; SOC 2 at 81% against existing
    Secureframe program)
  • Note Config alongside GuardDuty and Security Hub in the delegated-admin gap
  • Add the two criticals and hardware-MFA gaps to identity hardening
  • Add internet-facing instances with instance profiles and IMDSv2 to exposure
  • Order by priority and add a framing note
Expand the levers table from 5 to 8 workstreams, grounding each driver in verified counts from the Prowler run: - Add backup & resilience (0 of 9 EBS volumes have snapshots or a backup plan) - Add secrets & key management (19 secrets without rotation or resource policy, 2 KMS keys without auto-rotation, unencrypted log groups) - Add compliance acceleration (363 failures; SOC 2 at 81% against existing Secureframe program) - Note Config alongside GuardDuty and Security Hub in the delegated-admin gap - Add the two criticals and hardware-MFA gaps to identity hardening - Add internet-facing instances with instance profiles and IMDSv2 to exposure - Order by priority and add a framing note
adelvalle added 1 commit 2026-08-19 15:23:04 -06:00
Expand the levers table from 5 to 8 workstreams, grounding each driver in
verified counts from the Prowler run:

- Add backup & resilience (0 of 9 EBS volumes have snapshots or a backup plan)
- Add secrets & key management (19 secrets without rotation or resource policy,
  2 KMS keys without auto-rotation, unencrypted log groups)
- Add compliance acceleration (363 failures; SOC 2 at 81% against existing
  Secureframe program)
- Note Config alongside GuardDuty and Security Hub in the delegated-admin gap
- Add the two criticals and hardware-MFA gaps to identity hardening
- Add internet-facing instances with instance profiles and IMDSv2 to exposure
- Order by priority and add a framing note
adelvalle merged commit 9e3d1f58d5 into main 2026-08-19 15:23:08 -06:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: adelvalle/scrivas#1