| PASS |
low |
accessanalyzer |
us-east-1 |
accessanalyzer_enabled |
IAM Access Analyzer is enabled |
arn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zd |
|
IAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd is enabled. |
Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity. |
Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes. |
•CIS-7.0: 2.18
•CIS-1.4: 1.20
•CIS-1.5: 1.20
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC
•CIS-2.0: 1.20
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6
•CIS-5.0: 1.19
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view
•CIS-3.0: 1.20
•CIS-6.0: 2.19
•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.2.6
•ISO27001-2022: A.8.3
•AWS-AI-Security-Framework-1.0: AISF-DATA-02
•CIS-4.0.1: 1.20
•NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e
|
| FAIL |
low |
accessanalyzer |
us-east-2 |
accessanalyzer_enabled |
IAM Access Analyzer is enabled |
arn:aws:accessanalyzer:us-east-2:716468089330:analyzer/unknown |
|
IAM Access Analyzer in account 716468089330 is not enabled. |
Without an active analyzer, visibility into unintended public, cross-account, or risky internal access is lost. Adversaries can exploit exposed S3, snapshots, KMS keys, or permissive role trusts for data exfiltration and escalation. Unused permissions persist, enlarging the attack surface. This degrades confidentiality and integrity. |
Enable IAM Access Analyzer across all accounts and active Regions (or organization-wide). Operate on least privilege: continuously review findings, remove unintended access, and trim unused permissions. Use archive rules sparingly, integrate reviews into change/CI/CD workflows, and enforce separation of duties on policy changes. |
•CIS-7.0: 2.18
•CIS-1.4: 1.20
•CIS-1.5: 1.20
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.04B, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B, PSS-09.01AC
•CIS-2.0: 1.20
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_3, po_4, ov_2, ov_3, ac_1, ac_6
•CIS-5.0: 1.19
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Enabled security services, Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view
•CIS-3.0: 1.20
•CIS-6.0: 2.19
•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.2.6
•ISO27001-2022: A.8.3
•AWS-AI-Security-Framework-1.0: AISF-DATA-02
•CIS-4.0.1: 1.20
•NIS2: 3.2.3.e, 11.1.1, 11.2.1, 11.2.2.e
|
| PASS |
low |
accessanalyzer |
us-east-1 |
accessanalyzer_enabled_without_findings |
IAM Access Analyzer analyzer is active and has no active findings |
arn:aws:access-analyzer:us-east-1:716468089330:analyzer/_AccessAnalyzerForSecurityHubV2-85b74fuq78zd |
|
IAM Access Analyzer _AccessAnalyzerForSecurityHubV2-85b74fuq78zd does not have active findings. |
Unresolved Active findings indicate unintended external or internal access paths.
- Confidentiality: public/cross-account reads of data (buckets, snapshots, secrets)
- Integrity: rogue role assumption or KMS use enabling policy/data changes
- Lateral movement across accounts |
Enable IAM Access Analyzer in all relevant Regions and org/account scopes. Triage every Active finding:
- Remove unintended access by tightening resource and trust policies
- Enforce least privilege and separation of duties
- Archive only validated, intended access
- Continuously monitor and automate reviews |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: AM-09.04AC, IAM-06.01AC, IAM-10.01B, IAM-10.02B, INQ-04.01AC, PSS-08.03B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: ov_2, ac_4, cm_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Create analyzers in each active regions, Verify that events are present in SecurityHub aggregated view
•AWS-Foundational-Technical-Review: SECOPS-001
•CCC-v2025.10: CCC.Core.CN05.AR04, CCC.IAM.CN11.AR01
•SecNumCloud-3.2: 9.4
•ISO27001-2022: A.8.3
•AWS-AI-Security-Framework-1.0: AISF-DATA-02
•NIS2: 2.1.2.g, 2.1.2.h
|
| MANUAL |
medium |
account |
us-east-2 |
account_maintain_current_contact_details |
AWS account contact information is current |
arn:aws:iam::716468089330:root |
|
Login to the AWS Console. Choose your account name on the top right of the window -> My Account -> Contact Information. |
Outdated or single-person contacts delay security notifications, slow incident response, and complicate account recovery.
AWS may throttle services during abuse mitigation, reducing availability. Missed alerts enable ongoing misuse, risking data exfiltration and unauthorized changes (integrity). |
Adopt:
- Primary and alternate contacts for security, billing, operations
- Shared, monitored aliases and SMS-capable phone numbers (non-personal)
- Centralized management across accounts with periodic reviews
- Least privilege for who can modify contact data
- Regular reachability tests and documented ownership |
•CIS-7.0: 2.2
•CIS-1.4: 1.1
•CIS-1.5: 1.1
•KISA-ISMS-P-2023: 2.10.2
•C5-2025: IAM-03.01AS, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B
•CIS-2.0: 1.1
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01
•CIS-5.0: 1.1
•AWS-Account-Security-Onboarding: Billing, emergency, security contacts
•CIS-3.0: 1.1
•ENS-RD2022: op.ext.7.aws.am.1
•CIS-6.0: 2.1
•ISO27001-2022: A.5.5
•AWS-AI-Security-Framework-1.0: AISF-GOV-03
•CIS-4.0.1: 1.1
•NIS2: 2.2.3, 3.5.3.a, 5.1.7.b
|
| FAIL |
medium |
account |
us-east-2 |
account_maintain_different_contact_details_to_security_billing_and_operations |
AWS account has distinct Security, Billing, and Operations contact details, different from each other and from the root contact |
arn:aws:iam::716468089330:root |
|
SECURITY, BILLING and OPERATIONS contacts not found or they are not different between each other and between ROOT contact. |
Missing or shared contacts can delay response to abuse alerts, credential compromise, or billing anomalies, reducing availability (possible AWS traffic throttling) and raising confidentiality and integrity risk through extended exposure. If AWS cannot reach you, urgent mitigation may disrupt service. |
Maintain distinct, monitored Security, Billing, and Operations alternate contacts that differ from the root contact.
- Use team aliases and 24x7 phones
- Review and test contact paths regularly
- Centralize at org level for consistency
Applies operational resilience and separation of duties. |
•KISA-ISMS-P-2023: 2.10.2
•C5-2025: OIS-04.03B, IAM-06.06B, SSO-05.06B, SIM-01.03B, INQ-02.01B
•KISA-ISMS-P-2023-korean: 2.10.2
•ISO27001-2022: A.5.6
•AWS-AI-Security-Framework-1.0: AISF-GOV-03
|
| MANUAL |
medium |
account |
us-east-2 |
account_security_contact_information_is_registered |
AWS account has security alternate contact registered |
arn:aws:iam::716468089330:root |
|
Login to the AWS Console. Choose your account name on the top right of the window -> My Account -> Alternate Contacts -> Security Section. |
Missing or outdated security contact can delay or prevent AWS advisories from reaching responders, increasing risk to:
- Confidentiality: data exfiltration from undetected compromise
- Integrity: unauthorized changes persist longer
- Availability: resource abuse (e.g., cryptomining) and outages |
Define and maintain a Security alternate contact:
- Use a monitored alias (e.g., security@domain) and team phone
- Apply to every account (prefer Org-wide automation)
- Review after org/personnel changes and test delivery
- Document ownership and escalation paths
Align with incident response and least privilege principles. |
•CIS-7.0: 2.3
•CIS-1.4: 1.2
•CIS-1.5: 1.2
•AWS-Foundational-Security-Best-Practices: Account.1
•KISA-ISMS-P-2023: 2.10.2
•C5-2025: OIS-06.01B, SSO-05.06B, SIM-01.03B
•CIS-2.0: 1.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01
•CIS-5.0: 1.2
•PCI-4.0: A1.2.3.1
•AWS-Account-Security-Onboarding: Billing, emergency, security contacts
•CIS-3.0: 1.2
•ENS-RD2022: op.ext.7.aws.am.1
•CIS-6.0: 2.2
•ISO27001-2022: A.5.5
•AWS-AI-Security-Framework-1.0: AISF-GOV-03
•CIS-4.0.1: 1.2
•NIS2: 1.1.1.a, 1.2.3, 2.2.1, 3.1.2.d, 3.5.3.a, 5.1.7.b
|
| MANUAL |
medium |
account |
us-east-2 |
account_security_questions_are_registered_in_the_aws_account |
[DEPRECATED] AWS root user has security challenge questions configured |
arn:aws:iam::716468089330:root |
|
Login to the AWS Console as root. Choose your account name on the top right of the window -> My Account -> Configure Security Challenge Questions. |
Absence of these questions can limit support-assisted recovery if root credentials or MFA are lost, reducing availability and slowing incident response. Reliance on KBA also weakens confidentiality due to social engineering. Treat this as a recovery gap and adopt stronger, phishing-resistant factors. |
Favor stronger recovery instead of KBA:
- Enforce MFA for root and minimize root use
- Keep alternate contacts and root email current and protected
- Establish a tightly controlled break-glass role, applying least privilege and separation of duties
- Document and test recovery procedures; monitor root activity |
•CIS-1.4: 1.3
•CIS-1.5: 1.3
•KISA-ISMS-P-2023: 2.5.1, 2.5.3, 2.10.2
•CIS-2.0: 1.3
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP03, SEC10-BP01
•CIS-3.0: 1.3
•ENS-RD2022: op.ext.7.aws.am.1
•CIS-4.0.1: 1.3
|
| FAIL |
low |
backup |
us-east-2 |
backup_vaults_exist |
At least one AWS Backup vault exists |
arn:aws:backup:us-east-2:716468089330:backup-vault |
|
No Backup Vault exist. |
Without a vault, recovery points cannot be created or retained in AWS Backup, degrading availability and integrity. Data may be irrecoverable after deletion, ransomware, or misconfiguration, and RPO/RTO targets may be missed during incidents. |
Create and maintain a backup vault in each required region. Enforce least privilege access, encrypt with KMS CMKs, and enable Vault Lock to prevent tampering. Use lifecycle rules and cross-region/cross-account copies, and regularly test restores for defense in depth. |
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, OPS-08.01B, OPS-09.02B, CRY-16.02B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: be_5, ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•ENS-RD2022: mp.info.6.aws.bcku.1
•AWS-Foundational-Technical-Review: BAR-001
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR01, CCC.Core.CN14.AR02, CCC.Core.CN14.AR03
•SecNumCloud-3.2: 12.5, 17.6
•ISO27001-2022: A.8.13
•NIS2: 3.6.2, 4.1.2.f, 4.1.2.g, 4.2.2.b, 4.2.2.e, 12.1.2.c, 12.2.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl
|
| PASS |
high |
bedrock |
us-east-2 |
bedrock_full_access_policy_attached |
IAM role does not have AmazonBedrockFullAccess managed policy attached |
arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole |
|
IAM Role AmazonEKS_EBS_CSI_DriverRole does not have AmazonBedrockFullAccess policy attached. |
The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations |
Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges. |
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•SecNumCloud-3.2: 9.3
•ISO27001-2022: A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
bedrock |
us-east-2 |
bedrock_full_access_policy_attached |
IAM role does not have AmazonBedrockFullAccess managed policy attached |
arn:aws:iam::716468089330:role/IntruderReadOnlyRole |
|
IAM Role IntruderReadOnlyRole does not have AmazonBedrockFullAccess policy attached. |
The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations |
Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges. |
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•SecNumCloud-3.2: 9.3
•ISO27001-2022: A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
bedrock |
us-east-2 |
bedrock_full_access_policy_attached |
IAM role does not have AmazonBedrockFullAccess managed policy attached |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
IAM Role SecureframeRole-f983f1e89008 does not have AmazonBedrockFullAccess policy attached. |
The AmazonBedrockFullAccess policy grants broad permissions across all Bedrock resources. If a role with this policy is compromised, an attacker could:
- Invoke any model to exfiltrate data or generate harmful content
- Modify guardrails, logging, and security configurations
- Incur significant costs through unrestricted model invocations |
Apply least privilege: replace AmazonBedrockFullAccess with a custom policy granting only the specific Bedrock actions required.
Use permissions boundaries and SCPs to limit the scope of Bedrock permissions. Regularly review access with IAM Access Analyzer to identify and remove unused privileges. |
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•SecNumCloud-3.2: 9.3
•ISO27001-2022: A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| FAIL |
medium |
bedrock |
us-east-1 |
bedrock_guardrails_configured |
Bedrock has at least one guardrail configured in the audited region |
arn:aws:bedrock:us-east-1:716468089330:guardrails |
|
Bedrock has no guardrails configured in region us-east-1. |
Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere. |
Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
- Add sensitive information filters and denied topic policies
- Apply guardrails at the API call level using guardrailIdentifier where supported |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-AI-Security-Framework-1.0: AISF-AI-01
|
| FAIL |
medium |
bedrock |
us-east-2 |
bedrock_guardrails_configured |
Bedrock has at least one guardrail configured in the audited region |
arn:aws:bedrock:us-east-2:716468089330:guardrails |
|
Bedrock has no guardrails configured in region us-east-2. |
Without any configured Bedrock guardrails in a region, teams lack a native reusable policy object for content filtering and safety controls. Applications may invoke models without standardized protections against harmful content, prompt injection, or sensitive-data exposure unless equivalent controls are enforced elsewhere. |
Create at least one Bedrock guardrail in each region where Bedrock is used, then separately ensure those guardrails are attached to relevant agents and invocation paths.
- Configure content filters for harmful categories (hate, violence, sexual, misconduct)
- Add sensitive information filters and denied topic policies
- Apply guardrails at the API call level using guardrailIdentifier where supported |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-AI-Security-Framework-1.0: AISF-AI-01
|
| FAIL |
medium |
bedrock |
us-east-1 |
bedrock_model_invocation_logging_enabled |
Amazon Bedrock model invocation logging is enabled |
arn:aws:bedrock:us-east-1:716468089330:model-invocation-logging |
|
Bedrock Model Invocation Logging is disabled. |
Without invocation logs, you lose auditability and forensic visibility into model activity.
Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response. |
Enable model invocation logging and route events to CloudWatch Logs and/or S3.
Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties. |
•SOC2: cc_a_1_1
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•CCC-v2025.10: CCC.GenAI.CN05.AR01
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-AI-05
•NIS2: 3.2.3.c
|
| FAIL |
medium |
bedrock |
us-east-2 |
bedrock_model_invocation_logging_enabled |
Amazon Bedrock model invocation logging is enabled |
arn:aws:bedrock:us-east-2:716468089330:model-invocation-logging |
|
Bedrock Model Invocation Logging is disabled. |
Without invocation logs, you lose auditability and forensic visibility into model activity.
Credential misuse or prompt injection/jailbreak attempts may go unnoticed, enabling data exfiltration and unauthorized spend. Missing traceability weakens integrity controls and slows incident response. |
Enable model invocation logging and route events to CloudWatch Logs and/or S3.
Enforce least privilege on log access, use encryption, and set retention/lifecycle policies. Monitor for anomalies and alerts to support defense in depth and separation of duties. |
•SOC2: cc_a_1_1
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•CCC-v2025.10: CCC.GenAI.CN05.AR01
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-AI-05
•NIS2: 3.2.3.c
|
| FAIL |
low |
bedrock |
us-east-1 |
bedrock_prompt_management_exists |
Amazon Bedrock Prompt Management prompts exist in the region |
arn:aws:bedrock:us-east-1:716468089330:prompt-management |
|
No Bedrock Prompt Management prompts exist in region us-east-1. |
Without Prompt Management, prompts are scattered across applications with no central oversight, versioning, or auditability over instructions sent to foundation models, weakening governance and compliance posture.
Managed prompts are a governance enabler; prompt injection defenses are provided by Bedrock guardrails, covered by separate checks. |
Adopt Bedrock Prompt Management to centralize prompt definitions, enforce versioning, and maintain governance over model interactions.
Use managed prompts with guardrails and apply least privilege access controls to restrict who can create or modify prompts. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-AI-Security-Framework-1.0: AISF-AI-07
|
| PASS |
critical |
cloudformation |
us-east-2 |
cloudformation_stack_outputs_find_secrets |
CloudFormation stack outputs do not contain secrets |
arn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bdd |
|
No secrets found in CloudFormation Stack Secureframe-f983f1e89008 Outputs. |
Secrets in Outputs are readable to anyone with stack metadata access, enabling credential theft, unauthorized API calls, and lateral movement. Exposure via consoles, exports, or CI logs undermines confidentiality and can lead to privilege escalation and data exfiltration. |
Remove secrets from Outputs. Store credentials in Secrets Manager or Parameter Store and reference them via dynamic references; set NoEcho for sensitive parameters. Apply least privilege to view stack metadata, avoid exporting sensitive values, and add automated IaC secret scanning for defense in depth. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: DEV-02.01B
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
|
| FAIL |
medium |
cloudformation |
us-east-2 |
cloudformation_stacks_termination_protection_enabled |
CloudFormation stack has termination protection enabled |
arn:aws:cloudformation:us-east-2:716468089330:stack/Secureframe-f983f1e89008/23ccce50-ada1-11f0-b04d-0a74e0587bdd |
|
CloudFormation Stack Secureframe-f983f1e89008 has termination protection disabled. |
Without termination protection, human error or automation can delete entire stacks, causing immediate availability loss and potential data destruction of managed resources.
Attackers with delete rights can more easily trigger outages and hinder recovery. |
Enable termination protection on root stacks for critical workloads. Enforce least privilege on who can alter this setting or delete stacks, require change review via change sets, and apply stack policies plus DeletionPolicy: Retain for data stores for defense in depth. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03
|
| PASS |
medium |
cloudtrail |
us-east-2 |
cloudtrail_bedrock_logging_enabled |
CloudTrail logs Amazon Bedrock API calls for security auditing |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 from home region us-east-2 has an advanced management event selector to log Amazon Bedrock control-plane API calls. |
Without CloudTrail logging for Bedrock control-plane operations, changes to prompts, guardrails, agents, flows, or knowledge bases can become invisible, weakening forensics and incident response. Management events do not capture InvokeModel; pair this control with bedrock_model_invocation_logging_enabled or Bedrock data event selectors for invocation visibility. |
Enable CloudTrail logging for Amazon Bedrock on at least one actively logging trail. At minimum, enable management events to capture Bedrock control-plane operations. For invocation-level and other data-plane visibility, add advanced event selectors targeting Bedrock resource types or pair this control with bedrock_model_invocation_logging_enabled.
For broader region coverage, pair this control with a separate multi-region CloudTrail check. Centralize logs in an encrypted bucket or CloudWatch Logs to support defense in depth and forensic readiness for AI workloads. |
•SOC2: cc_7_2
•KISA-ISMS-P-2023: 2.9.4
•C5-2025: OPS-12.01B, OPS-15.01B
•HIPAA: 164_308_a_1_ii_d, 164_312_b
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-CSF-2.0: pt_1, ae_3, cm_3
•NIST-800-53-Revision-5: au_2_b, au_12_a, au_12_c
•CCC-v2025.10: CCC.AuditLog.CN02.AR01
•SecNumCloud-3.2: 12.6
•FFIEC: d2-ma-ma-b-2
•ISO27001-2022: A.8.15
•FedRamp-Moderate-Revision-4: au-2-a-d, au-12-a-c
|
| FAIL |
medium |
cloudtrail |
us-east-2 |
cloudtrail_bucket_requires_mfa_delete |
CloudTrail trail S3 bucket has MFA delete enabled |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 bucket (aws-cloudtrail-logs-716468089330-fb4a4f88) does not have MFA delete enabled. |
Without MFA Delete, stolen or over-privileged credentials can permanently delete log versions or change versioning, compromising log integrity and availability. This enables attacker cover-ups, hinders forensics, and weakens evidence for investigations. |
Enable MFA Delete on the CloudTrail log bucket with versioning enabled. Enforce least privilege so only tightly controlled identities can delete or alter logs, and require MFA for such actions. Apply defense in depth using a dedicated logging account and log file integrity validation. |
•KISA-ISMS-P-2023: 2.5.3, 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-09.02B, IAM-09.01AC, COM-04.01AC, PSS-05.01B, PSS-07.02B, PSS-12.03AC
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.9.4, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_3
•ENS-RD2022: op.exp.8.r4.aws.ct.3
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN07.AR01
•SecNumCloud-3.2: 12.7
•NIS2: 11.7.2
|
| PASS |
low |
cloudtrail |
us-east-2 |
cloudtrail_cloudwatch_logging_enabled |
CloudTrail trail has delivered logs to CloudWatch Logs in the last 24 hours |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Multiregion trail us-east-2 has been logging in the last 24h. |
Missing or stale CloudWatch delivery weakens visibility and delays detection, impacting confidentiality and integrity. Adversaries can:
- Hide privilege escalation
- Perform unauthorized resource changes
- Exfiltrate data via API misuse |
Integrate every trail with CloudWatch Logs and maintain continuous, near-real-time delivery. Enforce least privilege on the delivery role, prefer multi-Region coverage, and implement metric filters and alerts for sensitive actions. Centralize retention to support defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_a_1_1, pi_1_3
•CIS-1.4: 3.4
•CIS-1.5: 3.4
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: CloudTrail.5
•ISO27001-2013: A.12.4.Q
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.01AC, OIS-05.02B, AM-01.01AC, OPS-11.02AC, OPS-13.01B, OPS-13.02B, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-02.01B, SIM-03.07B, COM-04.01AC, PSS-04.01B, PSS-04.05B, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_d, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•CIS-2.0: 3.4
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-CSF-2.0: ip_8, ae_1, ae_3, cm_1, cm_3, cm_7
•NIST-800-171-Revision-2: 3_3_1, 3_3_2, 3_3_3, 3_3_5, 3_6_1, 3_6_2, 3_12_4
•PCI-4.0: 10.2.1.1.10, 10.2.1.2.8, 10.2.1.3.8, 10.2.1.4.8, 10.2.1.5.8, 10.2.1.6.8, 10.2.1.7.8, 10.2.1.8, 10.2.2.8, 10.3.1.8, 10.4.1.1.3, 10.6.3.10, 11.5.2.4, 11.6.1.4, 12.10.5.4, 5.3.4.9, A1.2.1.10, A3.3.1.6, A3.5.1.6
•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_6_1, au_6_3, au_7_1, au_12, ca_7, si_4_2, si_4_4, si_4_5, si_4
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_4_1, au_6_1, au_6_3, au_6_4, au_6_5, au_6_6, au_6_9, au_7_1, au_8_b, au_9_7, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, au_16, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•ENS-RD2022: op.exp.8.r1.aws.ct.7, op.mon.3.aws.cwl.1
•NIST-CSF-1.1: ae_1, ae_3, cm_2, cm_5, cp_4, ra_5, sc_4, pt_1
•AWS-Well-Architected-Framework-Reliability-Pillar: REL06-BP01
•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR02, CCC.LB.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-is-is-b-1, d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3
•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.3, 10.5.4
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-7-1, au-12-a-c, si-4-a-b-c
•NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
low |
cloudtrail |
us-east-2 |
cloudtrail_insights_exist |
CloudTrail trail has Insights enabled |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 has insight selectors and it is logging. |
Without Insights, abnormal API call or error rates can go unnoticed, delaying detection of credential abuse, privilege escalation, or runaway automation. Attackers may rapidly alter policies, delete resources, or exfiltrate data before response, impacting confidentiality and availability. |
Enable CloudTrail Insights on all logging trails (ideally all-Region or organization trails). Activate both ApiCallRateInsight and ApiErrorRateInsight. Integrate alerts with monitoring and review anomalies regularly. Apply defense in depth and least privilege to reduce potential blast radius. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-05.02B, SIM-03.07B, COM-04.01AC, PSS-12.03AC
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: cm_1, dp_4
•PCI-4.0: 10.3.2.2, 10.3.3.4, 10.3.4.3, 10.5.1.3, 5.3.4.8, A1.2.1.8
•ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01
•SecNumCloud-3.2: 12.9
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
|
| FAIL |
medium |
cloudtrail |
us-east-2 |
cloudtrail_kms_encryption_enabled |
CloudTrail trail logs are encrypted at rest with a KMS key |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Multiregion trail us-east-2 has encryption disabled. |
Absent a customer-managed KMS key, log protection relies only on storage permissions. Bucket misconfigurations or stolen credentials can expose audit data, aiding evasion and lateral movement. Missing key-level controls, rotation, and usage audit weaken confidentiality and forensic integrity. |
Enable SSE-KMS on every trail using a customer-managed KMS key. Apply least privilege so only authorized roles can Decrypt, and enforce separation of duties between key admins and log readers. Rotate keys and monitor key usage to provide defense in depth for CloudTrail data. |
•CISA: your-systems-3, your-data-1
•CIS-7.0: 4.5
•CIS-1.4: 3.7
•CIS-1.5: 3.7
•GDPR: article_25, article_30, article_32
•AWS-Foundational-Security-Best-Practices: CloudTrail.2
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, OPS-11.02AC, OPS-13.03B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, IAM-08.06B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, CRY-10.01AC, CRY-11.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.04B, PSS-12.02B, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 3.7
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5, pt_1, pt_4
•CIS-5.0: 3.5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.4, 10.3.3.6, 10.3.4.5, 3.5.1.5, 8.3.2.9, A1.2.1.11
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 3.5
•ENS-RD2022: op.exp.8.r4.aws.ct.4, op.exp.8.r4.aws.ct.7
•CIS-6.0: 4.5
•AWS-Foundational-Technical-Review: SDAT-002
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN02.AR01
•SecNumCloud-3.2: 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.3
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DETECT-01
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•CIS-4.0.1: 3.5
•NIS2: 9.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-svc
|
| PASS |
medium |
cloudtrail |
us-east-2 |
cloudtrail_log_file_validation_enabled |
CloudTrail trail has log file validation enabled |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Multiregion trail us-east-2 has log file validation enabled. |
Without validation, adversaries can alter, forge, or delete audit entries without detection, compromising log integrity and non-repudiation.
This impairs investigations, enables alert evasion, and obscures unauthorized changes across regions or accounts. |
Enable log file integrity validation on all trails (LogFileValidationEnabled=true).
Enforce least privilege on the logs bucket, retain and protect digest files (e.g., S3 Object Lock/MFA Delete), and monitor validation results to support defense in depth. |
•CISA: your-systems-3
•CIS-7.0: 4.2
•SOC2: cc_7_3, pi_1_3
•CIS-1.4: 3.2
•CIS-1.5: 3.2
•GDPR: article_25, article_32
•AWS-Foundational-Security-Best-Practices: CloudTrail.4
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-13.01AC, OPS-15.02AC, OPS-26.05B, OPS-26.01AS, DEV-08.02B, SIM-01.02AC, SIM-03.07B, COM-04.01AC, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_b, 164_308_a_1_ii_d, 164_312_b, 164_312_c_1, 164_312_c_2
•CIS-2.0: 3.2
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01, SEC06-BP06
•NIST-CSF-2.0: ds_6, pt_1
•CIS-5.0: 3.2
•NIST-800-171-Revision-2: 3_3_8, 3_13_1
•PCI-4.0: 10.3.2.5, 10.3.3.7, 10.3.4.6, A1.2.1.12
•NIST-800-53-Revision-4: si_7_1, si_7
•NIST-800-53-Revision-5: au_9_a, cm_6_a, cm_9_b, pm_11_b, pm_17_b, sa_1_1, sa_10_1, sc_16_1, si_1_a_2, si_4_d, si_7_1, si_7_3, si_7_7, si_7_a
•CIS-3.0: 3.2
•ENS-RD2022: op.exp.8.aws.ct.3
•CIS-6.0: 4.2
•NIST-CSF-1.1: ds_6, ds_7
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN01.AR01, CCC.AuditLog.CN01.AR02
•SecNumCloud-3.2: 10.4, 12.7, 16.6
•PCI-3.2.1: 10.5, 10.5.2, 10.5.5
•ProwlerThreatScore-1.0: 3.1.2
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•FedRamp-Moderate-Revision-4: au-9, si-7-1, si-7
•FedRAMP-Low-Revision-4: ac-2, au-2, au-9
•CIS-4.0.1: 3.2
•NIS2: 3.4.2.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla
|
| PASS |
medium |
cloudtrail |
us-east-2 |
cloudtrail_logs_s3_bucket_access_logging_enabled |
CloudTrail trail destination S3 bucket has access logging enabled |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Multiregion Trail us-east-2 S3 bucket access logging is enabled for bucket aws-cloudtrail-logs-716468089330-fb4a4f88. |
Without access logging on the CloudTrail logs bucket, access and changes to log files lack an independent audit trail. Attackers could read, delete, or replace logs without attribution, undermining log confidentiality and integrity, and slowing incident response. |
Enable S3 server access logging on the CloudTrail logs bucket and write logs to a separate, tightly controlled bucket. Apply least privilege, enable versioning, and consider Object Lock to deter tampering. Centralize monitoring to support defense-in-depth and rapid investigation. |
•CIS-7.0: 4.4
•SOC2: cc_a_1_1
•CIS-1.4: 3.6
•CIS-1.5: 3.6
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: CloudTrail.7
•ISO27001-2013: A.12.4.O
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, IAM-10.01B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, INQ-04.01AC, PSS-04.05B, PSS-12.03AC
•CIS-2.0: 3.6
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-CSF-2.0: pt_1
•CIS-5.0: 3.4
•AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM
•CIS-3.0: 3.4
•ENS-RD2022: op.exp.8.r1.aws.ct.6, op.exp.8.r4.aws.ct.5
•CIS-6.0: 4.4
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.7
•ProwlerThreatScore-1.0: 3.1.3
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•CIS-4.0.1: 3.4
•NIS2: 3.2.3.c, 11.1.1, 11.2.2.f
|
| PASS |
critical |
cloudtrail |
us-east-2 |
cloudtrail_logs_s3_bucket_is_not_publicly_accessible |
CloudTrail trail S3 bucket is not publicly accessible |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 from multiregion trail us-east-2 is not publicly accessible. |
Exposed CloudTrail logs erode confidentiality and integrity.
Adversaries can harvest API activity to map accounts, roles, and keys, enabling reconnaissance and evasion. If write is allowed, logs can be poisoned or deleted, thwarting investigations and compromising incident timelines. |
Apply least privilege to the log bucket:
- Enable S3 Block Public Access (account and bucket)
- Remove AllUsers/AuthenticatedUsers ACLs; avoid wildcard principals
- Permit only CloudTrail and constrain with aws:SourceArn
Use a dedicated private bucket and monitor for permission changes. |
•CIS-1.4: 3.3
•CIS-1.5: 3.3
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: CloudTrail.6
•ISO27001-2013: A.12.4.S, A.12.6.J
•KISA-ISMS-P-2023: 2.6.1, 2.10.1
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC
•CIS-2.0: 3.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ds_5, pt_1
•ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r4.aws.ct.2, op.exp.8.r4.aws.ct.6
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN04.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 12.7
•ProwlerThreatScore-1.0: 2.2.5
•ISO27001-2022: A.8.1, A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudtrail |
us-east-1 |
cloudtrail_multi_region_enabled |
Region has at least one CloudTrail trail logging |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 is multiregion and it is logging. |
Missing coverage in any region creates visibility gaps.
Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity). |
Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.
Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 4.1
•SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3
•CIS-1.4: 3.1
•CIS-1.5: 3.1
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: CloudTrail.1
•ISO27001-2013: A.12.4.T
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•CIS-2.0: 3.1
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03
•GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control
•CIS-5.0: 3.1
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23
•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Account-Security-Onboarding: Enable as part of Organization trail
•CIS-3.0: 3.1
•ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1
•CIS-6.0: 4.1
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1
•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3
•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ProwlerThreatScore-1.0: 3.1.1
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5
•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7
•CIS-4.0.1: 3.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07
|
| PASS |
high |
cloudtrail |
us-east-2 |
cloudtrail_multi_region_enabled |
Region has at least one CloudTrail trail logging |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 is multiregion and it is logging. |
Missing coverage in any region creates visibility gaps.
Attackers can use lesser-monitored regions to run API actions, hide unauthorized changes, and exfiltrate data without audit trails, weakening detective controls, hindering forensics, and delaying response (confidentiality and integrity). |
Use a multi-region CloudTrail trail or per-region trails so logging is active in every region, including unused ones.
Centralize logs, enforce least privilege to log stores, and add defense-in-depth with encryption, integrity validation, and retention. Continuously monitor trail health to catch gaps. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 4.1
•SOC2: cc_2_1, cc_7_2, cc_a_1_1, pi_1_3
•CIS-1.4: 3.1
•CIS-1.5: 3.1
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: CloudTrail.1
•ISO27001-2013: A.12.4.T
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: OIS-05.01B, OIS-05.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-15.03B, IAM-07.04B, DEV-08.02B, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•CIS-2.0: 3.1
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k, 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02, SEC04-BP03
•GxP-EU-Annex-11: 1-risk-management, 4.2-validation-documentation-change-control
•CIS-5.0: 3.1
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_4_1, 3_6_1, 3_6_2, 3_13_1, 3_13_2, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.22, 10.2.1.2.19, 10.2.1.3.19, 10.2.1.4.19, 10.2.1.5.19, 10.2.1.6.19, 10.2.1.7.19, 10.2.1.19, 10.2.2.19, 10.3.1.19, 10.6.3.24, 5.3.4.22, A1.2.1.23
•NIST-800-53-Revision-4: ac_2_4, ac_2, au_2, au_3, au_12, cm_2
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_1, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Account-Security-Onboarding: Enable as part of Organization trail
•CIS-3.0: 3.1
•ENS-RD2022: op.acc.6.r5.aws.iam.1, op.exp.5.aws.ct.1, op.exp.8.aws.ct.1, op.exp.8.aws.ct.6, op.exp.9.aws.ct.1, op.mon.1.aws.ct.1
•CIS-6.0: 4.1
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, ma_2, pt_1
•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN04.AR01, CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.2, 12.6, 14.2, 16.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-an-b-5, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3, d3-pc-im-b-7, d5-dr-de-b-3
•PCI-3.2.1: 3.2, 3.2.3, 3.4, 3.4.d, 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ProwlerThreatScore-1.0: 3.1.1
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5
•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7
•CIS-4.0.1: 3.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla, ksi-mla-07
|
| PASS |
low |
cloudtrail |
us-east-1 |
cloudtrail_multi_region_enabled_logging_management_events |
CloudTrail trail logs management events for read and write operations |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled. |
Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.
Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response. |
Enable a multi-region CloudTrail that logs management events for read and write in all regions.
Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4
•AWS-Account-Security-Onboarding: Enable as part of Organization trail
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.2, 12.6
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c
|
| PASS |
low |
cloudtrail |
us-east-2 |
cloudtrail_multi_region_enabled_logging_management_events |
CloudTrail trail logs management events for read and write operations |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 from home region us-east-2 is multi-region, is logging and have management events enabled. |
Without region-wide management event logging, changes to identities, networking, and audit settings can go untracked.
Adversaries can operate in overlooked regions to create resources, modify permissions, or disable logging, undermining integrity, confidentiality, and incident response. |
Enable a multi-region CloudTrail that logs management events for read and write in all regions.
Centralize logs in a separate, locked-down account; apply least privilege, encryption, retention, and integrity validation; and protect trails and storage with tamper-evident, deny-delete controls for defense-in-depth. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-05.02B, AM-01.01AC, PS-02.01B, PS-02.01AS, PS-02.02AS, OPS-11.02AC, OPS-12.01B, OPS-13.02B, OPS-13.01AC, OPS-13.03AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, DEV-08.02B, SSO-05.01AC, SIM-03.06B, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.02AC, PSS-12.03AC
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: po_4, ov_3, pt_1, ae_1, ae_3, cm_1, cm_3, dp_4
•AWS-Account-Security-Onboarding: Enable as part of Organization trail
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.Logging.CN01.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.2, 12.6
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-01
•NIS2: 3.1.2.a, 3.2.3.c, 3.4.2.c
|
| PASS |
low |
cloudtrail |
us-east-2 |
cloudtrail_s3_dataevents_read_enabled |
CloudTrail trail records S3 object-level read events for all S3 buckets |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations. |
Without object-level read logging, S3 access is opaque. Attackers or insiders can exfiltrate data via GetObject without audit trails, eroding confidentiality and hindering forensics, anomaly detection, and incident response. |
Enable CloudTrail data events for S3 objects with ReadOnly (or All) across all current and future buckets. Use a multi-Region trail, centralize logs in an encrypted bucket with lifecycle retention, and integrate monitoring/alerts to support defense in depth and accountable access. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 4.9
•SOC2: cc_2_1, cc_7_2
•CIS-1.4: 3.11
•CIS-1.5: 3.11
•GDPR: article_30
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i
•CIS-2.0: 3.11
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail
•CIS-5.0: 3.9
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Account-Security-Onboarding: Confirm that logs are present in S3 bucket and SIEM
•CIS-3.0: 3.9
•ENS-RD2022: op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4
•CIS-6.0: 4.9
•NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ProwlerThreatScore-1.0: 3.1.6
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5
•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7
•CIS-4.0.1: 3.9
•NIS2: 3.2.3.c, 3.2.3.g, 3.4.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla
|
| PASS |
low |
cloudtrail |
us-east-2 |
cloudtrail_s3_dataevents_write_enabled |
CloudTrail trail records all S3 object-level API operations for all buckets |
arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2 |
|
Trail us-east-2 from home region us-east-2 has an advanced data event selector to record all S3 object-level API operations. |
Without object-level write logging, unauthorized or accidental changes and deletions can go unobserved, undermining data integrity and availability. Forensics lose visibility into who modified or removed objects, hindering detection of ransomware, rogue automation, or insider tampering. |
Enable CloudTrail S3 data events for object-level write (and optionally read) across all buckets on a multi-Region trail. Apply least privilege to log storage, set lifecycle retention, and integrate alerts. Use advanced selectors to target sensitive buckets/operations for cost control and defense in depth. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 4.8
•SOC2: cc_2_1, cc_7_2, pi_1_2
•CIS-1.4: 3.10
•CIS-1.5: 3.10
•GDPR: article_30
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-07.04B, SSO-05.01AC, SIM-03.07B, COM-04.01AC, PSS-04.05B, PSS-12.03AC
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_a_2_i, 164_312_b, 164_312_e_2_i
•CIS-2.0: 3.10
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•GxP-EU-Annex-11: 8.2-printouts-data-changes, 9-audit-trails, 12.4-security-audit-trail
•CIS-5.0: 3.8
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.7, 10.2.1.2.7, 10.2.1.3.7, 10.2.1.4.7, 10.2.1.5.7, 10.2.1.6.7, 10.2.1.7.7, 10.2.1.7, 10.2.2.7, 10.3.1.7, 10.6.3.7, 5.3.4.7, A1.2.1.7
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Account-Security-Onboarding: Send S3 access logs for critical buckets to separate S3 bucket, Confirm that logs are present in S3 bucket and SIEM
•CIS-3.0: 3.8
•ENS-RD2022: op.exp.8.aws.ct.4, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3, op.exp.8.r1.aws.ct.4
•CIS-6.0: 4.8
•NIST-CSF-1.1: ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, ds_5
•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.AuditLog.CN02.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.1.5
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c, ca-7-a-b, si-4-16, si-4-2, si-4-4, si-4-5
•FedRAMP-Low-Revision-4: ac-2, au-2, ca-7
•CIS-4.0.1: 3.8
•NIS2: 3.2.3.c, 3.2.3.g
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-mla
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_alarm_state_configured |
CloudWatch metric alarm has actions configured for the ALARM state |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alert |
|
CloudWatch metric alarm scrivas-dev-api-error-alert has actions configured for the ALARM state. |
Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss |
Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_7, ip_8, dp_4
•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_alarm_state_configured |
CloudWatch metric alarm has actions configured for the ALARM state |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alert |
|
CloudWatch metric alarm scrivas-stage-error-alert has actions configured for the ALARM state. |
Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss |
Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_7, ip_8, dp_4
•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_alarm_state_configured |
CloudWatch metric alarm has actions configured for the ALARM state |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prod |
|
CloudWatch metric alarm scrivas_prod has actions configured for the ALARM state. |
Without an ALARM action, threshold breaches trigger no notification or automated response. This delays detection and containment, risking:
- Availability: prolonged outages or missed scale-out
- Integrity/confidentiality: unchecked anomalies enabling tampering or data loss |
Assign at least one ALARM-state action per alarm (e.g., notify via SNS or run automated remediation with Lambda/SSM). Keep actions enabled, apply least privilege to targets, and regularly test. For critical metrics, add redundant paths (EventBridge) for defense in depth. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_7, ip_8, dp_4
•PCI-4.0: 10.2.1.1.8, 10.2.1.1.9, 10.4.1.1.2, 10.4.1.2, 10.4.2.2, 10.4.2.3, 10.4.3.1, 10.6.3.8, 10.6.3.9, 10.7.1.3, 10.7.1.4, 10.7.2.3, 10.7.2.4, 11.5.2.2, 11.5.2.3, 11.6.1.2, 11.6.1.3, 12.10.5.2, 12.10.5.3, A3.3.1.3, A3.3.1.4, A3.3.1.5, A3.5.1.3, A3.5.1.4, A3.5.1.5
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_enabled |
CloudWatch metric alarm has actions enabled |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-dev-api-error-alert |
|
CloudWatch metric alarm scrivas-dev-api-error-alert has actions enabled. |
With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk. |
Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_8, dp_4
•CCC-v2025.10: CCC.LB.CN06.AR01
•SecNumCloud-3.2: 16.2
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_enabled |
CloudWatch metric alarm has actions enabled |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas-stage-error-alert |
|
CloudWatch metric alarm scrivas-stage-error-alert has actions enabled. |
With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk. |
Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_8, dp_4
•CCC-v2025.10: CCC.LB.CN06.AR01
•SecNumCloud-3.2: 16.2
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_alarm_actions_enabled |
CloudWatch metric alarm has actions enabled |
arn:aws:cloudwatch:us-east-2:716468089330:alarm:scrivas_prod |
|
CloudWatch metric alarm scrivas_prod has actions enabled. |
With alarm actions disabled, state changes neither notify nor remediate. Incidents can persist unnoticed, enabling unauthorized activity, configuration drift, or capacity exhaustion. Visibility drops, MTTR rises, and confidentiality, integrity, and availability are all at greater risk. |
Enable actions_enabled on critical alarms and attach least-privilege actions (SNS, automation) for ALARM and recovery states. Use redundant targets, regularly test notifications, and integrate with incident response. Apply defense in depth with complementary detections to ensure timely, reliable alerting. |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_8, dp_4
•CCC-v2025.10: CCC.LB.CN06.AR01
•SecNumCloud-3.2: 16.2
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_changes_to_network_acls_alarm_configured |
CloudWatch log metric filter and alarm exist for Network ACL (NACL) change events |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Absent monitoring of NACL changes reduces detection of policy tampering, risking loss of confidentiality (opened ingress/egress), degraded network integrity (lateral movement, bypassed segmentation), and reduced availability (traffic blackholes or lockouts). |
Implement a CloudWatch Logs metric filter and alarm for NACL change events from CloudTrail and route alerts to responders. Enforce least privilege on NACL management, require change control, and use defense in depth with configuration monitoring and flow logs to validate and monitor network posture. |
•CIS-7.0: 5.11
•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4
•CIS-1.4: 4.11
•CIS-1.5: 4.11
•MITRE-ATTACK: T1496
•ISO27001-2013: A.12.4.D
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•HIPAA: 164_308_a_6_i
•CIS-2.0: 4.11
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ra_5, cm_1, dp_4
•CIS-5.0: 4.11
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4
•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b
•CIS-3.0: 4.11
•CIS-6.0: 5.11
•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5
•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.12
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-2, ca-7, ir-4
•CIS-4.0.1: 4.11
•NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 6.4.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_changes_to_network_gateways_alarm_configured |
CloudWatch Logs metric filter and alarm exist for changes to network gateways |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without this monitoring, gateway changes can expose private networks to the Internet or break connectivity. Adversaries or mistakes can enable data exfiltration, bypass network inspection, and trigger outages via deletions or detachments, impacting confidentiality and availability. |
Send CloudTrail to CloudWatch Logs and create a metric filter for the listed gateway events with an alarm that notifies responders. Enforce least privilege for gateway modifications, require change approvals, and route alerts to monitored channels as part of defense in depth. |
•CIS-7.0: 5.12
•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4
•CIS-1.4: 4.12
•CIS-1.5: 4.12
•MITRE-ATTACK: T1496
•ISO27001-2013: A.12.4.C
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B
•HIPAA: 164_308_a_6_i
•CIS-2.0: 4.12
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ra_5, ae_2, ae_3, cm_1, dp_4
•CIS-5.0: 4.12
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4
•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b
•CIS-3.0: 4.12
•CIS-6.0: 5.12
•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5
•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.13
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ir-4
•CIS-4.0.1: 4.12
•NIS2: 2.2.3, 3.2.3.a, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_changes_to_network_route_tables_alarm_configured |
Account monitors VPC route table changes with a CloudWatch Logs metric filter and alarm |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without monitoring of route table changes, unauthorized or accidental edits can redirect traffic, bypass inspection, or blackhole routes, impacting confidentiality (exfiltration), integrity (tampered paths), and availability (outages from misrouted traffic). |
Implement a CloudWatch Logs metric filter and alarm on CloudTrail for these route table events and notify responders. Enforce least privilege for route modifications, require change control, and apply defense in depth with VPC Flow Logs and guardrails to prevent and quickly contain unsafe routing changes. |
•CIS-7.0: 5.13
•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4
•CIS-1.4: 4.13
•CIS-1.5: 4.13
•MITRE-ATTACK: T1496
•ISO27001-2013: A.12.4.B
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-13.03AC, OPS-26.06B, COS-03.02B, PSS-04.01B
•HIPAA: 164_308_a_6_i
•CIS-2.0: 4.13
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ae_2, ae_3, cm_1, dp_4
•CIS-5.0: 4.13
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4
•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b
•CIS-3.0: 4.13
•CIS-6.0: 5.13
•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5
•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.14
•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ir-4
•CIS-4.0.1: 4.13
•NIS2: 2.2.3, 3.2.3.a, 3.2.3.f, 3.2.4, 6.4.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_changes_to_vpcs_alarm_configured |
AWS account has a CloudWatch Logs metric filter and alarm for VPC changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on VPC changes, unauthorized or accidental edits to routes, peering, or attributes can go unnoticed, exposing private networks and enabling data exfiltration (C), lateral movement and traffic tampering (I), and outages from misrouted or bridged networks (A). |
Create a CloudWatch Logs metric filter and alarm on CloudTrail for critical VPC change events, and notify responders. Apply least privilege to network changes, require change approvals, and use defense in depth (segmentation, route controls) to prevent and contain unauthorized modifications. |
•CIS-7.0: 5.14
•SOC2: cc_5_2, cc_7_2, cc_7_3, cc_7_4
•CIS-1.4: 4.14
•CIS-1.5: 4.14
•MITRE-ATTACK: T1496
•ISO27001-2013: A.12.4.A
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, COS-03.02B, PSS-04.01B
•HIPAA: 164_308_a_6_i
•CIS-2.0: 4.14
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ra_5, ae_2, cm_1
•CIS-5.0: 4.14
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_12_4
•NIST-800-53-Revision-4: ac_2_4, au_6_1, au_6_3, au_7_1, ca_7, ir_4_1, si_4_2, si_4_4, si_4_5, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_2, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31, sc_36_1_a, si_2_a, si_4_12, si_5_1, si_5_b
•CIS-3.0: 4.14
•CIS-6.0: 5.14
•NIST-CSF-1.1: ae_5, cm_2, cm_5, cp_4, ra_5
•CCC-v2025.10: CCC.Core.CN09.AR03, CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•FFIEC: d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.15
•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•FedRamp-Moderate-Revision-4: ac-2-4, au-6-1-3, au-7-1, ca-7-a-b, ir-4-1, ir-4-1, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ir-4
•CIS-4.0.1: 4.14
•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.4, 6.4.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_cross_account_sharing_disabled |
CloudWatch does not allow cross-account sharing |
arn:aws:iam:us-east-2:716468089330:role |
|
CloudWatch doesn't allow cross-account sharing. |
Granting other accounts visibility into observability data reduces confidentiality and enables reconnaissance. Adversaries or over-privileged partners can map architectures, profile workloads, and spot alerting gaps, increasing chances of lateral movement and evasion. |
Disable cross-account sharing unless strictly required. If needed, restrict access to specific trusted accounts, scope read-only permissions to only necessary resources, and use a dedicated monitoring account. Apply least privilege and separation of duties, and regularly audit role trust and access patterns. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01
•ENS-RD2022: op.acc.4.aws.iam.1
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* |
|
Log Group /aws/guardduty/malware-scan-events does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* |
|
Log Group scrivas-gate-prod does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* |
|
Log Group scrivas-backend-prod-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* |
|
Log Group scrivas-search-prod-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* |
|
Log Group scrivas-patient-prod-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* |
|
Log Group vpc_logs does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* |
|
Log Group scrivas-backend-stage-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* |
|
Log Group scrivas-patient-stage-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* |
|
Log Group scrivas-gate-stage does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* |
|
Log Group scrivas-search-stage-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* |
|
Log Group scrivas-gate-dev does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* |
|
Log Group scrivas-patient-dev-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* |
|
Log Group scrivas-search-dev-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* |
|
Log Group ec2-docker-logs does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* |
|
Log Group scrivas-backend-dev-env does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* |
|
Log Group /aws/vpc/flow-logs/us-east-2 does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* |
|
Log Group aws-cloudtrail-logs-716468089330-e5f9b539 does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* |
|
Log Group RDSOSMetrics does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_kms_encryption_enabled |
CloudWatch log group is encrypted with an AWS KMS key |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* |
|
Log Group /aws/eks/scrivas-stage/cluster does not have AWS KMS keys associated. |
Without a customer-managed KMS key, logs rely on service-managed encryption, limiting control and auditability.
- Confidentiality: weaker key-policy barriers against unauthorized reads
- Integrity/availability: no custom rotation or rapid revoke, hindering incident response and compliance |
Associate each log group with a customer-managed KMS key via kmsKeyId.
- Enforce least privilege in key and IAM policies, granting kms:Decrypt only to required principals
- Enable rotation and monitor key usage
- Separate keys by app/tenant to support defense in depth and rapid revocation |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_3, pi_1_4
•MITRE-ATTACK: T1040
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-04.01AC, OIS-08.02B, AM-01.01AC, OPS-11.02AC, OPS-13.03B, OPS-14.03B, OPS-26.05B, OPS-26.01AS, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-04.01B, PSS-04.04B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_5
•NIST-800-171-Revision-2: 3_3_8, 3_13_11, 3_13_16
•PCI-4.0: 10.3.2.3, 10.3.3.5, 10.3.4.4, 3.5.1.4, 8.3.2.8, A1.2.1.9
•NIST-800-53-Revision-4: au_9, sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1, 12.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.15, A.8.16, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: au-9, sc-28
•FedRAMP-Low-Revision-4: au-9
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* |
|
No secrets found in /aws/guardduty/malware-scan-events log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* |
|
Potential secrets found in log group scrivas-gate-prod in log stream gate-api at 2026-06-10T04:40:33.598-04:00 - Postgres URL with hardcoded password on line 1; at 2026-06-10T04:42:34.736-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* |
|
No secrets found in scrivas-backend-prod-env log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* |
|
No secrets found in scrivas-search-prod-env log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* |
|
Potential secrets found in log group scrivas-patient-prod-env in log stream patient-api at 2026-05-21T23:52:27.259-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* |
|
No secrets found in vpc_logs log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* |
|
No secrets found in scrivas-backend-stage-env log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* |
|
Potential secrets found in log group scrivas-patient-stage-env in log stream patient-api at 2026-04-07T16:47:19.389-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* |
|
Potential secrets found in log group scrivas-gate-stage in log stream gate-api at 2026-04-07T13:11:28.464-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* |
|
No secrets found in scrivas-search-stage-env log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* |
|
Potential secrets found in log group scrivas-gate-dev in log stream gate-api at 2026-03-17T09:06:17.190-04:00 - Postgres URL with hardcoded password on line 1; at 2026-03-17T09:33:01.067-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* |
|
Potential secrets found in log group scrivas-patient-dev-env in log stream patient-api at 2026-03-05T14:20:05.593-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* |
|
No secrets found in scrivas-search-dev-env log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* |
|
No secrets found in ec2-docker-logs log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* |
|
Potential secrets found in log group scrivas-backend-dev-env in log stream encounter-api at 2026-02-24T08:31:46.315-04:00 - Postgres URL with hardcoded password on line 1. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* |
|
No secrets found in /aws/vpc/flow-logs/us-east-2 log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* |
|
No secrets found in aws-cloudtrail-logs-716468089330-e5f9b539 log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* |
|
No secrets found in RDSOSMetrics log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_no_secrets_in_logs |
CloudWatch log group contains no secrets in its log events |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* |
|
No secrets found in /aws/eks/scrivas-stage/cluster log group. |
Leaked credentials in logs erode confidentiality and enable unauthorized API calls. Attackers reusing tokens/keys can escalate privileges, alter resources, and exfiltrate data. Subscriptions and exports widen exposure, and users with logs:Unmask can reveal values, increasing the blast radius. |
Avoid logging secrets via application sanitization and data minimization. Apply CloudWatch data protection policies to audit and mask sensitive patterns. Enforce least privilege for log readers and restrict logs:Unmask. Rotate exposed keys, reduce retention, and monitor findings to validate controls. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.01AC, OPS-11.02AC, OPS-13.03B, OPS-26.05B, OPS-26.01AS, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* |
|
Log Group /aws/guardduty/malware-scan-events is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* |
|
Log Group scrivas-gate-prod is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* |
|
Log Group scrivas-backend-prod-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* |
|
Log Group scrivas-search-prod-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* |
|
Log Group scrivas-patient-prod-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* |
|
Log Group vpc_logs is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* |
|
Log Group scrivas-backend-stage-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* |
|
Log Group scrivas-patient-stage-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* |
|
Log Group scrivas-gate-stage is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* |
|
Log Group scrivas-search-stage-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* |
|
Log Group scrivas-gate-dev is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* |
|
Log Group scrivas-patient-dev-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* |
|
Log Group scrivas-search-dev-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* |
|
Log Group ec2-docker-logs is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* |
|
Log Group scrivas-backend-dev-env is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* |
|
Log Group /aws/vpc/flow-logs/us-east-2 is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* |
|
Log Group aws-cloudtrail-logs-716468089330-e5f9b539 is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* |
|
Log Group RDSOSMetrics is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| PASS |
high |
cloudwatch |
us-east-2 |
cloudwatch_log_group_not_publicly_accessible |
CloudWatch Log Group is not publicly accessible |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* |
|
Log Group /aws/eks/scrivas-stage/cluster is not publicly accessible. |
Public access to log groups enables unauthorized reading of logs, revealing secrets and operational metadata, harming confidentiality. If broad actions are allowed, attackers can modify subscriptions or logs, undermining integrity and disrupting availability of audit evidence. |
Remove public access from log group resource policies. Replace Principal:"*" and Resource:"*" with narrowly scoped principals and specific ARNs. Grant only necessary actions, apply conditions to constrain use, and enforce least privilege and separation of duties with regular policy reviews. |
•SOC2: pi_1_4
•KISA-ISMS-P-2023: 2.6.1, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, PS-03.02B, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, IAM-10.01B, COS-02.01B, PSS-04.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.1, 2.10.2
•NIST-CSF-2.0: ds_5
•CCC-v2025.10: CCC.Core.CN09.AR01, CCC.AuditLog.CN09.AR01, CCC.Logging.CN04.AR01, CCC.Monitor.CN04.AR01
•SecNumCloud-3.2: 12.7
•ISO27001-2022: A.8.15, A.8.16
•NIS2: 3.2.3.c
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/guardduty/malware-scan-events:* |
|
Log Group /aws/guardduty/malware-scan-events has less than 365 days retention period (90 days). |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-prod:* |
|
Log Group scrivas-gate-prod comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-prod-env:* |
|
Log Group scrivas-backend-prod-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-prod-env:* |
|
Log Group scrivas-search-prod-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-prod-env:* |
|
Log Group scrivas-patient-prod-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:vpc_logs:* |
|
Log Group vpc_logs has less than 365 days retention period (30 days). |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-stage-env:* |
|
Log Group scrivas-backend-stage-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-stage-env:* |
|
Log Group scrivas-patient-stage-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-stage:* |
|
Log Group scrivas-gate-stage comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-stage-env:* |
|
Log Group scrivas-search-stage-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-gate-dev:* |
|
Log Group scrivas-gate-dev comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-patient-dev-env:* |
|
Log Group scrivas-patient-dev-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-search-dev-env:* |
|
Log Group scrivas-search-dev-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:ec2-docker-logs:* |
|
Log Group ec2-docker-logs comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:scrivas-backend-dev-env:* |
|
Log Group scrivas-backend-dev-env comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/vpc/flow-logs/us-east-2:* |
|
Log Group /aws/vpc/flow-logs/us-east-2 comply with 365 days retention period since it has 365 days. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:aws-cloudtrail-logs-716468089330-e5f9b539:* |
|
Log Group aws-cloudtrail-logs-716468089330-e5f9b539 comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:RDSOSMetrics:* |
|
Log Group RDSOSMetrics has less than 365 days retention period (30 days). |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| PASS |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_group_retention_policy_specific_days_enabled |
CloudWatch log group has a retention policy of at least the configured minimum days or never expires |
arn:aws:logs:us-east-2:716468089330:log-group:/aws/eks/scrivas-stage/cluster:* |
|
Log Group /aws/eks/scrivas-stage/cluster comply with 365 days retention period since it never expires. |
Short log retention erodes audit evidence. Adversaries can wait out the window, creating gaps in detection, forensics, and compliance reporting. This degrades the availability of historical logs and the integrity of incident timelines. |
Define a minimum retention baseline (e.g., >=365 days) aligned to legal and investigative needs. Apply it consistently with documented exceptions. Automate enforcement, monitor changes, and restrict who can modify retention under least privilege and defense in depth. |
•SOC2: cc_7_2, cc_7_3, cc_c_1_2
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-14.01B, OPS-14.02B, OPS-26.05B, OPS-26.01AS, PI-03.02B, PSS-04.01B
•HIPAA: 164_312_b
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_3_1, 3_6_1, 3_6_2
•PCI-4.0: 10.5.1.4, 3.2.1.3, 3.3.1.1.3, 3.3.1.3.3, 3.3.2.3, 3.3.3.3, 5.3.4.11
•NIST-800-53-Revision-4: au_11, si_12
•NIST-800-53-Revision-5: ac_16_b, au_6_3, au_6_4, au_6_6, au_6_9, au_10, au_11, au_11_1, au_12_1, au_12_2, au_12_3, au_14_a, au_14_b, ca_7_b, pm_14_a_1, pm_14_b, pm_21_b, pm_31, sc_28_2, si_4_17, si_12
•ENS-RD2022: op.exp.8.r3.aws.cw.1
•CCC-v2025.10: CCC.Logging.CN02.AR01, CCC.Logging.CN02.AR02
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1
•PCI-3.2.1: 10.1, 10.7, 10.7.b, 10.7.c
•ProwlerThreatScore-1.0: 3.2.2
•ISO27001-2022: A.8.15, A.8.16
•FedRamp-Moderate-Revision-4: au-6-1-3, au-11, si-12
•FedRAMP-Low-Revision-4: au-11
•NIS2: 1.1.1.h, 3.2.3.c, 3.2.5, 4.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla, ksi-mla-07
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled |
CloudWatch Logs metric filter and alarm exist for AWS Config configuration changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on AWS Config changes, actions like StopConfigurationRecorder or DeleteDeliveryChannel can silently suspend recording and delivery.
This degrades the integrity and availability of configuration audit data, enabling undetected changes and delaying incident response. |
Create a CloudWatch Logs metric filter and alarm for config.amazonaws.com events (StopConfigurationRecorder, DeleteDeliveryChannel, PutDeliveryChannel, PutConfigurationRecorder). Route CloudTrail to Logs, notify responders, and enforce least privilege and separation of duties on Config changes to prevent abuse. |
•CIS-7.0: 5.9
•SOC2: cc_5_2
•CIS-1.4: 4.9
•CIS-1.5: 4.9
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.F
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•CIS-2.0: 4.9
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_7, dp_4
•CIS-5.0: 4.9
•CIS-3.0: 4.9
•CIS-6.0: 5.9
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.10
•ISO27001-2022: A.8.15, A.8.16
•CIS-4.0.1: 4.9
•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled |
CloudWatch Logs metric filter and alarm exist for CloudTrail configuration changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Absent this monitoring, logging can be stopped or altered without notice, eroding visibility.
That enables covert activity and data exfiltration without audit evidence, harming confidentiality, the integrity of records, and the availability of reliable logs for detection and forensics. |
Implement a metric filter for trail configuration events and a linked alarm that notifies response channels.
Apply least privilege and separation of duties for trail changes, add defense in depth with centralized logging and validation, and regularly test that alerts fire. |
•CISA: your-data-2
•CIS-7.0: 5.5
•SOC2: cc_5_2
•CIS-1.4: 4.5
•CIS-1.5: 4.5
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.J
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-13.03AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, SIM-03.07B, COM-04.01AC, PSS-04.01B
•CIS-2.0: 4.5
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_3, ra_5, ip_8, pt_1, ae_1, ae_2, ae_3, cm_1, cm_3, cm_7, dp_4
•CIS-5.0: 4.5
•AWS-Account-Security-Onboarding: Critical alert on cloudtrail settings changes
•CIS-3.0: 4.5
•ENS-RD2022: op.exp.8.aws.ct.2, op.exp.8.r1.aws.ct.2, op.exp.8.r1.aws.ct.3
•CIS-6.0: 5.5
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN09.AR02, CCC.Core.CN09.AR03, CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR01, CCC.Logging.CN07.AR01, CCC.LB.CN04.AR01
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.6
•ISO27001-2022: A.8.15, A.8.16
•CIS-4.0.1: 4.5
•NIS2: 2.2.3, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.2.4, 3.5.4, 7.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_authentication_failures |
Account has a CloudWatch Logs metric filter and alarm for AWS Management Console authentication failures |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Absent visibility into failed console logins enables undetected brute-force and credential-stuffing attempts, extending attacker dwell time.
Successful guesses can grant console access, risking data confidentiality, configuration integrity, and availability through destructive changes. |
Implement a log metric filter for ConsoleLogin failures and attach a CloudWatch alarm with actionable notifications. Tune thresholds to reduce noise and route alerts to incident response.
Apply least privilege and enforce MFA to limit impact, and correlate alerts with source IP and user context. |
•CIS-7.0: 5.6
•SOC2: pi_1_3
•CIS-1.4: 4.6
•CIS-1.5: 4.6
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.I
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, PSS-04.01B
•HIPAA: 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii
•CIS-2.0: 4.6
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ra_5, ip_7, ip_8, pt_1, ae_2, cm_1, cm_3, cm_7, dp_4
•CIS-5.0: 4.6
•AWS-Account-Security-Onboarding: Alert on rise of ConsoleLoginFailures events
•CIS-3.0: 4.6
•ENS-RD2022: op.exp.8.aws.ct.5
•CIS-6.0: 5.6
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.7
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.6
•NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 7.2.b
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_aws_organizations_changes |
CloudWatch Logs metric filter and alarm exist for AWS Organizations changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on AWS Organizations changes, attackers or misconfigurations can silently alter governance, enabling unauthorized access and policy bypass. They could create/remove accounts, change or detach SCPs, or delete the organization, risking data exposure (C), privilege escalation (I), and service disruption (A). |
Send CloudTrail events to CloudWatch Logs, add a metric filter for organizations.amazonaws.com change events, and attach an alarm that notifies responders. Enforce least privilege and separation of duties for org admins, require MFA and approvals, and regularly test alerts to ensure timely detection and response. |
•CIS-7.0: 5.15
•SOC2: cc_5_2
•CIS-1.4: 4.15
•CIS-1.5: 4.15
•MITRE-ATTACK: T1496
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•CIS-2.0: 4.15
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ae_3, cm_7
•CIS-5.0: 4.15
•CIS-3.0: 4.15
•CIS-6.0: 5.15
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.16
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.15
•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk |
Account has a CloudWatch log metric filter and alarm for disabling or scheduled deletion of customer-managed KMS keys |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Missing alerts on CMK disablement or scheduled deletion undermines availability and integrity: encrypted data may become undecryptable, backups unusable, and recovery impossible. Attackers or insiders can change key states unnoticed, causing outages and irreversible data loss. |
Establish CloudWatch metric filters and alarms for DisableKey and ScheduleKeyDeletion CloudTrail events to enable rapid response.
- Apply least privilege to KMS administration
- Enforce change control and separation of duties
- Use deletion waiting periods and monitor all regions |
•CIS-7.0: 5.7
•CIS-1.4: 4.7
•CIS-1.5: 4.7
•MITRE-ATTACK: T1485, T1496
•GDPR: article_25
•ISO27001-2013: A.10.1.C, A.12.4.H
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.02AC, OIS-08.02B, HR-03.02AC, AM-01.01AC, AM-07.02B, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, CRY-05.02B, PSS-04.01B
•CIS-2.0: 4.7
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ae_2, cm_7
•CIS-5.0: 4.7
•CIS-3.0: 4.7
•ENS-RD2022: op.exp.10.aws.cmk.4, op.exp.10.aws.cmk.5
•CIS-6.0: 5.7
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.KeyMgmt.CN01.AR01
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.8
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.7
•NIS2: 3.2.3.c, 3.2.3.g, 3.5.4, 7.2.b
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_for_s3_bucket_policy_changes |
CloudWatch log metric filter and alarm exist for S3 bucket policy changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on S3 policy and ACL changes, unauthorized modifications can go unnoticed, weakening confidentiality and integrity. Misuse could expose buckets publicly, grant write/delete access, or alter replication paths, enabling data exfiltration and destructive actions. |
Establish and maintain metric filters and alarms for S3 bucket policy, ACL, CORS, lifecycle, and replication changes. Route alerts to monitored channels and integrate with SIEM. Enforce least privilege, require change reviews, and use defense in depth to prevent and quickly detect unsafe bucket policy changes. |
•CIS-7.0: 5.8
•SOC2: cc_5_2
•CIS-1.4: 4.8
•CIS-1.5: 4.8
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.G
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•CIS-2.0: 4.8
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: pt_1, ae_1, ae_2, cm_7
•CIS-5.0: 4.8
•CIS-3.0: 4.8
•CIS-6.0: 5.8
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.AuditLog.CN03.AR02
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.9
•ISO27001-2022: A.8.15, A.8.16
•CIS-4.0.1: 4.8
•NIS2: 2.2.3, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_policy_changes |
CloudWatch Logs metric filter and alarm exist for IAM policy changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Absent alerting on IAM policy changes, privilege modifications can go unnoticed, enabling privilege escalation, hidden backdoors, or permission revocations. This threatens confidentiality and integrity, and may impact availability if critical access is removed or misconfigured. |
Create a metric filter for IAM policy create/update/delete and attach/detach events with an alarm to notify responders.
- Enforce least privilege and separation of duties for policy changes
- Require approvals and central logging across Regions/accounts
- Integrate alerts with incident response |
•CIS-7.0: 5.4
•SOC2: cc_5_2, pi_1_3
•CIS-1.4: 4.4
•CIS-1.5: 4.4
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.K
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•CIS-2.0: 4.4
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_3, ae_2, cm_7
•CIS-5.0: 4.4
•CIS-3.0: 4.4
•ENS-RD2022: op.exp.8.aws.ct.5
•CIS-6.0: 5.4
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•PCI-3.2.1: 8.1, 8.1.2
•ProwlerThreatScore-1.0: 3.3.5
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.4
•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 7.2.b, 11.5.2.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_root_usage |
Account has a CloudWatch Logs metric filter and alarm for root account usage |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on root activity, full-privilege actions can proceed unnoticed, impacting:
- confidentiality via data access/exfiltration
- integrity via policy/config tampering
- availability via deletions or shutdowns
Delayed detection increases blast radius and persistence. |
Enable real-time alerts for root activity using a log metric filter and a high-priority alarm with notifications.
Reduce exposure: enforce least privilege, keep root for break-glass with MFA, disable root access keys, and route alerts into incident response for defense in depth. |
•CIS-7.0: 5.3
•SOC2: pi_1_3
•CIS-1.4: 4.3
•CIS-1.5: 4.3
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.L
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01B, IAM-03.03B, IAM-06.04B, IAM-06.05B, PSS-04.01B
•HIPAA: 164_308_a_6_i, 164_308_a_6_ii
•CIS-2.0: 4.3
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ip_8, ae_2, cm_7, dp_4
•CIS-5.0: 4.3
•AWS-Account-Security-Onboarding: Critical alert on every root user activity
•CIS-3.0: 4.3
•ENS-RD2022: op.exp.8.aws.ct.5, op.exp.8.aws.cw.1
•CIS-6.0: 5.3
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01
•SecNumCloud-3.2: 12.9
•PCI-3.2.1: 7.2, 7.2.1
•ProwlerThreatScore-1.0: 3.3.4
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-IAM-04, AISF-DETECT-05
•CIS-4.0.1: 4.3
•NIS2: 2.3.1, 3.2.1, 3.2.2, 3.2.3.c, 3.2.3.e, 3.2.3.g, 3.5.4, 7.2.b, 9.2.c.vii
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_security_group_changes |
CloudWatch Logs metric filter and alarm exist for security group changes |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on security group changes, unauthorized or mistaken rules can expose services to the Internet, enabling brute force and lateral movement (confidentiality, integrity). Deletions or restrictive edits can break connectivity (availability). Delayed detection increases attacker dwell time and impact. |
Establish real-time alerts for security group modifications by sending CloudTrail to CloudWatch, creating metric filters and alarms, and notifying responders.
- Enforce least privilege on SG changes
- Use change management and tagging
- Centralize logs, test alarms, and maintain runbooks
- Layer with NACLs and WAF for defense in depth |
•CIS-7.0: 5.10
•SOC2: cc_5_2
•CIS-1.4: 4.10
•CIS-1.5: 4.10
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.E
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.03B, OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, PSS-04.01B
•CIS-2.0: 4.10
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_3, ip_8, ae_1, ae_2, cm_7, dp_4
•CIS-5.0: 4.10
•CIS-3.0: 4.10
•CIS-6.0: 5.10
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.11
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.10
•NIS2: 2.2.3, 3.2.2, 3.2.3.b, 3.2.3.c, 3.2.3.f, 3.2.3.g, 3.5.4, 11.5.2.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_sign_in_without_mfa |
CloudWatch log metric filter and alarm exist for Management Console sign-in without MFA |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on non-MFA console logins, successful use of stolen passwords can go undetected, enabling:
- Unauthorized console access and IAM changes
- Data exfiltration or deletion
Impacts: loss of confidentiality and integrity, and potential availability disruption. |
Enforce MFA for all console-capable identities and maintain alerts for ConsoleLogin with MFAUsed != \"Yes\".
Apply least privilege, route alarms to monitored channels, and tune for SSO to reduce noise. Test alarms regularly and review coverage as part of defense in depth. |
•CIS-7.0: 5.2
•CIS-1.4: 4.2
•CIS-1.5: 4.2
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.M
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-16.01B, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-03.01AC, IAM-09.02B, IAM-09.01AC, PSS-04.01B, PSS-05.01B, PSS-07.02B
•CIS-2.0: 4.2
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•CIS-5.0: 4.2
•ASD-Essential-Eight-Nov 2023: E8-3.1
•CIS-3.0: 4.2
•ENS-RD2022: op.exp.8.aws.ct.5
•CIS-6.0: 5.2
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.3
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.2
•NIS2: 3.2.3.c, 3.2.3.d, 3.2.3.g, 3.5.4, 9.2.c.vii, 11.7.2
|
| FAIL |
medium |
cloudwatch |
us-east-2 |
cloudwatch_log_metric_filter_unauthorized_api_calls |
CloudWatch Logs metric filter and alarm exist for unauthorized API calls |
arn:aws:logs:us-east-2:716468089330:log-group |
|
No CloudWatch log groups found with metric filters or alarms associated. |
Without alerting on unauthorized API calls, permission probing and failed access by compromised identities can go unnoticed. Attackers can enumerate services, pivot, and attempt privilege escalation, threatening data confidentiality and integrity. |
Enable real-time alerting by adding a CloudWatch Logs metric filter for unauthorized errors (*UnauthorizedOperation, AccessDenied*) and associating it with an alarm that notifies responders.
- Enforce least privilege to reduce noise
- Integrate with IR tooling for defense in depth |
•CIS-7.0: 5.1
•SOC2: pi_1_3
•CIS-1.4: 4.1
•CIS-1.5: 4.1
•MITRE-ATTACK: T1496
•GDPR: article_25
•ISO27001-2013: A.12.4.N
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-04.01AC, OIS-04.02AC, HR-03.02AC, AM-01.01AC, AM-09.03AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS, OPS-26.06B, IAM-06.05B, PSS-04.01B
•CIS-2.0: 4.1
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_3, ra_5, ip_7, ip_8, pt_1, ae_1, ae_2, cm_1, cm_3, cm_7, dp_4
•CIS-5.0: 4.1
•CIS-3.0: 4.1
•ENS-RD2022: op.exp.8.aws.ct.5
•CIS-6.0: 5.1
•NIST-CSF-1.1: cm_2, ra_5, sc_4
•CCC-v2025.10: CCC.Core.CN04.AR01, CCC.IAM.CN10.AR01, CCC.IAM.CN10.AR02
•SecNumCloud-3.2: 12.9
•ProwlerThreatScore-1.0: 3.3.2
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-05
•CIS-4.0.1: 4.1
•NIS2: 3.2.3.c, 3.2.3.g, 3.2.4, 3.4.2.c, 3.5.4
|
| FAIL |
high |
config |
us-east-2 |
config_delegated_admin_and_org_aggregator_all_regions |
AWS Config has a delegated administrator and an organization aggregator covering all AWS regions |
arn:aws:config:us-east-2:716468089330:config-aggregator/unknown |
|
AWS Config has no Organization Aggregator configured in any region (no delegated administrator registered for config.amazonaws.com). |
Without an org-wide AWS Config aggregator and a delegated administrator, configuration data is fragmented across accounts and regions, compliance reporting is incomplete, and drift detection is delayed. Adversaries or misconfigurations can persist in unmonitored accounts, eroding audit readiness and regulatory posture. |
Register a delegated administrator for AWS Config via AWS Organizations and create at least one Configuration Aggregator with an OrganizationAggregationSource that covers all AWS regions. This centralizes configuration data across the organization for unified compliance and audit reporting. |
|
| PASS |
medium |
config |
us-east-2 |
config_recorder_all_regions_enabled |
AWS Config recorder is enabled and not in failure state or disabled |
arn:aws:config:us-east-2:716468089330:recorder |
|
AWS Config recorder default is enabled. |
Gaps in Config recording create blind spots. Changes in unmonitored Regions aren't captured, weakening integrity and auditability. Adversaries can alter resources or stage assets unnoticed, enabling misconfigurations and delaying incident response. |
Enable AWS Config in every Region with continuous recording and maintain healthy recorder status. |
•CIS-7.0: 4.3
•SOC2: cc_2_1, cc_3_1, cc_3_4, cc_8_1, pi_1_3
•CIS-1.4: 3.5
•CIS-1.5: 3.5
•MITRE-ATTACK: T1190, T1078, T1204, T1098, T1136, T1525, T1562, T1110, T1040, T1119, T1530, T1485, T1486, T1491, T1499, T1496, T1498
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: Config.1
•ISO27001-2013: A.12.4.P
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OIS-05.01B, PS-02.01B, PS-02.01AS, PS-02.02AS, DEV-08.02B
•HIPAA: 164_308_a_1_ii_a
•CIS-2.0: 3.5
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP02
•GxP-EU-Annex-11: 10-change-and-configuration-management, 4.5-validation-development-quality, 4.6-validation-quality-performance
•NIST-CSF-2.0: rm_1, po_3, po_4, ov_3, pt_1
•CIS-5.0: 3.3
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1
•AWS-Account-Security-Onboarding: Enable continuous recording for most of the resources, Confirm that records are present in central aggregator
•CIS-3.0: 3.3
•ENS-RD2022: op.exp.1.aws.cfg.1, op.exp.1.aws.cfg.2, op.exp.3.aws.cfg.1, op.exp.3.r3.aws.cfg.1, op.mon.3.r2.aws.cfg.1, op.mon.3.r6.aws.cfg.1
•CIS-6.0: 4.3
•NIST-CSF-1.1: cm_2, am_1, ra_5, sc_4, ip_12
•CCC-v2025.10: CCC.Core.CN04.AR01
•SecNumCloud-3.2: 8.1, 12.2, 13.1, 14.2, 17.5, 18.3
•PCI-3.2.1: 2.4, 2.4.a, 10.5, 10.5.2, 11.5, 11.5.a, 11.5.b
•ProwlerThreatScore-1.0: 3.3.1
•ISO27001-2022: A.5.16, A.5.22
•AWS-AI-Security-Framework-1.0: AISF-GOV-01
•CIS-4.0.1: 3.3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy, ksi-mla-07
|
| PASS |
medium |
config |
us-east-2 |
config_recorder_using_aws_service_role |
AWS Config recorder uses the AWSServiceRoleForConfig service-linked role |
arn:aws:config:us-east-2:716468089330:recorder |
|
AWS Config recorder default is using AWSServiceRoleForConfig. |
Using a custom or incorrect role can break recording or create blind spots, undermining the integrity and availability of configuration history. Over‑privileged roles weaken least privilege, increasing risk of unauthorized access, stealthy changes, and delayed incident response. |
Use the AWS‑managed service‑linked role AWSServiceRoleForConfig for all recorders to enforce least privilege and consistent trust.
Avoid custom roles; restrict who can modify the recorder or role; monitor for drift and ensure recording remains enabled as part of defense in depth. |
•KISA-ISMS-P-2023: 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, DEV-08.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2
•NIST-CSF-2.0: rm_1, po_4, ov_3, pt_1
•SecNumCloud-3.2: 13.1
•AWS-AI-Security-Framework-1.0: AISF-GOV-01
•FedRAMP-20x-KSI-Low-25.05C: ksi-piy
|
| FAIL |
medium |
drs |
us-east-1 |
drs_job_exist |
Region has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery job |
arn:aws:drs:us-east-1:716468089330:recovery-job |
|
DRS is not enabled for this region. |
Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime. |
Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery. |
•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490
•KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2
•KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2
•NIST-CSF-2.0: be_5, ip_9
•ENS-RD2022: op.cont.3.aws.drs.1
|
| FAIL |
medium |
drs |
us-east-2 |
drs_job_exist |
Region has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery job |
arn:aws:drs:us-east-2:716468089330:recovery-job |
|
DRS is not enabled for this region. |
Without DRS enabled or any prior jobs, workloads are unprotected and untested, undermining availability.
During outages or ransomware, recovery may be delayed or fail, increasing RTO/RPO, causing data loss and prolonged downtime. |
Enable DRS in required Regions and protect critical workloads. Define RTO/RPO and run regular recovery drills to validate launch settings and dependencies. Apply least privilege, monitor replication health, and document failover procedures to ensure consistent, repeatable recovery. |
•MITRE-ATTACK: T1190, T1485, T1486, T1491, T1490
•KISA-ISMS-P-2023: 2.10.2, 2.12.1, 2.12.2
•KISA-ISMS-P-2023-korean: 2.10.2, 2.12.1, 2.12.2
•NIST-CSF-2.0: be_5, ip_9
•ENS-RD2022: op.cont.3.aws.drs.1
|
| PASS |
medium |
dynamodb |
us-east-2 |
dynamodb_table_autoscaling_enabled |
DynamoDB table uses on-demand capacity or has auto scaling enabled for read and write capacity units |
arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock |
•ManagedBy=terraform
•Purpose=terraform-backend-lock
|
DynamoDB table terraform-lock automatically scales capacity on demand. |
Insufficient capacity scaling causes throttling that degrades availability and increases latency.
Sustained throttling can trigger retry storms, timeouts, and backlogs, risking missed writes or out-of-order processing that impacts data integrity and drives operational costs. |
Adopt elastic capacity: prefer on-demand for unpredictable traffic, or use PROVISIONED with auto scaling on both reads and writes.
Define safe utilization targets and bounds, monitor consumption, and plan for bursts to maintain availability and resilience over manual fixed throughput. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: ds_4
|
| FAIL |
medium |
dynamodb |
us-east-2 |
dynamodb_table_deletion_protection_enabled |
DynamoDB table has deletion protection enabled |
arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock |
•ManagedBy=terraform
•Purpose=terraform-backend-lock
|
DynamoDB table terraform-lock does not have deletion protection enabled. |
Without deletion protection, tables can be removed by authorized actions or misconfigured automation, causing irrecoverable data loss and service outage. This impacts integrity and availability, and increases the blast radius of compromised credentials or mistaken runbooks. |
Enable deletion protection on critical tables.
- Enforce least privilege to restrict who can modify this setting
- Require change control to disable it before planned deletes
- Combine with PITR and backups for defense in depth
- Use automation to make this the default for new tables |
•AWS-Foundational-Security-Best-Practices: DynamoDB.6, DynamoDB.7
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: AM-07.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: ds_3, ds_4, pt_5
•SecNumCloud-3.2: 17.4
|
| FAIL |
medium |
dynamodb |
us-east-2 |
dynamodb_table_protected_by_backup_plan |
DynamoDB table is protected by a backup plan |
arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock |
•ManagedBy=terraform
•Purpose=terraform-backend-lock
|
DynamoDB table terraform-lock is not protected by a backup plan. |
Without a backup plan, table data lacks governed copies, harming availability and integrity. Accidental deletes, corrupt writes, or malicious actions can become unrecoverable, and RPO/RTO worsen. You also forfeit cross-Region/account copies and immutability features, increasing downtime and data loss. |
Place all critical tables under an AWS Backup backup plan following defense in depth and least privilege:
- Use tag-based assignments for coverage at scale
- Define schedules, retention, and cross-Region/account copies
- Enable Vault Lock for immutability
- Regularly test restores and restrict backup deletion |
•AWS-Foundational-Security-Best-Practices: DynamoDB.4
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: be_5, ds_4, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.9, 10.3.3.11
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN14.AR02
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 4.1.4, 12.1.2.c, 12.2.2.b
|
| PASS |
medium |
dynamodb |
us-east-2 |
dynamodb_tables_kms_cmk_encryption_enabled |
DynamoDB table is encrypted at rest with AWS KMS |
arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock |
•ManagedBy=terraform
•Purpose=terraform-backend-lock
|
DynamoDB table terraform-lock has KMS encryption enabled with key ec1c4624-868a-4759-a6cb-78a0853bd17f. |
Relying on the default service-owned key reduces control over confidentiality: no custom key policies, limited auditability, and no independent rotation or disablement. This weakens least-privilege enforcement and incident response, and can impede meeting mandates that require customer-controlled keys. |
Encrypt tables with KMS keys in your account-prefer customer-managed keys for sensitive data.
- Enforce least-privilege key policies and scope grants
- Enable rotation and monitor key usage
- Separate duties for key admins vs data users
- Restrict which principals can use the key for DynamoDB
|
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•MITRE-ATTACK: T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, IAM-09.03B, IAM-09.02AC, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1
•NIST-800-171-Revision-2: 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.11, 3.5.1.12, 8.3.2.18, 8.3.2.19
•NIST-800-53-Revision-4: sc_13
•NIST-800-53-Revision-5: au_9_3, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.dydb.1
•AWS-Foundational-Technical-Review: SDAT-002
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.5, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
|
| FAIL |
medium |
dynamodb |
us-east-2 |
dynamodb_tables_pitr_enabled |
DynamoDB table has point-in-time recovery (PITR) enabled |
arn:aws:dynamodb:us-east-2:716468089330:table/terraform-lock |
•ManagedBy=terraform
•Purpose=terraform-backend-lock
|
DynamoDB table terraform-lock does not have point-in-time recovery enabled. |
Without PITR, unintended or malicious writes/deletes cannot be precisely rolled back, leading to permanent data loss and corrupted state. Failures from buggy deployments, compromised credentials, or faulty batch jobs reduce data integrity and availability, and prolong incident recovery and forensic analysis. |
Enable PITR on critical tables and set a recovery window aligned to your RPO (1-35 days). Enforce least privilege on who can modify backup settings. Regularly test restores and monitor backup status. Embed PITR in IaC and change control for consistency, and apply defense in depth with on-demand backups for key milestones. |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: DynamoDB.2
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_13_2
•ASD-Essential-Eight-Nov 2023: E8-8.1, E8-8.2
•PCI-4.0: 10.3.3.10, 10.5.1.6, 3.2.1.5, 3.3.1.1.5, 3.3.1.3.5, 3.3.2.5, 3.3.3.5
•NIST-800-53-Revision-4: cp_9, cp_10, si_12
•NIST-800-53-Revision-5: cp_1_2, cp_2_5, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, sc_5_2, si_13_5
•NIST-CSF-1.1: ip_4, ip_9, rp_1, rp_1
•AWS-Well-Architected-Framework-Reliability-Pillar: REL09-BP03
•SecNumCloud-3.2: 12.5
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c
•FedRamp-Moderate-Revision-4: cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: cp-9, cp-10, sc-5
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna, ksi-rpl
|
| PASS |
medium |
ec2 |
us-east-1 |
ec2_ami_account_block_public_access |
AMI block public access is enabled at the account level |
arn:aws:ec2:us-east-2:716468089330:account |
|
AMI Block Public Access is enabled in us-east-1. |
Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors. |
Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_ami_account_block_public_access |
AMI block public access is enabled at the account level |
arn:aws:ec2:us-east-2:716468089330:account |
|
AMI Block Public Access is enabled in us-east-2. |
Without blocking public access, AMIs could be accidentally or maliciously shared publicly, exposing baked-in secrets, source code, and infrastructure details to unauthorized actors. |
Enable AMI block public access (block-new-sharing) in every active Region. Apply guardrails (SCPs) to prevent it from being disabled, and review any AMIs that are currently shared publicly. |
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_default_encryption |
EBS default encryption is enabled |
arn:aws:ec2:us-east-2:716468089330:volume |
|
EBS Default Encryption is activated. |
Without encryption by default, data on new EBS volumes and snapshots may be stored in plaintext. A compromised account or mis-shared snapshot can expose disk contents, enabling data exfiltration, offline analysis, and loss of confidentiality. |
Enable EBS encryption by default in every region and select a customer-managed KMS key. Apply least privilege to key use, rotate keys, and monitor access. Enforce encrypted volume creation with organizational guardrails and secure templates as defense in depth. |
•CISA: your-systems-3, your-data-1
•CIS-7.0: 6.1.1
•MITRE-ATTACK: T1119
•AWS-Foundational-Security-Best-Practices: EC2.7
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 |
|
EBS Snapshot vol-07bd5c93cb1ce9a93 is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c |
|
EBS Snapshot vol-049bd3b9fbf52844c is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 |
|
EBS Snapshot vol-00abcebca9a065189 is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 |
|
EBS Snapshot vol-0fc1a9c187da02554 is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a |
|
EBS Snapshot vol-0655f47f37fd9283a is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c |
|
EBS Snapshot vol-06fd9a9b51f0c386c is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 |
|
EBS Snapshot vol-0ca0556d08ef42c06 is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b |
|
EBS Snapshot vol-03f685457f48aef3b is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_encryption |
EBS volume is encrypted |
arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 |
|
EBS Snapshot vol-096ef60e2b2bc8850 is encrypted. |
Unencrypted volumes or snapshots can be copied, shared, or recovered and reveal raw data, undermining confidentiality.
Adversaries with host or account access can read disks offline, harvest secrets, or alter system images, affecting integrity and enabling lateral movement. |
Encrypt all EBS volumes and enable encryption by default for new volumes and snapshot copies.
Apply least privilege to KMS keys, restrict snapshot sharing, and enforce defense in depth with policies and templates that prevent creation of unencrypted storage. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_5
•CIS-1.4: 2.2.1
•CIS-1.5: 2.2.1
•MITRE-ATTACK: T1119
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: EC2.3
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-03.01B, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•CIS-2.0: 2.2.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-g, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP02
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•CIS-5.0: 5.1.1
•NIST-800-171-Revision-2: 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.20, 8.3.2.34
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1, si_19_4
•CIS-3.0: 2.2.1
•ENS-RD2022: mp.si.2.aws.kms.1
•CIS-6.0: 6.1.1
•NIST-CSF-1.1: ds_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.3
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ProwlerThreatScore-1.0: 4.2.1
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-28
•CIS-4.0.1: 5.1.1
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 |
|
EBS Volume vol-07bd5c93cb1ce9a93 is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c |
|
EBS Volume vol-049bd3b9fbf52844c is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 |
|
EBS Volume vol-00abcebca9a065189 is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 |
|
EBS Volume vol-0fc1a9c187da02554 is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a |
|
EBS Volume vol-0655f47f37fd9283a is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c |
|
EBS Volume vol-06fd9a9b51f0c386c is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 |
|
EBS Volume vol-0ca0556d08ef42c06 is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b |
|
EBS Volume vol-03f685457f48aef3b is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_ebs_volume_protected_by_backup_plan |
EBS volume is protected by a backup plan |
arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 |
|
EBS Volume vol-096ef60e2b2bc8850 is not protected by a backup plan. |
Absent backup coverage, volumes face data loss, weakened integrity, and reduced availability. Deletion or corruption-whether accidental or malicious-can leave no recovery path, causing prolonged outages, failed point-in-time restoration, unmet retention needs, and harder incident response. |
Include all critical EBS volumes in standardized AWS Backup plans aligned to your RPO/RTO. Use tags for automatic assignment, enable cross-Region/account copies, apply Vault Lock for WORM retention, encrypt with KMS, enforce least-privilege access, and regularly test restores to verify integrity. |
•AWS-Foundational-Security-Best-Practices: EC2.28
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-06.01B, OPS-07.01B, DEV-11.02B, BCM-01.01B, BCM-01.02B, BCM-02.01B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ip_4, rc_rp_1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.3.3.12, 10.3.3.13, 10.3.3.14, 10.3.3.24
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 3.1, 3.1.c
•ISO27001-2022: A.8.14
•NIS2: 3.6.2, 4.1.2.g, 12.1.2.c, 12.2.2.b
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-07bd5c93cb1ce9a93 |
|
Snapshots not found for the EBS volume vol-07bd5c93cb1ce9a93. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-049bd3b9fbf52844c |
|
Snapshots not found for the EBS volume vol-049bd3b9fbf52844c. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-00abcebca9a065189 |
|
Snapshots not found for the EBS volume vol-00abcebca9a065189. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0fc1a9c187da02554 |
|
Snapshots not found for the EBS volume vol-0fc1a9c187da02554. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0655f47f37fd9283a |
|
Snapshots not found for the EBS volume vol-0655f47f37fd9283a. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-06fd9a9b51f0c386c |
|
Snapshots not found for the EBS volume vol-06fd9a9b51f0c386c. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-0ca0556d08ef42c06 |
|
Snapshots not found for the EBS volume vol-0ca0556d08ef42c06. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-03f685457f48aef3b |
|
Snapshots not found for the EBS volume vol-03f685457f48aef3b. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_ebs_volume_snapshots_exists |
EBS volume has at least one snapshot |
arn:aws:ec2:us-east-2:716468089330:volume/vol-096ef60e2b2bc8850 |
|
Snapshots not found for the EBS volume vol-096ef60e2b2bc8850. |
Missing EBS snapshots removes point-in-time recovery. Accidental deletion, corruption, or ransomware can cause irrecoverable data loss and prolonged service outages, degrading data integrity and availability and complicating recovery and forensics. |
Establish automated, policy-based EBS snapshot coverage for all volumes aligned to business RPO/RTO.
- Schedule regular snapshots with retention controls
- Encrypt snapshots and enforce least privilege access
- Replicate to another Region/account for DR
- Periodically test restores and document procedures |
•SOC2: cc_7_5
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•ASD-Essential-Eight-Nov 2023: E8-8.1
•PCI-4.0: 10.5.1.7, 3.2.1.6, 3.3.1.1.6, 3.3.1.3.6, 3.3.2.6, 3.3.3.6
•AWS-Audit-Manager-Control-Tower-Guardrails: 1.0.2
•SecNumCloud-3.2: 12.5
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-008ec7fbfb6122115 |
•Name=ML_dev
|
Elastic IP 16.58.108.209 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0f1b179c7dbcd4a49 |
•Name=Netbird_elasticip
|
Elastic IP 16.59.189.218 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b3287d784d49d661 |
•Name=Scrivas_stage_env
|
Elastic IP 18.118.91.126 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0b8681b277d57fe92 |
•Name=scrivas-dev-env
|
Elastic IP 3.14.230.56 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-096b94ac565c27327 |
•Name=Ml_prod_ip
|
Elastic IP 3.147.5.202 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-02269883e142e58a1 |
•Name=scrivas_prod_env
|
Elastic IP 3.150.90.196 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_elastic_ip_unassigned |
Elastic IP is associated with an instance or network interface |
arn:aws:ec2:us-east-2:716468089330:eip-allocation/eipalloc-0dfd7e61faef43c26 |
•Name=ML_stage
|
Elastic IP 52.14.227.224 is associated with an instance or network interface. |
Unused Elastic IPs consume public IPv4 capacity and incur ongoing charges. Hoarded addresses can exhaust quotas, blocking new allocations and delaying deployments (availability). Lack of ownership tracking increases operational drift and misconfigurations, risking unintended exposure when later reassigned. |
Release unused Elastic IPs or promptly associate them only where required. Enforce least privilege for address allocation, apply tagging to track ownership, and schedule periodic audits. Prefer private networking or managed front ends to reduce public IPv4 use. Automate reclaiming of unassociated addresses in lifecycle policies. |
•CISA: your-systems-1, your-surroundings-1
•AWS-Foundational-Security-Best-Practices: EC2.12
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_4_1
•NIST-CSF-1.1: ds_3
•FFIEC: d1-g-it-b-1
•PCI-3.2.1: 2.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_account_imdsv2_enabled |
IMDSv2 is required by default for EC2 instances at the account level |
arn:aws:ec2:us-east-2:716468089330:account |
|
IMDSv2 is not enabled by default for EC2 instances. |
Without a default of IMDSv2, new instances may enable IMDSv1, exposing metadata via simple HTTP. SSRF or proxy misconfigs can steal temporary IAM credentials, enabling data exfiltration (confidentiality), unauthorized API changes (integrity), and lateral movement that can disrupt services (availability). |
Enforce IMDSv2 at the account level in every Region by setting http_tokens to required. Add guardrails with SCP/IAM conditions. Standardize AMIs and launch templates to require tokens, validate workload compatibility, and apply least privilege to instance roles for defense in depth. For containers, prefer hop limit 2. |
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•C5-2025: OPS-25.01B
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.i
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_instance_detailed_monitoring_enabled |
EC2 instance has detailed monitoring enabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 does not have detailed monitoring enabled. |
Without 1-minute metrics, visibility drops, delaying detection of:
- Sudden CPU/network/disk spikes affecting availability
- Malicious workloads (crypto-mining, brute force)
- Data exfiltration patterns
Slower detection expands blast radius, raising incident impact and response cost. |
Enable detailed monitoring to collect 1-minute metrics on critical instances. Use defense in depth: baseline normal behavior, create alerts for anomalies, and correlate metrics with logs and traces. Review dashboards regularly. If costs matter, prioritize production, internet-facing, and autoscaling fleets. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•PCI-4.0: 10.2.1.1.15, 10.4.1.1.4, 10.4.1.3, 10.4.2.4, 10.6.3.15, 10.7.1.5, 10.7.2.5, A3.3.1.7, A3.5.1.7
•NIS2: 3.2.3.h
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_imdsv2_enabled |
EC2 instance requires IMDSv2 or has the instance metadata service disabled |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 has IMDSv2 enabled and required. |
Permitting IMDSv1 or optional tokens lets SSRF or compromised workloads retrieve temporary IAM credentials, impacting confidentiality and integrity. Stolen role creds can drive privilege escalation, unauthorized data access, and lateral movement across AWS resources. |
Apply defense in depth:
- Require IMDSv2 tokens on all instances (http_tokens: required)
- Disable metadata where not needed (http_endpoint: disabled)
- Minimize hop limit to 1 when feasible
- Update SDKs/apps for IMDSv2
- Restrict instance profile permissions (least privilege)
- Block metadata access from untrusted workloads |
•CIS-7.0: 6.7
•SOC2: cc_7_2
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: EC2.8
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•CIS-2.0: 5.6
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC06-BP01
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.7
•NIST-800-171-Revision-2: 3_12_4
•PCI-4.0: 8.2.8.4
•NIST-800-53-Revision-4: ac_6, ca_7, si_4_2, si_4
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, mp_2, sc_23_3
•CIS-3.0: 5.6
•CIS-6.0: 6.7
•NIST-CSF-1.1: cm_2, cm_5, cp_4, cp_5, ra_5, sc_4
•ProwlerThreatScore-1.0: 4.1.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ca-7-a-b, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-3, ca-7
•CIS-4.0.1: 5.7
•NIS2: 6.7.2.i
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b at IP 16.58.108.209 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db is not internet facing with an instance profile. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e at IP 3.14.230.56 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 at IP 52.14.227.224 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb at IP 18.118.91.126 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd at IP 3.150.90.196 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_instance_internet_facing_with_instance_profile |
EC2 instance is not internet-facing with an instance profile attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 at IP 3.147.5.202 is internet-facing with Instance Profile arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Publicly reachable instances with IAM role credentials expand the blast radius. Remote exploits or misconfigurations can steal credentials via the instance metadata service, enabling unauthorized API calls, data exfiltration, and lateral movement, impacting confidentiality, integrity, and availability. |
Avoid direct Internet exposure. Place workloads behind an Application Load Balancer and protect HTTP apps with WAF. Remove public IPs or restrict ingress to trusted sources. Apply least privilege to instance profiles and enforce IMDSv2. Use bastion hosts or Session Manager for admin access. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•ENS-RD2022: mp.com.4.aws.vpc.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_managed_by_ssm |
EC2 instance is managed by AWS Systems Manager or not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 is managed by Systems Manager. |
Unmanaged instances lack centralized patching, inventory, and secure remote access. This increases exposure to brute force on SSH/RDP, delayed patching, and poor visibility. Exploits can enable lateral movement and persistence, degrading confidentiality, integrity, and availability. |
Enroll all instances as Systems Manager managed nodes. Prefer Session Manager over SSH/RDP, restrict inbound admin ports, and use least privilege roles. Ensure connectivity to SSM endpoints (or private endpoints), automate patching and inventory, and monitor activity for defense-in-depth. |
•CISA: your-systems-1
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.1
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP04, SEC06-BP05
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-2.1, E8-2.6, E8-2.7
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_1, cm_8_3, sa_3, sa_10, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_2, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, si_3_c_2
•ENS-RD2022: op.acc.4.aws.iam.6, op.acc.4.aws.sys.1, op.exp.1.aws.sys.1, op.exp.4.aws.sys.2, op.exp.4.r2.aws.sys.1, op.exp.9.aws.img.1, op.acc.4.aws.iam.3
•NIST-CSF-1.1: am_1, am_2, ds_3, ds_7, ds_8, ip_1, ip_2, ip_12
•SecNumCloud-3.2: 8.1, 12.10, 12.12
•RBI-Cyber-Security-Framework: annex_i_1_1
•FFIEC: d1-g-it-b-1, d3-pc-im-b-5
•ISO27001-2022: A.5.26
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, sa-3-a, sa-10, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-8, sa-3
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-piy
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b is not older than 180 days (100 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db is not older than 180 days (159 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e is not older than 180 days (154 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 is not older than 180 days (97 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb is not older than 180 days (145 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd is not older than 180 days (91 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_older_than_specific_days |
EC2 instance is not older than the configured maximum age or is not running |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 is not older than 180 days (91 days). |
Long-lived instances often run unpatched OS and agents, enabling:
- Exploitation of known CVEs loss of confidentiality
- Privilege escalation and tampering integrity compromise
- Malware/crypto-mining and instability reduced availability
Aged hosts also drift from baselines and impede response. |
Adopt short-lived, patched workloads:
- Rebuild regularly from hardened, updated images; rotate AMIs
- Use centralized patch management and vulnerability scanning
- Retire or modernize legacy hosts; tag for lifecycle
- Apply least privilege and defense in depth to limit blast radius
Adjust max_ec2_instance_age_in_days to match policy. |
•CISA: your-systems-1
•AWS-Foundational-Security-Best-Practices: EC2.4
•KISA-ISMS-P-2023: 2.9.2
•HIPAA: 164_308_a_1_ii_b
•KISA-ISMS-P-2023-korean: 2.9.2
•GxP-21-CFR-Part-11: 11.10-a
•NIST-800-171-Revision-2: 3_4_1, 3_4_2
•ASD-Essential-Eight-Nov 2023: E8-2.8
•NIST-800-53-Revision-4: cm_2
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_8_6
•NIST-CSF-1.1: ds_7, ip_1
•FFIEC: d1-g-it-b-1
•ISO27001-2022: A.8.10
•FedRamp-Moderate-Revision-4: cm-2
•FedRAMP-Low-Revision-4: cm-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_paravirtual_type |
EC2 instance virtualization type is HVM |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 virtualization type is set to HVM. |
Using paravirtual (PV) weakens isolation versus HVM/Nitro and blocks features like ENA and NVMe. Confidentiality and integrity can suffer due to reliance on legacy hypercalls/drivers; availability and performance may degrade under load, increasing exposure to kernel/driver exploits and noisy-neighbor impacts. |
Standardize on HVM/Nitro. Migrate PV workloads to HVM AMIs and current instance families; ensure support for ENA and NVMe, current kernels, and hardened configs. Apply defense in depth and least privilege. Use immutable images with staged testing, then retire PV images to prevent drift and regressions. |
•AWS-Foundational-Security-Best-Practices: EC2.24
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cassandra_exposed_to_internet |
EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Cassandra ports open to the Internet. |
Internet-exposed Cassandra enables unauthorized queries on 9042, remote management via 7199 (JMX), and tampering with inter-node channels on 7000/7001 and 9160.
Attackers can read/modify data (confidentiality, integrity), disrupt or take over the cluster (availability), and pivot within the VPC. |
Apply least privilege network access:
- Remove 0.0.0.0/0 and ::/0 to Cassandra ports
- Allow only trusted subnets or VPN/bastion
- Keep nodes in private subnets; segment inter-node traffic
- Enforce authentication and TLS/mTLS for clients and JMX
- Add defense in depth with NACLs and monitoring |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_cifs_exposed_to_internet |
EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have CIFS ports open to the Internet. |
Publicly reachable SMB allows unauthorized access and remote code execution, enabling credential theft, NTLM relay, and share enumeration. Attackers can exfiltrate files, tamper or delete data, and spread ransomware, degrading confidentiality, integrity, and availability. |
Restrict CIFS/SMB to trusted internal sources using least privilege; do not allow 0.0.0.0/0.
Adopt defense in depth: place hosts in private subnets, require VPN or controlled jump paths, and enforce segmentation. Disable SMB if unnecessary or use alternatives (e.g., SFTP). Require strong auth and SMB signing. |
•CIS-7.0: 6.1.2
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•CIS-5.0: 5.1.2
•CIS-6.0: 6.1.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.1.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Elasticsearch/Kibana ports open to the Internet. |
Public access to Elasticsearch/Kibana can lead to:
- Unauthorized queries or dashboard viewing confidentiality loss
- Index changes or cluster control via 9300 integrity impact
- Scans and bulk queries availability degradation
Enables data exfiltration and lateral movement. |
Apply least privilege to network exposure:
- Restrict 9200, 9300, 5601 to trusted sources or keep them private
- Use private subnets, VPN/peering, or bastion/SSM for admin access
- Enforce authentication and TLS on Elasticsearch/Kibana
- Avoid public IPs unless strictly required |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.3, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ftp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have FTP ports open to the Internet. |
Exposed FTP invites Internet brute force and transmits in cleartext, enabling credential theft and packet sniffing (confidentiality).
Attackers can upload/alter files (integrity) and abuse services for malware staging or DoS (availability). Publicly reachable hosts are rapidly probed by scanners. |
Deny public ingress to FTP ports 20-21 following least privilege. Prefer SFTP or FTPS; if transfers are required, restrict to trusted sources and use private access (VPN or dedicated network). Apply defense in depth with tightened security groups and network ACLs, and monitor authentication and access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kafka_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Kafka port 9092 open to the Internet. |
Public Kafka access undermines CIA: adversaries can read topics and metadata (confidentiality), publish or alter events (integrity), and overwhelm brokers (availability). Exposure also eases reconnaissance and lateral movement from the broker host. |
Apply least privilege: restrict TCP 9092 to trusted networks, not 0.0.0.0/0 or ::/0. Keep brokers in private subnets and use private connectivity (VPN/peering). Enforce TLS and authenticated clients with granular ACLs, and add defense in depth via NACLs or proxies. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_kerberos_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Kerberos ports open to the Internet. |
Public Kerberos exposure risks CIA:
- Password spraying/AS-REP roasting against accounts
- Unauthorized password changes on 464
- Realm/user enumeration and DoS of KDC/services
Stolen tickets enable lateral movement and privilege escalation in Active Directory or the Kerberos realm. |
Restrict Kerberos ports to trusted sources only.
- Prefer private connectivity (VPN, peering) over public exposure
- Place KDCs/services in private subnets without public IPs
- Apply least privilege with narrowly scoped security group rules and NACLs
- Add defense-in-depth: host firewalls and monitor authentication activity |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ldap_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have LDAP ports open to the Internet. |
Publicly reachable LDAP/LDAPS enables:
- Directory enumeration and weak/anonymous bind attempts
- Password spraying and credential theft (cleartext on 389)
- Unauthorized queries causing data exfiltration
Abuse may lead to privilege escalation and availability impact via account lockouts. |
Limit LDAP to trusted networks:
- Allowlist specific source CIDRs in security groups (least privilege)
- Use private connectivity (peering/VPN) instead of Internet
- Require LDAPS, strong certificates, and disable insecure binds
- Add NACLs and monitoring for defense in depth
If external access is required, place a proxy and enforce rate limits. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_memcached_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Memcached port 11211 open to the Internet. |
Internet-exposed Memcached weakens:
- Availability: abuse for reflection/amplification and resource exhaustion
- Confidentiality: unauthorized reads of cached objects and metadata
- Integrity: manipulation of cache entries influencing app behavior
Public reachability also aids reconnaissance and lateral movement. |
Apply least privilege on network access:
- Restrict TCP 11211 to trusted sources or internal subnets only
- Place instances in private subnets; avoid public IPs
- Layer defense in depth with NACLs and routing to block Internet paths
- Prefer private connectivity (peering/VPN) and implement service-level authentication where available |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mongodb_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have MongoDB ports open to the Internet. |
Internet-exposed MongoDB invites scanning, brute force, and exploits leading to:
- Data extraction (confidentiality)
- Collection tampering or deletion (integrity)
- DoS or ransomware disruptions (availability)
A compromised DB host can also enable lateral movement within the environment. |
Apply least privilege to MongoDB access:
- Remove Internet-wide rules; allow only trusted sources
- Keep DBs on private subnets without public IPs; use private connectivity or proxies
- Enforce strong auth and TLS
- Add segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_mysql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have MySQL port 3306 open to the Internet. |
Publicly reachable MySQL enables Internet scanning, brute force, and credential stuffing, leading to unauthorized queries and data dumps (confidentiality). Attackers can alter or delete data (integrity), overload the service with query floods (availability), and pivot from the DB host into adjacent workloads. |
Restrict TCP 3306 to trusted sources per least privilege:
- Allow DB access only from specific application subnets or security groups
- Place database hosts in private subnets without public IPs
- Apply defense in depth with VPN/peering for admin access, TLS for connections, and host firewalls; optionally reinforce with NACLs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_oracle_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Oracle ports open to the Internet. |
Exposed Oracle listener ports enable SID enumeration, credential brute force, and TNS abuse. A successful intrusion can grant database access, causing data exfiltration (C), unauthorized changes (I), and outages via exploits or DoS (A). Internet scanning quickly finds these endpoints, enlarging the attack surface. |
Restrict Oracle ports to trusted sources; remove 0.0.0.0/0 and ::/0. Place databases in private subnets without public IPs. Use VPN/Direct Connect or bastions for access. Enable TLS on 2484, strong auth, and apply least privilege rules with defense in depth using NACLs and monitoring. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_postgresql_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have PostgreSQL port 5432 open to the Internet. |
Exposed TCP 5432 enables unauthenticated Internet probes and brute-force attempts against PostgreSQL, risking database confidentiality, integrity, and availability. Attackers could dump data, alter schemas, create backdoor accounts, pivot within the VPC, or exploit unpatched flaws at scale. |
Restrict PostgreSQL to trusted sources only:
- Remove 0.0.0.0/0 and ::/0 rules
- Apply least privilege security groups (allow from app tier or VPN)
- Place instances in private subnets without public IPs
- Enforce TLS and strong auth; disable unused listeners
- Layer with NACLs and monitoring for defense in depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_rdp_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have RDP port 3389 open to the Internet. |
Internet-exposed RDP allows:
- Brute force and credential reuse on Windows logons
- Exploitation of RDP flaws for remote code execution
- Lateral movement and data exfiltration
This threatens confidentiality, integrity, and availability through data theft, tampering, account lockouts, or ransomware. |
Remove Internet-wide RDP. Apply least privilege:
- Restrict TCP 3389 to trusted IPs
- Prefer private access via VPN or a hardened bastion; consider Session Manager
- Use just-in-time access and short-lived rules
- Enforce strong auth (e.g., NLA) and monitor logs
Adopt defense in depth with layered network controls. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_redis_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Redis port 6379 open to the Internet. |
Exposed Redis allows remote access to cached data and secrets, reducing confidentiality. Unauthorized commands (SET, DEL, FLUSHALL, config changes) can corrupt or erase data, harming integrity. Internet scanning and abuse can exhaust memory and disrupt service, degrading availability and enabling lateral movement. |
Apply least privilege network access: restrict Redis to trusted sources or VPC-only, place instances in private subnets, and avoid public IPs.
Layer controls with NACLs and host firewalls, enforce authentication and TLS on Redis, and use VPN/bastion or proxies to broker access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_sqlserver_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have SQL Server ports open to the Internet. |
Internet-reachable SQL services enable:
- Brute-force and credential-stuffing of DB logins
- Exploitation of SQL Server flaws for remote code execution
- Unauthorized queries and data exfiltration
This threatens confidentiality and integrity, and facilitates lateral movement from the database host. |
Enforce least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 1433-1434
- Allow only trusted IPs or app tiers via security group references
- Keep databases in private subnets without public IPs; access via VPN or bastion
- Require TLS and strong authentication; monitor access. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_ssh_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have SSH port 22 open to the Internet. |
Internet-exposed SSH invites brute force and credential stuffing. A successful sign-in grants remote shell, enabling data exfiltration, tampering of workloads, and lateral movement within the VPC, degrading confidentiality, integrity, and availability. |
Apply least privilege on SSH:
- Restrict ingress to trusted IPs; avoid 0.0.0.0/0 and ::/0
- Prefer Session Manager or a hardened bastion behind VPN
- Use key-based auth; disable passwords
- Add defense in depth with network controls and monitor access logs |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•CCC-v2025.10: CCC.Core.CN01.AR02
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
Instance i-095bd68aff22b103b does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
Instance i-02754e7ae419cd5db does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
Instance i-010066e6c9027aa6e does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
Instance i-046e7fc4677eaa796 does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
Instance i-067bdb5e3e09fa4bb does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
Instance i-073154fb4fa773bbd does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_instance_port_telnet_exposed_to_internet |
EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
Instance i-0055a6b877ba156e7 does not have Telnet port 23 open to the Internet. |
Exposed Telnet weakens confidentiality and integrity: credentials and commands are plaintext, enabling interception and session hijacking. Attackers can brute-force to gain shell, run remote commands, exfiltrate data, and pivot laterally, also threatening availability through misuse or takeover. |
Eliminate Telnet: disable the service and block TCP 23.
Apply least privilege network access-restrict admin connectivity via SSH through bastion or VPN, keep management paths private, and segregate hosts. Use defense in depth with monitoring and strong authentication for any legacy needs. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_3
•ProwlerThreatScore-1.0: 2.1.6
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•NIS2: 6.7.2.g
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db not associated with an Instance Profile Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_profile_attached |
EC2 instance is associated with an IAM instance profile role |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 associated with Instance Profile Role arn:aws:iam::716468089330:instance-profile/EC2-CloudWatchAgent-Role. |
Without an instance profile, apps often rely on long-term access keys on the host. Exposed keys can be used from anywhere to read data, alter resources, or disrupt services, impacting confidentiality, integrity, and availability. Keys may persist in AMIs, images, or logs, hindering rotation and amplifying blast radius. |
Attach an IAM instance profile to every instance and grant only permissions each workload requires (least privilege). Eliminate static keys on hosts; use temporary credentials with automatic rotation. Separate roles per application, enforce separation of duties, and limit who can assign roles (govern via iam:PassRole). Monitor role usage for anomalies. |
•CIS-7.0: 2.16
•CIS-1.4: 1.18
•CIS-1.5: 1.18
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: HR-01.01B, AM-03.01B, IAM-01.01B, IAM-01.04B, IAM-03.03B, IAM-08.02B, IAM-10.01B, IAM-10.02B, PSS-09.01AC
•CIS-2.0: 1.18
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP01, SEC03-BP02, SEC06-BP04, SEC06-BP05
•CIS-5.0: 1.17
•NIST-800-171-Revision-2: 3_1_1, 3_1_2
•PCI-4.0: 7.2.1.5, 7.2.2.5, 7.2.5.3, 7.3.1.3, 7.3.2.3, 7.3.3.3, 8.2.7.3, 8.2.8.5, 8.3.4.3
•NIST-800-53-Revision-5: ac_3, cm_5_1_a, cm_6_a
•CIS-3.0: 1.18
•CIS-6.0: 2.17
•FFIEC: d3-pc-am-b-1
•ProwlerThreatScore-1.0: 1.2.4
•ISO27001-2022: A.8.2, A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 1.18
•NIS2: 11.1.1, 11.2.2.d
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b has a Public IP: 16.58.108.209 (ec2-16-58-108-209.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db has a Public IP: 16.59.189.218 (ec2-16-59-189-218.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e has a Public IP: 3.14.230.56 (ec2-3-14-230-56.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 has a Public IP: 52.14.227.224 (ec2-52-14-227-224.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb has a Public IP: 18.118.91.126 (ec2-18-118-91-126.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd has a Public IP: 3.150.90.196 (ec2-3-150-90-196.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_instance_public_ip |
EC2 instance does not have a public IP address |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 has a Public IP: 3.147.5.202 (ec2-3-147-5-202.us-east-2.compute.amazonaws.com). |
Publicly addressed instances are Internet-scannable, enabling direct probing and brute-force of exposed services and management ports. This increases risks of unauthorized access, remote code execution, and data exfiltration (confidentiality, integrity), and allows direct DDoS targeting, degrading availability. |
Avoid assigning public IPs unless strictly required. Place workloads in private subnets and expose only via load balancers with WAF; use bastions or Session Manager for administration. Enforce least privilege security groups, prefer private endpoints, and route egress via NAT for defense in depth. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_6
•MITRE-ATTACK: T1190
•AWS-Foundational-Security-Best-Practices: EC2.9
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ac_3, ac_5, ip_8
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
No secrets found in EC2 instance i-095bd68aff22b103b since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
No secrets found in EC2 instance i-02754e7ae419cd5db since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
No secrets found in EC2 instance i-010066e6c9027aa6e since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
No secrets found in EC2 instance i-046e7fc4677eaa796 since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
No secrets found in EC2 instance i-067bdb5e3e09fa4bb since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
No secrets found in EC2 instance i-073154fb4fa773bbd since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_instance_secrets_user_data |
EC2 instance user data contains no secrets |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
No secrets found in EC2 instance i-0055a6b877ba156e7 since User Data is empty. |
Secrets embedded in User Data undermine confidentiality and integrity. Anyone with instance or build-system access can read them, reuse credentials to call services, exfiltrate data, or move laterally. Exposure may persist in AMIs, snapshots, and backups, increasing blast radius over time. |
Avoid placing secrets in User Data. Store them in a managed secret service and fetch at runtime via a least-privilege instance role. Prefer short-lived credentials with regular rotation. Limit who can view or edit User Data and apply defense in depth with automated secret scanning in build pipelines. |
•MITRE-ATTACK: T1552
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP03
•NIST-CSF-2.0: ds_5
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-DATA-05
•NIS2: 3.5.3.a
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_stopped_older_than_specific_days |
EC2 instance has not been stopped longer than the configured maximum days |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 is not stopped. |
Long-stopped instances remain unmonitored and unpatched while still retaining EBS volumes, network configuration, IAM instance profiles, and SSH keys. This expands attack surface and incurs unnecessary storage cost. Stale AMIs and credentials attached to abandoned instances increase the chance of compromise if the instance is later started. |
Establish a lifecycle policy for stopped instances:
- Tag instances with owner and expiry
- Terminate instances no longer needed to reclaim EBS cost
- If retained, start regularly for patching or rebuild from a hardened AMI
- Prefer ephemeral, autoscaled workloads over long-lived stopped hosts
Adjust max_ec2_instance_stopped_days to match policy. |
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b uses only one ENI: ( Interfaces: ['eni-0eb7c8be6cbdcdb2e'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db uses only one ENI: ( Interfaces: ['eni-0c6930a5310520d0f'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e uses only one ENI: ( Interfaces: ['eni-0ce22bed73e11293b'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 uses only one ENI: ( Interfaces: ['eni-0e6a8f502a37c7496'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb uses only one ENI: ( Interfaces: ['eni-0f39fad20067101e6'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd uses only one ENI: ( Interfaces: ['eni-047c4fd5cc9b17732'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_instance_uses_single_eni |
EC2 instance has no more than one Elastic Network Interface (ENI) attached |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 uses only one ENI: ( Interfaces: ['eni-0f8af55ce6e60d737'] ). |
Multiple ENIs create dual-homed hosts across subnets and security groups, enabling unintended routing and policy bypass. Adversaries can pivot between segments, use alternate egress for data exfiltration, or exploit asymmetric paths, undermining segmentation and confidentiality/integrity while complicating containment. |
Prefer a single ENI per instance.
If multi-homing is unavoidable:
- Place ENIs in least-privilege subnets/SGs
- Keep source/destination check enabled and routes explicit
- Use gateways/LBs for NAT or ingress, not the host
- Monitor flow logs and formally approve exceptions
Embed defense in depth and zero trust. |
•AWS-Foundational-Security-Best-Practices: EC2.17
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 Instance i-095bd68aff22b103b is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 Instance i-02754e7ae419cd5db is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 Instance i-010066e6c9027aa6e is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 Instance i-046e7fc4677eaa796 is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 Instance i-067bdb5e3e09fa4bb is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 Instance i-073154fb4fa773bbd is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_instance_with_outdated_ami |
EC2 instance uses a non-deprecated Amazon AMI |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 Instance i-0055a6b877ba156e7 is not using an outdated AMI. |
Running on a deprecated AMI undermines security and availability:
- Missing patches enable exploitation of known CVEs (confidentiality/integrity)
- Unsupported components hinder hardening and forensics
- AMI removal from catalogs complicates scale-out and recovery (availability) |
Adopt non-deprecated, maintained AMIs and perform rolling replacements of affected instances. Standardize on hardened golden images with regular AMI rotation and DeprecationTime monitoring. Update launch templates/ASGs to reference current images. Automate patching via an image pipeline and apply defense in depth. |
•ASD-Essential-Eight-Nov 2023: E8-2.8
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_any_port |
Network ACL does not allow ingress from 0.0.0.0/0 to any port |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 |
|
Network ACL acl-0434045af7cd4bbc7 has every port open to the Internet. |
Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control. |
Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting. |
•CISA: your-data-2
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4
•CCC-v2025.10: CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_any_port |
Network ACL does not allow ingress from 0.0.0.0/0 to any port |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 |
|
Network ACL acl-0cabb33741ea2f4f8 has every port open to the Internet. |
Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control. |
Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting. |
•CISA: your-data-2
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4
•CCC-v2025.10: CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_any_port |
Network ACL does not allow ingress from 0.0.0.0/0 to any port |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 |
|
Network ACL acl-0e58a8e59c5863345 has every port open to the Internet. |
Allowing Internet-wide ingress at the subnet layer enables broad port scanning and unsolicited connections. Attackers can probe and exploit exposed services, risking data disclosure and tampering (confidentiality, integrity) and causing outages via floods or brute-force (availability). Any security group lapse then lacks a compensating control. |
Adopt a deny-by-default NACL posture: block 0.0.0.0/0 and allow only required ports from trusted CIDRs. Apply least privilege using security groups for fine-grained access, with NACLs as coarse stateless filters. Review and prune rules regularly, and employ defense in depth with monitoring and alerting. |
•CISA: your-data-2
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_1, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•NIST-800-53-Revision-4: ac_4, cm_2, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_4_21, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_2_a, cm_2_2, cm_6_a, cm_7_b, cm_8_6, cm_9_b, sc_7_5, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•NIST-CSF-1.1: ae_1, ac_3, ac_5, pt_4
•CCC-v2025.10: CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3, annex_i_5_1
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_22 |
Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 |
|
Network ACL acl-0434045af7cd4bbc7 has SSH port 22 open to the Internet. |
An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity. |
Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
Pair tight security groups with periodic rule reviews and change control to maintain defense in depth. |
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03
•CIS-5.0: 5.2
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_22 |
Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 |
|
Network ACL acl-0cabb33741ea2f4f8 has SSH port 22 open to the Internet. |
An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity. |
Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
Pair tight security groups with periodic rule reviews and change control to maintain defense in depth. |
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03
•CIS-5.0: 5.2
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_22 |
Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 |
|
Network ACL acl-0e58a8e59c5863345 has SSH port 22 open to the Internet. |
An ACL allowing Internet-wide SSH erodes defense in depth. Systems reachable on TCP 22 face brute-force, credential stuffing, reconnaissance, and SSH exploit attempts.
Changes to routes or security groups can create direct exposure, enabling unauthorized access and lateral movement, undermining confidentiality and integrity. |
Apply least privilege at the subnet layer:
- Do not allow 0.0.0.0/0 to TCP 22
- Restrict SSH to trusted sources, or avoid direct SSH via Session Manager or a bastion behind VPN
Pair tight security groups with periodic rule reviews and change control to maintain defense in depth. |
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02, SEC05-BP03
•CIS-5.0: 5.2
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_3389 |
Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0434045af7cd4bbc7 |
|
Network ACL acl-0434045af7cd4bbc7 has Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity. |
Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.
- Restrict RDP to specific admin IP ranges
- Prefer bastion hosts or Session Manager over direct RDP
- Use private subnets and layer controls for defense in depth
|
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_3389 |
Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0cabb33741ea2f4f8 |
|
Network ACL acl-0cabb33741ea2f4f8 has Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity. |
Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.
- Restrict RDP to specific admin IP ranges
- Prefer bastion hosts or Session Manager over direct RDP
- Use private subnets and layer controls for defense in depth
|
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_networkacl_allow_ingress_tcp_port_3389 |
Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:network-acl/acl-0e58a8e59c5863345 |
|
Network ACL acl-0e58a8e59c5863345 has Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables password spraying, brute force, and exploitation of RDP flaws to gain remote control. Allowing it at the subnet layer weakens defense in depth-a misconfigured security group or route can expose instances-leading to data exfiltration, privilege escalation, and ransomware, impacting confidentiality and integrity. |
Enforce least privilege: do not allow TCP 3389 from 0.0.0.0/0 in network ACLs.
- Restrict RDP to specific admin IP ranges
- Prefer bastion hosts or Session Manager over direct RDP
- Use private subnets and layer controls for defense in depth
|
•CIS-7.0: 6.2
•SOC2: cc_6_6
•CIS-1.4: 5.1
•CIS-1.5: 5.1
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.21
•KISA-ISMS-P-2023: 2.6.1, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.1
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•CIS-5.0: 5.2
•PCI-4.0: 1.2.8.21, 1.3.1.24, 1.3.2.24, 1.4.2.22, 1.5.1.21, A1.1.3.21
•CIS-3.0: 5.1
•CIS-6.0: 6.2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2
•ProwlerThreatScore-1.0: 2.1.3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.2
•NIS2: 6.7.2.g
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
critical |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports |
Security group does not have all ports open to the Internet |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have all ports open to the Internet. |
Opening every port to the Internet enables broad scanning and exploit attempts, leading to unauthorized access, remote code execution, and data exfiltration, with easier lateral movement into the VPC. Confidentiality, integrity, and availability are all at risk. |
Enforce least privilege on ingress: allow only required ports from trusted sources, avoid 0.0.0.0/0 and ::/0. Prefer private access (VPN, bastion, or Session Manager), use security group references, and layer defense in depth with network ACLs. Periodically review and remove unused rules. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5, ds_5, ip_1, pt_4
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•ENS-RD2022: mp.com.1.aws.sg.2
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR02, CCC.Core.CN05.AR01, CCC.Core.CN05.AR05
•SecNumCloud-3.2: 13.2
•PCI-3.2.1: 1.1, 1.1.4, 1.1.4.c, 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.2.3, 1.2.3.b, 1.3, 1.3.2, 1.3.5
•ProwlerThreatScore-1.0: 2.1.4
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to the Internet. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| FAIL |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port |
Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or instance owners |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) has at least one port open to the Internet but its network interface type (interface) is not allowed. |
Open ingress to any port on non-approved interfaces enables external scanning, brute force, and exploitation of unintended services. This threatens confidentiality (unauthorized access), integrity (tampering), and availability (DoS), and facilitates lateral movement. |
Apply least privilege: restrict ingress to required ports and trusted sources; avoid 0.0.0.0/0 and ::/0 except for managed public endpoints. Place workloads behind load balancers, API gateways, or WAFs; use private networking. Allow public rules only on approved interface types. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•PCI-4.0: 1.2.5.17, 1.2.8.41, 1.3.1.45, 1.3.2.45, 1.4.2.43, 1.5.1.40, 2.2.5.17, A1.1.3.40
•SecNumCloud-3.2: 9.6, 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRAMP-20x-KSI-Low-25.05C: ksi-cna
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has a port open to a specific public IP address in ingress rule. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip |
Security group does not have any port open to a specific public IP address |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any port open to a public IP address. |
Ingress rules with specific public IPs can become stale when personnel change or access requirements expire. An attacker with compromised AWS credentials could also add narrow IP rules to gain access on any port, bypassing checks that only look for 0.0.0.0/0 or ::/0. |
Review all security group rules with specific public IP sources. Remove stale entries for former employees or expired access. Use VPN, AWS Systems Manager Session Manager, or AWS Client VPN instead of direct IP-based access. For third-party integrations, use VPC endpoints or AWS PrivateLink where possible. |
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have any high-risk port open to the Internet. |
Public exposure of these ports enables:
- RCE via SMB/RPC and weak admin consoles (445, 135, 3000, 5000, 8080)
- Credential theft/data leakage via mail protocols (25, 110, 143)
- Spam relay on 25
Impacts: confidentiality, integrity, and availability through exploitation and mass scanning. |
Restrict these ports using least privilege:
- Deny Internet ingress; allow only trusted CIDRs or private connectivity
- Place services behind VPN, bastion, or proxies/WAF; prefer private endpoints
- Disable unnecessary services; require auth and TLS on exposed apps
Apply defense in depth with security groups and network ACLs. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.19
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•C5-2025: OIS-05.03B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.4, 2.6.6, 2.10.2
•NIST-CSF-2.0: ac_5
•SecNumCloud-3.2: 13.2
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have SSH port 22 open to the Internet. |
Exposed SSH invites Internet-scale brute force and credential stuffing. A successful login grants remote shell, enabling data theft (confidentiality), code or config tampering (integrity), and cryptomining or service disruption (availability), plus lateral movement within the environment. |
Apply least privilege to SSH:
- Disallow 0.0.0.0/0 and ::/0; allow only trusted IPs or VPN ranges
- Prefer private access via bastion hosts or AWS Systems Manager Session Manager
- Enforce key-based auth, disable passwords, rotate keys
- Add network segmentation and monitoring for defense in depth |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6, cc_7_2
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.13
•ISO27001-2013: A.12.6.C, A.13.1.C
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•HIPAA: 164_308_a_1_ii_b, 164_312_e_1
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3
•CIS-5.0: 5.3, 5.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_4_7, 3_13_1, 3_13_2, 3_13_5, 3_13_6
•PCI-4.0: 1.2.8.17, 1.3.1.19, 1.3.2.19, 1.4.2.18, 1.5.1.17, A1.1.3.17
•NIST-800-53-Revision-4: ac_4, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_17_b, ac_17_1, ac_17_9, ac_17_10, cm_9_b, sc_7_7, sc_7_11, sc_7_12, sc_7_16, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_c
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•NIST-CSF-1.1: ae_1, ac_3, ac_5, ds_7, pt_4
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.2
•CCC-v2025.10: CCC.Core.CN01.AR02
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_5_1, annex_i_7_3
•FFIEC: d3-pc-am-b-10, d3-pc-im-b-1, d3-pc-im-b-2, d3-pc-im-b-6, d4-c-co-b-2
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 2.2, 2.2.2
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•FedRamp-Moderate-Revision-4: ac-4, ac-17-1, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-17, cm-2, sc-7
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 |
Security group does not allow ingress from the Internet to TCP port 3389 (RDP) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft RDP port 3389 open to the Internet. |
Internet-exposed RDP enables brute force and credential stuffing and increases the chance of remote code execution via RDP flaws.
Adversaries can gain interactive access, exfiltrate data (confidentiality), tamper with systems (integrity), and trigger ransomware or service disruption (availability). |
Apply least privilege: disallow 0.0.0.0/0 and ::/0 to 3389; permit only specific IPs or private networks.
Prefer Session Manager, VPN, or a hardened bastion with MFA and just-in-time access. Use private subnets and add defense in depth with network controls and monitoring. |
•CIS-7.0: 6.3, 6.4
•SOC2: cc_6_6
•CIS-1.4: 5.2
•CIS-1.5: 5.2, 5.3
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•AWS-Foundational-Security-Best-Practices: EC2.14
•ISO27001-2013: A.12.6.B, A.13.1.B
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•CIS-2.0: 5.2, 5.3
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_3, ac_5
•CIS-5.0: 5.3, 5.4
•CIS-3.0: 5.2, 5.3
•CIS-6.0: 6.3, 6.4
•AWS-Foundational-Technical-Review: NETSEC-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 2.0.1
•SecNumCloud-3.2: 13.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.4, 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•CIS-4.0.1: 5.3, 5.4
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Casandra ports 7199, 8888 and 9160 open to the Internet. |
Exposed Cassandra interfaces (7199 JMX, 9160 Thrift, 8888 tools) enable:
- Unauthorized reads of data/metrics (confidentiality)
- Schema and cluster changes (integrity)
- Remote operations causing outages (availability)
Public reachability also increases brute-force and exploit attempts. |
Restrict ingress on 7199, 9160, 8888 to trusted sources:
- Enforce least privilege allow-lists; avoid 0.0.0.0/0 and ::/0
- Place nodes in private subnets; use VPN or a bastion for admin
- Prefer strong auth and mTLS; bind management to internal interfaces
- Apply defense in depth with segmentation (north-south and east-west) |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and 5601 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Elasticsearch/Kibana ports 9200, 9300 and 5601 open to the Internet. |
Open Elasticsearch/Kibana ports to the Internet erode CIA:
- Confidentiality: unauthorized queries and data exfiltration
- Integrity: index tampering/deletion, cluster control via 9300
- Availability: API abuse, exploit-based outages, and Kibana 5601 brute-force |
Limit ingress to 9200, 9300, and 5601 to trusted CIDRs or private connectivity; never allow 0.0.0.0/0 or ::/0. Prefer private access via VPN, bastion, or private endpoints. Apply least privilege, network segmentation, and defense in depth (NACLs/WAF). Require strong auth and TLS on Elasticsearch/Kibana. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have FTP ports 20 and 21 open to the Internet. |
Exposed FTP weakens CIA:
- Confidentiality: cleartext credentials/files enable interception and brute force.
- Integrity: unauthorized uploads or tampering enable malware staging.
- Availability: mass scans and login attempts can exhaust resources and disrupt services. |
Apply least privilege and defense in depth:
- Remove 0.0.0.0/0 and ::/0 to 20/21; allow only trusted IPs or private access (VPN/peering).
- Prefer SFTP/FTPS or HTTPS; disable anonymous FTP.
- Segment transfer hosts, monitor access, and enforce rate limits and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Kafka port 9092 open to the Internet. |
Public Kafka 9092 access allows arbitrary clients to connect, enabling topic enumeration, data exfiltration, and producer/consumer impersonation (C/I). Brokers can be flooded or exploited, disrupting clusters (A). Exposure gives attackers a foothold for lateral movement inside the VPC. |
Apply least privilege: restrict 9092 to required subnets or IPs; avoid 0.0.0.0/0 and ::/0. Place brokers on private networks and use peering or VPN for access. Enforce mutual TLS/SASL and topic ACLs, and add defense in depth with segmentation and NACLs. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Memcached port 11211 open to the Internet. |
Exposed Memcached enables unauthenticated access, impacting CIA:
- Confidentiality: read cached data (sessions, secrets)
- Integrity: modify or poison entries
- Availability: flush or overload cache, degrading apps
Open 11211 is widely scanned, enabling unauthorized access and lateral movement. |
Apply least privilege and segmentation:
- Restrict TCP 11211 to trusted CIDRs or security groups
- Keep Memcached on private subnets; avoid public IPs
- Add defense in depth with NACLs/firewalls; disable unused protocols
- Use private connectivity (VPN/peering) and monitor access |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MongoDB ports 27017 and 27018 open to the Internet. |
Public MongoDB ports invite unauthenticated probing, brute force, and misuse of weak configs. Attackers can read/alter data, drop collections, or deploy ransomware, compromising confidentiality and integrity.
Exposure also enables enumeration and lateral movement, threatening availability. |
Apply least privilege to MongoDB access:
- Block 0.0.0.0/0 and ::/0
- Allow only trusted IPs or private networks
- Prefer private connectivity and SG-to-SG references
- Enforce authentication and TLS
- Segment east-west traffic and monitor access for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have MySQL port 3306 open to the Internet. |
Public MySQL access lets anyone reach the service, enabling credential brute force and vulnerability exploitation. This threatens:
- Confidentiality: data exfiltration
- Integrity: unauthorized writes or schema changes
- Availability: DoS from abuse or scans |
Apply least privilege: restrict 3306 to specific sources or peer security groups only. Keep databases in private subnets and use VPN, bastion, or application proxies for admin access. Enable defense in depth with TLS and strong auth. Never allow 0.0.0.0/0 or ::/0 ingress. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Oracle ports 1521 and 2483 open to the Internet. |
Public Oracle listener exposure enables attackers to:
- Brute force credentials and enumerate services
- Exploit listener flaws for remote access
- Run unauthorized queries causing data exfiltration
- Launch DoS on the listener
This jeopardizes database confidentiality, integrity, and availability. |
Apply least privilege and defense in depth: disallow public ingress to TCP 1521 and TCP 2483.
Restrict access to trusted CIDRs or peer security groups, keep databases on private networks, and require VPN, bastion, or proxy access. Enforce TLS and segment east-west and north-south traffic. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Postgres port 5432 open to the Internet. |
Exposing 5432 to the Internet enables credential stuffing and Postgres exploits, risking data disclosure (confidentiality), unauthorized changes (integrity), and service disruption via brute force or DoS (availability). |
Apply least privilege on security groups: remove 0.0.0.0/0 and ::/0 for 5432, allow only trusted CIDRs or private peers. Prefer private access (VPC-only) via VPN, bastion, or proxy. Add defense in depth with SG references and network ACLs, and enforce TLS and strong authentication. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Redis port 6379 open to the Internet. |
Public Redis access undermines confidentiality, integrity, and availability:
- Read keys and secrets
- Modify or flush data and configs
- Exhaust memory for DoS
Attackers can brute-force AUTH, exploit replication or modules for code execution, and pivot within the VPC. |
Restrict Redis to private connectivity and apply least privilege:
- Allow 6379 only from required app hosts, security groups, or CIDRs
- Prefer VPC/private networks or VPN over public IPs
- Enforce Redis AUTH and TLS, bind to private interfaces
- Use segmentation and monitoring for defense in depth |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 |
Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Microsoft SQL Server ports 1433 and 1434 open to the Internet. |
Internet-exposed SQL ports enable credential brute force, service enumeration, and remote exploitation. Compromise can lead to unauthorized queries, data exfiltration or tampering, and outages via destructive commands, degrading confidentiality, integrity, and availability. |
Apply least privilege on network access:
- Restrict SQL ingress to trusted IPs or via VPN/bastion
- Place databases in private subnets; allow only app-tier sources
- Avoid 0.0.0.0/0 and ::/0
- Use defense in depth with network ACLs/firewalls
- Monitor auth failures and rate-limit repeated attempts |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.4, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 |
Security group does not allow ingress from the Internet to TCP port 23 (Telnet) |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) does not have Telnet port 23 open to the Internet. |
Public Telnet exposes cleartext credentials and remote shell access.
- Brute-force and credential interception enable account takeover
- Command execution enables data theft and lateral movement
This threatens confidentiality and integrity and can degrade availability through misuse. |
Remove rules permitting Internet access to TCP 23 from 0.0.0.0/0 or ::/0. Disable Telnet on hosts. Prefer SSH or SSM and apply least privilege network rules. Restrict admin access to trusted IPs, VPN, or private endpoints, and use defense in depth with NACLs and logging. |
•SOC2: cc_6_6
•MITRE-ATTACK: T1199, T1048, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•C5-2025: PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.6.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•CCC-v2025.10: CCC.Core.CN01.AR03
•ProwlerThreatScore-1.0: 2.1.7
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
high |
ec2 |
us-east-2 |
ec2_securitygroup_allow_wide_open_public_ipv4 |
Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) has no potential wide-open non-RFC1918 address. |
Over-broad public CIDRs expand exposure and enable:
- Confidentiality loss via unauthorized access and exfiltration
- Integrity compromise by exploiting exposed services
- Availability impact from scanning and abuse
Open egress further allows C2 beacons and bulk data exfiltration to untrusted IPs. |
Apply least privilege on security groups:
- Allow only known IPs (prefer /32 or tight CIDRs)
- Use private connectivity (VPN, Direct Connect, private endpoints)
- Restrict and log egress; deny by default
- Segment with security group references and network ACLs for defense-in-depth |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•AWS-Foundational-Technical-Review: NETSEC-001
•SecNumCloud-3.2: 12.14
•ISO27001-2022: A.8.1, A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791 |
|
Security group default (sg-093604be72efb9791) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 |
|
Security group ec2-rds-2 (sg-0d87b03d9b2789750) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853 |
|
Security group default (sg-0dbf3eea7e40c7853) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 |
|
Security group rds-ec2-3 (sg-058c35683b5b40123) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7 |
|
Security group default (sg-0438e6794e0d9c0d7) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 |
|
Security group rds-ec2-1 (sg-0084c72426d93c9c6) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f |
|
Security group ec2-rds-1 (sg-0f29b9425a85de27f) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 |
|
Security group rds-ec2-2 (sg-09fbc74b0b61042d9) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b |
|
Security group ec2-rds-3 (sg-06728bf2249b5938b) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) was created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) was created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_from_launch_wizard |
Security group not created using the EC2 Launch Wizard |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) was not created using the EC2 Launch Wizard. |
Wizard-generated groups often include overly permissive rules (e.g., 0.0.0.0/0 to admin ports), expanding exposure. Attackers can run port scans and brute-force to gain entry, then lateral movement and data exfiltration, impacting confidentiality and integrity; broad egress aids command-and-control. |
Replace or harden these groups. Apply least privilege: restrict inbound to required sources, avoid public admin ports, and minimize egress. Use approved baseline security groups, enforce change control with IaC and guardrails, prefer private administration (bastion or Session Manager), and remove unused rules. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•ENS-RD2022: mp.com.1.aws.sg.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 |
|
Security group ec2-rds-2 (sg-0d87b03d9b2789750) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 |
|
Security group rds-ec2-3 (sg-058c35683b5b40123) it is not being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) it is not being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 |
|
Security group rds-ec2-1 (sg-0084c72426d93c9c6) it is not being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f |
|
Security group ec2-rds-1 (sg-0f29b9425a85de27f) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 |
|
Security group rds-ec2-2 (sg-09fbc74b0b61042d9) it is not being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b |
|
Security group ec2-rds-3 (sg-06728bf2249b5938b) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
low |
ec2 |
us-east-2 |
ec2_securitygroup_not_used |
Non-default EC2 security group is in use |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) it is being used. |
Orphaned security groups may later be attached with overly permissive rules without review, enabling unintended inbound or lateral access that compromises confidentiality and integrity. They also create configuration drift, increasing the chance of misapplied access controls. |
Apply least privilege and strong lifecycle management: delete or quarantine unused security groups, enforce ownership tags and retention policies, review regularly, and manage changes via IaC with approvals. Restrict who can attach groups and use guardrails to prevent reuse of stale or permissive groups. |
•AWS-Foundational-Security-Best-Practices: EC2.22
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•NIST-CSF-2.0: ac_5, ip_1
•ENS-RD2022: mp.com.1.aws.sg.3
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-093604be72efb9791 |
|
Security group default (sg-093604be72efb9791) has 1 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0256d81b7afd54cf9 |
•Name=Ml_prod_sg
|
Security group ml_prod_sg (sg-0256d81b7afd54cf9) has 3 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0d87b03d9b2789750 |
|
Security group ec2-rds-2 (sg-0d87b03d9b2789750) has 0 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00aeb4e01a8f2c24c |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-074cd9d22ca5c317c (sg-00aeb4e01a8f2c24c) has 1 inbound rules and 0 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0dbf3eea7e40c7853 |
|
Security group default (sg-0dbf3eea7e40c7853) has 1 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-058c35683b5b40123 |
|
Security group rds-ec2-3 (sg-058c35683b5b40123) has 1 inbound rules and 0 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09c07fdd8e013a9c0 |
•Name=Scrivas_Ml_dev
|
Security group Scrivas_Ml_dev (sg-09c07fdd8e013a9c0) has 3 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0438e6794e0d9c0d7 |
|
Security group default (sg-0438e6794e0d9c0d7) has 1 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0a96c99b508643831 |
•GuardDutyManaged=true
|
Security group GuardDutyManagedSecurityGroup-vpc-03b6368ab9a21d2c7 (sg-0a96c99b508643831) has 1 inbound rules and 0 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0084c72426d93c9c6 |
|
Security group rds-ec2-1 (sg-0084c72426d93c9c6) has 1 inbound rules and 0 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0f29b9425a85de27f |
|
Security group ec2-rds-1 (sg-0f29b9425a85de27f) has 0 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09dff2d35b97ded21 |
•Name=scrivas_prod
|
Security group scrivas_prod_sg (sg-09dff2d35b97ded21) has 6 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-09fbc74b0b61042d9 |
|
Security group rds-ec2-2 (sg-09fbc74b0b61042d9) has 1 inbound rules and 0 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-06728bf2249b5938b |
|
Security group ec2-rds-3 (sg-06728bf2249b5938b) has 0 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-00c13b6b4f05b6748 |
•Name=sg-netbird
|
Security group launch-wizard-2 (sg-00c13b6b4f05b6748) has 4 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0621cd7244c8006b3 |
•Name=scrivas-dev-env
|
Security group launch-wizard-1 (sg-0621cd7244c8006b3) has 6 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ec2 |
us-east-2 |
ec2_securitygroup_with_many_ingress_egress_rules |
Security group has 50 or fewer inbound rules and 50 or fewer outbound rules |
arn:aws:ec2:us-east-2:716468089330:security-group/sg-0823502d51c886ab1 |
|
Security group scrivas_stage_env (sg-0823502d51c886ab1) has 6 inbound rules and 1 outbound rules. |
Rule sprawl weakens least privilege: large rule sets can hide overly permissive entries, exposing services to the Internet or unintended peers. This enables unauthorized access, data exfiltration, and lateral movement, impacting confidentiality and integrity, and can threaten availability via abuse of exposed services. |
Apply least privilege and segmentation:
- Limit rules to required ports, protocols, and sources
- Split workloads into dedicated security groups per role
- Prefer SG-to-SG references over broad CIDRs
- Regularly review, deduplicate, and remove stale rules
- Layer controls (NACLs, private endpoints) for defense in depth |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP03
•AWS-Foundational-Technical-Review: NETSEC-001
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
ecr |
us-east-2 |
ecr_registry_scan_images_on_push_enabled |
ECR registry has image scanning on push enabled for all repositories |
arn:aws:ecr:us-east-2:716468089330:registry/716468089330 |
|
ECR registry 716468089330 has ENHANCED scan with scan on push enabled. |
Absent or filtered scan on push lets vulnerable images be pushed and deployed without timely detection, enabling exploitation of known CVEs (RCE, privilege escalation), supply chain compromise, and lateral movement - threatening workload integrity and data confidentiality. |
Enable registry-wide scan on push and ensure rules apply to all repositories (no filters). Prefer enhanced scanning for broader coverage, and pair with continuous scans when available. Integrate findings into CI/CD gates and alerts to enforce defense in depth and block promotion of risky images. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.2
•C5-2025: PSS-11.01B, PSS-11.01AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.2
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•CCC-v2025.10: CCC.CntrReg.CN01.AR01
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
low |
ecr |
us-east-2 |
ecr_repositories_lifecycle_policy_enabled |
ECR repository has a lifecycle policy configured |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice |
|
Repository scrivas/patientsummaryservice has a lifecycle policy configured. |
Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage |
Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk. |
•AWS-Foundational-Security-Best-Practices: ECR.3
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: OPS-26.04B, OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7
•NIS2: 12.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
low |
ecr |
us-east-2 |
ecr_repositories_lifecycle_policy_enabled |
ECR repository has a lifecycle policy configured |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser |
|
Repository scrivas/patientdocumentparser has a lifecycle policy configured. |
Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage |
Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk. |
•AWS-Foundational-Security-Best-Practices: ECR.3
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: OPS-26.04B, OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7
•NIS2: 12.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
low |
ecr |
us-east-2 |
ecr_repositories_lifecycle_policy_enabled |
ECR repository has a lifecycle policy configured |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber |
|
Repository scrivas/sonioxtranscriber has a lifecycle policy configured. |
Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage |
Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk. |
•AWS-Foundational-Security-Best-Practices: ECR.3
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: OPS-26.04B, OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7
•NIS2: 12.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
low |
ecr |
us-east-2 |
ecr_repositories_lifecycle_policy_enabled |
ECR repository has a lifecycle policy configured |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions |
|
Repository scrivas/saisuggestions has a lifecycle policy configured. |
Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage |
Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk. |
•AWS-Foundational-Security-Best-Practices: ECR.3
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: OPS-26.04B, OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7
•NIS2: 12.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
low |
ecr |
us-east-2 |
ecr_repositories_lifecycle_policy_enabled |
ECR repository has a lifecycle policy configured |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor |
|
Repository scrivas/postprocessor has a lifecycle policy configured. |
Without lifecycle policies, images accumulate indefinitely, leading to:
- Availability issues when quotas block pushes and CI/CD
- Integrity risk from redeploying outdated, vulnerable images
- Cost growth from unnecessary storage |
Implement lifecycle policies per repository to expire untagged, old, or excess images and retain a small set of trusted releases. Validate outcomes before applying, review rules regularly, and apply consistently across Regions when replicating. This supports defense in depth by reducing image attack surface and operational risk. |
•AWS-Foundational-Security-Best-Practices: ECR.3
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: OPS-26.04B, OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•PCI-4.0: 10.5.1.8, 3.2.1.7, 3.3.1.1.7, 3.3.1.3.7, 3.3.2.7, 3.3.3.7
•NIS2: 12.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
critical |
ecr |
us-east-2 |
ecr_repositories_not_publicly_accessible |
ECR repository is not publicly accessible |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice |
|
Repository scrivas/patientsummaryservice is not publicly accessible. |
Public access to ECR repositories weakens confidentiality and integrity.
Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata. |
Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing |
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1
•ProwlerThreatScore-1.0: 2.3.7
•ISO27001-2022: A.8.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
critical |
ecr |
us-east-2 |
ecr_repositories_not_publicly_accessible |
ECR repository is not publicly accessible |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser |
|
Repository scrivas/patientdocumentparser is not publicly accessible. |
Public access to ECR repositories weakens confidentiality and integrity.
Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata. |
Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing |
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1
•ProwlerThreatScore-1.0: 2.3.7
•ISO27001-2022: A.8.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
critical |
ecr |
us-east-2 |
ecr_repositories_not_publicly_accessible |
ECR repository is not publicly accessible |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber |
|
Repository scrivas/sonioxtranscriber is not publicly accessible. |
Public access to ECR repositories weakens confidentiality and integrity.
Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata. |
Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing |
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1
•ProwlerThreatScore-1.0: 2.3.7
•ISO27001-2022: A.8.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
critical |
ecr |
us-east-2 |
ecr_repositories_not_publicly_accessible |
ECR repository is not publicly accessible |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions |
|
Repository scrivas/saisuggestions is not publicly accessible. |
Public access to ECR repositories weakens confidentiality and integrity.
Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata. |
Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing |
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1
•ProwlerThreatScore-1.0: 2.3.7
•ISO27001-2022: A.8.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
critical |
ecr |
us-east-2 |
ecr_repositories_not_publicly_accessible |
ECR repository is not publicly accessible |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor |
|
Repository scrivas/postprocessor is not publicly accessible. |
Public access to ECR repositories weakens confidentiality and integrity.
Anyone can pull images, exposing proprietary code or embedded secrets; if pushes are allowed, attackers can poison images, enabling supply-chain compromise. Uncontrolled pulls can raise egress costs and leak repository metadata. |
Apply least privilege to repository policies:
- Avoid Principal:"*" and block anonymous access
- Grant minimal actions to specific accounts/roles
- Require authenticated pulls/pushes via IAM
- Use private connectivity (e.g., VPC endpoints)
- Add defense in depth with image scanning and signing |
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1
•ProwlerThreatScore-1.0: 2.3.7
•ISO27001-2022: A.8.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_scan_images_on_push_enabled |
[DEPRECATED] ECR repository has image scanning on push enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice |
|
ECR repository scrivas/patientsummaryservice has scan on push disabled. |
Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines. |
Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management. |
•AWS-Foundational-Security-Best-Practices: ECR.1
•C5-2025: PSS-11.01B, PSS-11.01AC
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02
•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•SecNumCloud-3.2: 12.11, 14.6
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_scan_images_on_push_enabled |
[DEPRECATED] ECR repository has image scanning on push enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser |
|
ECR repository scrivas/patientdocumentparser has scan on push disabled. |
Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines. |
Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management. |
•AWS-Foundational-Security-Best-Practices: ECR.1
•C5-2025: PSS-11.01B, PSS-11.01AC
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02
•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•SecNumCloud-3.2: 12.11, 14.6
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_scan_images_on_push_enabled |
[DEPRECATED] ECR repository has image scanning on push enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber |
|
ECR repository scrivas/sonioxtranscriber has scan on push disabled. |
Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines. |
Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management. |
•AWS-Foundational-Security-Best-Practices: ECR.1
•C5-2025: PSS-11.01B, PSS-11.01AC
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02
•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•SecNumCloud-3.2: 12.11, 14.6
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_scan_images_on_push_enabled |
[DEPRECATED] ECR repository has image scanning on push enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions |
|
ECR repository scrivas/saisuggestions has scan on push disabled. |
Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines. |
Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management. |
•AWS-Foundational-Security-Best-Practices: ECR.1
•C5-2025: PSS-11.01B, PSS-11.01AC
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02
•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•SecNumCloud-3.2: 12.11, 14.6
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_scan_images_on_push_enabled |
[DEPRECATED] ECR repository has image scanning on push enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor |
|
ECR repository scrivas/postprocessor has scan on push disabled. |
Without scan on push, images with known CVEs can enter registries and reach runtime unnoticed, undermining integrity and confidentiality through exploitable packages. Attackers may achieve code execution and lateral movement. Delayed detection increases operational risk and extends remediation timelines. |
Enable image scanning on push (scan_on_push) for all repositories and use findings as promotion gates. Prefer continuous/enhanced scanning for defense in depth, set severity thresholds, and block or quarantine noncompliant images. Integrate results with CI/CD and adopt shift-left vulnerability management. |
•AWS-Foundational-Security-Best-Practices: ECR.1
•C5-2025: PSS-11.01B, PSS-11.01AC
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP06, SEC06-BP02, SEC11-BP02
•PCI-4.0: 11.3.1.2.1, 11.3.1.3.3, 11.3.1.3
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•SecNumCloud-3.2: 12.11, 14.6
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_tag_immutability |
ECR repository has image tag immutability enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientsummaryservice |
|
Repository scrivas/patientsummaryservice does not have immutability configured. |
Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality. |
Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored. |
•AWS-Foundational-Security-Best-Practices: ECR.2
•C5-2025: AM-09.01B, OPS-26.03B
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_tag_immutability |
ECR repository has image tag immutability enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/patientdocumentparser |
|
Repository scrivas/patientdocumentparser does not have immutability configured. |
Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality. |
Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored. |
•AWS-Foundational-Security-Best-Practices: ECR.2
•C5-2025: AM-09.01B, OPS-26.03B
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_tag_immutability |
ECR repository has image tag immutability enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/sonioxtranscriber |
|
Repository scrivas/sonioxtranscriber does not have immutability configured. |
Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality. |
Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored. |
•AWS-Foundational-Security-Best-Practices: ECR.2
•C5-2025: AM-09.01B, OPS-26.03B
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_tag_immutability |
ECR repository has image tag immutability enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/saisuggestions |
|
Repository scrivas/saisuggestions does not have immutability configured. |
Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality. |
Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored. |
•AWS-Foundational-Security-Best-Practices: ECR.2
•C5-2025: AM-09.01B, OPS-26.03B
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| FAIL |
medium |
ecr |
us-east-2 |
ecr_repositories_tag_immutability |
ECR repository has image tag immutability enabled |
arn:aws:ecr:us-east-2:716468089330:repository/scrivas/postprocessor |
|
Repository scrivas/postprocessor does not have immutability configured. |
Mutable tags allow replacing the image behind a trusted tag, undermining release integrity. This enables supply-chain injection, unintended rollouts, and backdoored deployments, harming availability. Malicious images can exfiltrate data, impacting confidentiality. |
Enable tag immutability so tags map to a single artifact. Use versioned tags per build, block retagging in CI/CD, and apply least privilege for push actions. Layer image signing and admission controls to run only trusted images. If exceptions are needed, keep them narrow and monitored. |
•AWS-Foundational-Security-Best-Practices: ECR.2
•C5-2025: AM-09.01B, OPS-26.03B
•FedRAMP-20x-KSI-Low-25.05C: ksi-tpr
|
| PASS |
high |
emr |
us-east-1 |
emr_cluster_account_public_block_enabled |
EMR account has Block Public Access enabled |
arn:aws:elasticmapreduce:us-east-1:716468089330:cluster |
|
EMR Account has Block Public Access enabled. |
Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.
Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption. |
Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.
Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth. |
•AWS-Foundational-Security-Best-Practices: EMR.2
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8
•ProwlerThreatScore-1.0: 2.3.11
•ISO27001-2022: A.8.1
|
| PASS |
high |
emr |
us-east-2 |
emr_cluster_account_public_block_enabled |
EMR account has Block Public Access enabled |
arn:aws:elasticmapreduce:us-east-2:716468089330:cluster |
|
EMR Account has Block Public Access enabled. |
Public EMR-facing rules enable Internet reachability to cluster nodes and UIs, inviting brute force and remote exploits.
Attackers can exfiltrate job data, alter processing, or pivot into the VPC, degrading confidentiality, integrity, and availability through data theft, tampering, and service disruption. |
Keep EMR Block Public Access enabled and minimize exceptions; allow only required ports and restrict sources.
Apply least privilege on security groups, place clusters in private subnets, and use bastion hosts or Session Manager. Combine with VPC controls and monitoring for defense in depth. |
•AWS-Foundational-Security-Best-Practices: EMR.2
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•PCI-4.0: 1.2.8.16, 1.3.1.18, 1.3.2.18, 1.4.2.17, 1.5.1.16, 10.3.2.12, 3.5.1.3.14, A1.1.2.8, A1.1.3.16, A3.4.1.8
•ProwlerThreatScore-1.0: 2.3.11
•ISO27001-2022: A.8.1
|
| PASS |
high |
eventbridge |
us-east-1 |
eventbridge_bus_cross_account_access |
AWS EventBridge event bus does not allow cross-account access |
arn:aws:events:us-east-1:716468089330:event-bus/default |
|
EventBridge event bus default does not allow cross-account access. |
Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods. |
Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.
Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_5, ac_4, dp_4
•CCC-v2025.10: CCC.Core.CN05.AR03
|
| PASS |
high |
eventbridge |
us-east-2 |
eventbridge_bus_cross_account_access |
AWS EventBridge event bus does not allow cross-account access |
arn:aws:events:us-east-2:716468089330:event-bus/default |
|
EventBridge event bus default does not allow cross-account access. |
Cross-account event injection can erode integrity and availability. Spoofed events may trigger rules and invoke downstream targets, causing unintended actions, data exposure via targets, lateral movement through over-privileged roles, and cost or service disruption from event floods. |
Apply least privilege on the event bus resource policy: allow only specific account IDs or org scope (e.g., aws:PrincipalOrgID) and avoid wildcard Principal or *.
Constrain rules to trusted senders using the account field and vetted sources, and add monitoring/throttling for defense in depth. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: OPS-13.03AC, IAM-10.01B, COS-04.01B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_5, ac_4, dp_4
•CCC-v2025.10: CCC.Core.CN05.AR03
|
| PASS |
high |
eventbridge |
us-east-1 |
eventbridge_bus_exposed |
AWS EventBridge event bus policy does not allow public access |
arn:aws:events:us-east-1:716468089330:event-bus/default |
|
EventBridge event bus default is not exposed to everyone. |
Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events. |
Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: "*".
Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity. |
•CIS-7.0: 2.21
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_5, ac_4, dp_4
•ProwlerThreatScore-1.0: 2.3.13
|
| PASS |
high |
eventbridge |
us-east-2 |
eventbridge_bus_exposed |
AWS EventBridge event bus policy does not allow public access |
arn:aws:events:us-east-2:716468089330:event-bus/default |
|
EventBridge event bus default is not exposed to everyone. |
Publicly accessible event buses enable event injection and unauthorized rule changes, undermining integrity and enabling lateral movement. Attackers can trigger downstream targets, causing data exposure, service disruption, and unexpected costs through high-volume events. |
Apply least privilege resource policies: limit principals to specific accounts or your organization, and constrain actions and event attributes (e.g., source, detail-type). Avoid Principal: "*".
Use defense in depth with rule patterns that include the expected account. Monitor policy changes and bus activity. |
•CIS-7.0: 2.21
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_5, ac_4, dp_4
•ProwlerThreatScore-1.0: 2.3.13
|
| FAIL |
medium |
guardduty |
us-east-1 |
guardduty_centrally_managed |
GuardDuty detector is managed by an administrator account or is the administrator with member accounts |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c is not centrally managed. |
Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability. |
Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization
•ENS-RD2022: op.mon.1.aws.gd.3
•ISO27001-2022: A.5.25, A.5.28, A.5.29
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| FAIL |
medium |
guardduty |
us-east-2 |
guardduty_centrally_managed |
GuardDuty detector is managed by an administrator account or is the administrator with member accounts |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc is not centrally managed. |
Lack of central management fragments visibility and slows incident response across accounts and regions. Adversaries can persist unnoticed, perform lateral movement, exfiltrate data, and alter configurations, harming confidentiality, integrity, and availability. |
Designate a delegated administrator (preferably via AWS Organizations) and enroll all accounts as members. Enable auto-enrollment for new accounts, standardize detector settings across required regions, and route findings to central monitoring. Apply least privilege and separation of duties. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•AWS-Account-Security-Onboarding: Export scan results as metrics in centralized collector, Enable as part of central configuration for Organization
•ENS-RD2022: op.mon.1.aws.gd.3
•ISO27001-2022: A.5.25, A.5.28, A.5.29
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| FAIL |
high |
guardduty |
us-east-1 |
guardduty_delegated_admin_enabled_all_regions |
GuardDuty has delegated admin configured and is enabled in all regions with organization auto-enable |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty in region us-east-1 has issues: no delegated administrator configured. |
Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration. |
Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization. |
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
|
| FAIL |
high |
guardduty |
us-east-2 |
guardduty_delegated_admin_enabled_all_regions |
GuardDuty has delegated admin configured and is enabled in all regions with organization auto-enable |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty in region us-east-2 has issues: no delegated administrator configured. |
Without org-wide Amazon GuardDuty configuration, gaps can occur where detectors are enabled in some regions but not others, delegated admin is inconsistent, and new accounts are not auto-enrolled. This fragments threat visibility, delays incident response, and allows adversaries to exploit unmonitored regions or accounts for lateral movement and data exfiltration. |
Configure a delegated administrator for GuardDuty via AWS Organizations. Enable GuardDuty detectors in all opted-in regions and configure auto-enable to automatically enroll new member accounts. This ensures consistent threat detection coverage across the entire organization. |
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_ec2_malware_protection_enabled |
GuardDuty detector has Malware Protection for EC2 enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Malware Protection for EC2 enabled. |
Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
- Confidentiality loss via data exfiltration/credential theft
- Integrity compromise through tampering and backdoors
- Availability impact from ransomware/cryptominers
Persistence increases lateral movement across the environment. |
Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9
•C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9
•NIST-CSF-2.0: ip_7, cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_ec2_malware_protection_enabled |
GuardDuty detector has Malware Protection for EC2 enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Malware Protection for EC2 enabled. |
Absent this coverage, malware on EC2 or containers can remain undetected, enabling:
- Confidentiality loss via data exfiltration/credential theft
- Integrity compromise through tampering and backdoors
- Availability impact from ransomware/cryptominers
Persistence increases lateral movement across the environment. |
Enable Malware Protection for EC2 across all accounts and Regions under centralized administration. Apply least privilege to findings access, define scan scope with tags and minimize exclusions, and retain snapshots based on data sensitivity. Integrate alerts with IR/SIEM and pair with hardening and vulnerability scanning for defense in depth. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.10.9
•C5-2025: OPS-04.01B, OPS-05.01B, OPS-05.02B, OPS-05.01AS, OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.10.9
•NIST-CSF-2.0: ip_7, cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_eks_audit_log_enabled |
GuardDuty detector has EKS Audit Log Monitoring enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Audit Log Monitoring enabled. |
Without it, Kubernetes API abuse may go undetected, impacting CIA:
- Secret access and data exfiltration
- RBAC changes enabling privilege escalation
- Rogue deployments for persistence/cryptomining
Attackers can laterally move to AWS using harvested credentials. |
Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
- Route findings to alerting/IR workflows
- Enforce least privilege on access to findings and configs
- Combine with defense-in-depth: hardened RBAC and runtime monitoring |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•SecNumCloud-3.2: 12.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•NIS2: 3.2.3.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_eks_audit_log_enabled |
GuardDuty detector has EKS Audit Log Monitoring enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Audit Log Monitoring enabled. |
Without it, Kubernetes API abuse may go undetected, impacting CIA:
- Secret access and data exfiltration
- RBAC changes enabling privilege escalation
- Rogue deployments for persistence/cryptomining
Attackers can laterally move to AWS using harvested credentials. |
Enable EKS Audit Log Monitoring on all detectors in every required Region, centrally managed by the GuardDuty administrator.
- Route findings to alerting/IR workflows
- Enforce least privilege on access to findings and configs
- Combine with defense-in-depth: hardened RBAC and runtime monitoring |
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-23.01B, OPS-26.05B, OPS-26.01AS
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2, 2.11.3
•SecNumCloud-3.2: 12.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•NIS2: 3.2.3.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
medium |
guardduty |
us-east-1 |
guardduty_eks_runtime_monitoring_enabled |
GuardDuty detector has EKS Runtime Monitoring enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has EKS Runtime Monitoring enabled. |
Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability). |
- Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
- Enforce least privilege for agents and segment cluster access
- Integrate findings with response workflows and periodically verify runtime coverage
|
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_7, cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•NIS2: 3.2.3.h
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
medium |
guardduty |
us-east-2 |
guardduty_eks_runtime_monitoring_enabled |
GuardDuty detector has EKS Runtime Monitoring enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has EKS Runtime Monitoring enabled. |
Absent EKS runtime monitoring, in-cluster activity is blind to detection. Adversaries can run malware or cryptominers, exfiltrate secrets via pods, tamper with workloads, or pivot to other services, degrading confidentiality, corrupting integrity, and exhausting resources (availability). |
- Enable EKS Runtime Monitoring with automated agent management across all accounts and clusters
- Enforce least privilege for agents and segment cluster access
- Integrate findings with response workflows and periodically verify runtime coverage
|
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: ip_7, cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•NIS2: 3.2.3.h
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_is_enabled |
GuardDuty detector is enabled and not suspended |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c enabled. |
Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions. |
Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth. |
•CISA: your-systems-3, your-crisis-response-2
•SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4
•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046
•AWS-Foundational-Security-Best-Practices: GuardDuty.1
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC
•HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04
•NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7
•PCI-4.0: 11.5.1.1.2, 11.5.1.2
•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4
•NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b
•AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection
•ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1
•AWS-Foundational-Technical-Review: IAM-002
•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5
•CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01
•SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2
•FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3
•PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c
•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_is_enabled |
GuardDuty detector is enabled and not suspended |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc enabled. |
Without active GuardDuty, threats in CloudTrail, VPC Flow Logs, DNS, S3, EKS, EBS, and Lambda can go unnoticed. Attackers can exfiltrate data, move laterally, and mine crypto, degrading confidentiality, integrity, and availability-especially in unmonitored Regions. |
Enable and keep GuardDuty active in all supported Regions and accounts under a delegated admin. Turn on relevant protection plans and auto-enroll new accounts. Avoid suspended detectors, enforce least privilege for admins, and integrate findings into response for defense in depth. |
•CISA: your-systems-3, your-crisis-response-2
•SOC2: cc_3_1, cc_3_2, cc_4_2, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4
•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1552, T1048, T1496, T1498, T1580, T1526, T1046
•AWS-Foundational-Security-Best-Practices: GuardDuty.1
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-05.03AC, OPS-13.01B, OPS-23.01B, SIM-01.02AC
•HIPAA: 164_308_a_1_ii_a, 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04, SEC05-BP04
•NIST-CSF-2.0: ip_7, ip_12, cm_1, cm_7
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_4, 3_14_6, 3_14_7
•PCI-4.0: 11.5.1.1.2, 11.5.1.2
•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, ra_5, sa_10, si_4_1, si_4_2, si_4_4, si_4_5, si_4_16, si_4
•NIST-800-53-Revision-5: ac_2_12_a, ac_3_12_b, au_3_1, au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, cm_8_3_a, pe_6_2, pe_6_4, pm_14_a_1, pm_14_b, pm_16, pm_31, ra_1_a, ra_1_a_1, ra_1_a_2, ra_3_4, ra_3_a_1, ra_5_a, ra_5_4, ra_10_a, ra_10_a_1, ra_10_a_2, sc_5_1, sc_5_3_a, sc_5_3_b, sc_5_a, sc_5_b, sc_43_b, si_3_8_a, si_4_a, si_4_a_1, si_4_a_2, si_4_b, si_4_c, si_4_1, si_4_2, si_4_3, si_4_4_a, si_4_4_b, si_4_10, si_4_13_a, si_4_14, si_4_23, si_4_25, si_5_1, si_5_b
•AWS-Account-Security-Onboarding: Enabled security services, Alert on each High finding, Enable as part of central configuration for Organization, Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection
•ENS-RD2022: op.exp.6.aws.gd.1, op.exp.7.aws.gd.1, op.mon.1.aws.gd.1, op.mon.1.aws.gd.2, op.mon.3.r1.aws.gd.1, op.mon.3.r3.aws.gd.1
•AWS-Foundational-Technical-Review: IAM-002
•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5
•CCC-v2025.10: CCC.Core.CN07.AR01, CCC.IAM.CN10.AR01
•SecNumCloud-3.2: 12.4, 12.9, 13.3, 16.2
•FFIEC: d1-rm-ra-b-2, d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3
•PCI-3.2.1: 11.4, 11.4.a, 11.4.b, 11.4.c
•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, cm-8-3-a, ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, sc-5, si-4-1, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, cm-8, ir-4, sc-5
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_lambda_protection_enabled |
GuardDuty detector has Lambda Protection enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c has Lambda Protection enabled. |
Without Lambda Protection, Lambda network traffic is uninspected, enabling:
- C2 callbacks and data exfiltration (confidentiality)
- Malicious code altering data or configs (integrity)
- Lateral movement or abuse causing disruption (availability) |
Enable Lambda Protection on all detectors in every active Region and account.
Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_lambda_protection_enabled |
GuardDuty detector has Lambda Protection enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has Lambda Protection enabled. |
Without Lambda Protection, Lambda network traffic is uninspected, enabling:
- C2 callbacks and data exfiltration (confidentiality)
- Malicious code altering data or configs (integrity)
- Lateral movement or abuse causing disruption (availability) |
Enable Lambda Protection on all detectors in every active Region and account.
Apply least privilege to Lambda roles, restrict egress with network controls, and integrate findings with alerting and response for defense in depth. In multi-account setups, manage centrally for consistent coverage. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_no_high_severity_findings |
GuardDuty detector has no high severity findings |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector 06cd01bd46fd95ae0932955e7606db6c does not have high severity findings. |
Unresolved High findings often signal active compromise, enabling:
- Data exfiltration and unauthorized access (confidentiality)
- Privilege escalation and tampering (integrity)
- Disruption via malware/crypto-mining (availability)
Attackers can pivot laterally and persist if not contained. |
Treat High findings as incidents.
- Prioritize triage and containment; isolate affected resources, rotate secrets
- Automate alerting and response with playbooks; integrate into IR
- Enforce least privilege, network segmentation, and hardened baselines
- Continuously tune detections and remove unused access to prevent recurrence
|
•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B
•HIPAA: 164_308_a_6_ii
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_2
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3
•NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4
•NIST-800-53-Revision-5: ir_4_a
•AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection
•ENS-RD2022: op.exp.7.aws.gd.1
•AWS-Foundational-Technical-Review: IAM-002, SECOPS-001
•NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3
•CCC-v2025.10: CCC.Core.CN07.AR01
•SecNumCloud-3.2: 12.4, 16.3
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d3-dc-an-b-1, d5-er-es-b-4
•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c
•FedRAMP-Low-Revision-4: ir-4
•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr
|
| FAIL |
high |
guardduty |
us-east-2 |
guardduty_no_high_severity_findings |
GuardDuty detector has no high severity findings |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector 4acd016b4a01f41ab229556d98e12efc has 1 high severity findings. |
Unresolved High findings often signal active compromise, enabling:
- Data exfiltration and unauthorized access (confidentiality)
- Privilege escalation and tampering (integrity)
- Disruption via malware/crypto-mining (availability)
Attackers can pivot laterally and persist if not contained. |
Treat High findings as incidents.
- Prioritize triage and containment; isolate affected resources, rotate secrets
- Automate alerting and response with playbooks; integrate into IR
- Enforce least privilege, network segmentation, and hardened baselines
- Continuously tune detections and remove unused access to prevent recurrence
|
•SOC2: cc_3_2, cc_4_2, cc_7_3, cc_7_4
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•C5-2025: OIS-08.08B, AM-09.03AC, OPS-04.01B, OPS-13.01B, OPS-18.02B, OPS-18.03B, OPS-23.01B, SIM-03.01B
•HIPAA: 164_308_a_6_ii
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•NIST-CSF-2.0: ov_2
•NIST-800-171-Revision-2: 3_6_1, 3_6_2, 3_11_2, 3_11_3
•NIST-800-53-Revision-4: ir_4_1, ir_6_1, ir_7_1, ra_5, sa_10, si_4
•NIST-800-53-Revision-5: ir_4_a
•AWS-Account-Security-Onboarding: Threat Detection, RDS protection, Lambda protection, S3 protection, Malware Scanning, Confirm that events are present in SIEM, Apply suppression filters to disable useless findings, Include in process of incident response based on events, Runtime protection
•ENS-RD2022: op.exp.7.aws.gd.1
•AWS-Foundational-Technical-Review: IAM-002, SECOPS-001
•NIST-CSF-1.1: ae_4, cm_5, cp_4, an_2, mi_3
•CCC-v2025.10: CCC.Core.CN07.AR01
•SecNumCloud-3.2: 12.4, 16.3
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d3-dc-an-b-1, d5-er-es-b-4
•ISO27001-2022: A.5.19, A.5.21, A.5.25, A.5.28, A.5.29, A.8.7, A.8.9
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRamp-Moderate-Revision-4: ir-4-1, ir-4-1, ir-6-1, ir-7-1, ra-5, sa-10, si-4-a-b-c
•FedRAMP-Low-Revision-4: ir-4
•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_rds_protection_enabled |
GuardDuty detector has RDS Protection enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector has RDS Protection enabled. |
Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability. |
Enable GuardDuty RDS Protection across all accounts and Regions.
- Enforce least privilege for DB users and rotate credentials
- Restrict network exposure to databases
- Integrate findings with alerting and incident response for rapid containment |
•AWS-Foundational-Security-Best-Practices: GuardDuty.9
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_rds_protection_enabled |
GuardDuty detector has RDS Protection enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector has RDS Protection enabled. |
Without RDS Protection, anomalous database logins can go unnoticed. Attackers using stolen or brute-forced credentials may access data, alter schemas, or pivot via the DB, impacting confidentiality and integrity, and potentially availability. |
Enable GuardDuty RDS Protection across all accounts and Regions.
- Enforce least privilege for DB users and rotate credentials
- Restrict network exposure to databases
- Integrate findings with alerting and incident response for rapid containment |
•AWS-Foundational-Security-Best-Practices: GuardDuty.9
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-1 |
guardduty_s3_protection_enabled |
GuardDuty detector has S3 Protection enabled |
arn:aws:guardduty:us-east-1:716468089330:detector/06cd01bd46fd95ae0932955e7606db6c |
|
GuardDuty detector has S3 Protection enabled. |
Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
- Exfiltration via mass reads/copies
- Destructive deletes
- Policy/ACL tampering
Undetected actions degrade data confidentiality, integrity, and availability. |
Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering. |
•AWS-Foundational-Security-Best-Practices: GuardDuty.10
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
guardduty |
us-east-2 |
guardduty_s3_protection_enabled |
GuardDuty detector has S3 Protection enabled |
arn:aws:guardduty:us-east-2:716468089330:detector/4acd016b4a01f41ab229556d98e12efc |
|
GuardDuty detector has S3 Protection enabled. |
Without S3 Protection, object-level S3 activity isn't analyzed, enabling:
- Exfiltration via mass reads/copies
- Destructive deletes
- Policy/ACL tampering
Undetected actions degrade data confidentiality, integrity, and availability. |
Enable S3 Protection across all accounts and Regions to add defense in depth for S3. Apply least privilege to IAM and bucket policies, keep Block Public Access enforced, integrate findings with alerting, and regularly review anomalies to prevent data loss and tampering. |
•AWS-Foundational-Security-Best-Practices: GuardDuty.10
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: OPS-23.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: cm_7
•SecNumCloud-3.2: 12.4
•AWS-AI-Security-Framework-1.0: AISF-DETECT-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/Admin |
|
Group Admin provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/devops |
|
Group devops provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/ecr-push-group |
|
Group ecr-push-group provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/otherpermission |
|
Group otherpermission provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/secertmanageraccess |
|
Group secertmanageraccess provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_administrator_access_with_mfa |
IAM group members granted AdministratorAccess have MFA enabled |
arn:aws:iam::716468089330:group/storage-access |
|
Group storage-access provides non-administrative access. |
Admin users without MFA are vulnerable to single-factor compromise. Stolen or guessed credentials can yield full control, enabling privilege escalation, policy changes, data exfiltration, and destructive operations, impacting confidentiality, integrity, and availability. |
Enforce MFA for all administrator identities.
- Add conditions (e.g., aws:MultiFactorAuthPresent) to privileged permissions
- Prefer hardware/FIDO2 devices
- Apply least privilege and favor roles/SSO over users
- Continuously monitor MFA status and remove unused admin access |
•MITRE-ATTACK: T1078, T1098, T1550
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-05.02B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•NIST-CSF-2.0: rr_1, ac_4, ip_1
•ASD-Essential-Eight-Nov 2023: E8-3.1
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR02, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•NIS2: 11.1.2.c, 11.3.2.a, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_avoid_root_usage |
AWS account root user has not been used in the last day |
arn:aws:iam::716468089330:root |
|
Root user in the account wasn't accessed in the last 1 days. |
Recent root usage expands blast radius:
- Data exfiltration (confidentiality)
- Policy/key tampering (integrity)
- Resource deletion and billing changes (availability)
Routine use reduces anomaly visibility and eases account takeover impact. |
Minimize root usage by applying least privilege with admin roles or federated SSO and temporary credentials.
- Enforce MFA on root
- Avoid or remove root access keys
- Require multi-person approval
- Monitor and alert on any root sign-in
- Use org guardrails for defense in depth |
•CIS-7.0: 2.7
•CIS-1.4: 1.7
•CIS-1.5: 1.7
•MITRE-ATTACK: T1078, T1098
•ISO27001-2013: A.9.2.H, A.9.4.H
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.10.2
•C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-06.04B
•CIS-2.0: 1.7
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.6
•AWS-Account-Security-Onboarding: Block root user
•CIS-3.0: 1.7
•ENS-RD2022: op.acc.2.aws.iam.4, op.acc.4.aws.iam.7
•CIS-6.0: 2.6
•CCC-v2025.10: CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.6
•ProwlerThreatScore-1.0: 1.2.5
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-04
•CIS-4.0.1: 1.7
•NIS2: 6.7.2.e, 11.3.2.b, 11.3.2.c, 11.4.2.a
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSOrganizationsServiceTrustPolicy |
|
AWS policy AWSOrganizationsServiceTrustPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy |
|
AWS policy CloudWatchAgentServerPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AWSServiceCatalogAdminFullAccess |
|
AWS policy AWSServiceCatalogAdminFullAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/CloudwatchApplicationInsightsServiceLinkedRolePolicy |
|
AWS policy CloudwatchApplicationInsightsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore |
|
AWS policy AmazonSSMManagedInstanceCore is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AutoScalingServiceRolePolicy |
|
AWS policy AutoScalingServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonRDSServiceRolePolicy |
|
AWS policy AmazonRDSServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSElasticLoadBalancingServiceRolePolicy |
|
AWS policy AWSElasticLoadBalancingServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyServiceRolePolicy |
|
AWS policy AmazonGuardDutyServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/CloudWatchReadOnlyAccess |
|
AWS policy CloudWatchReadOnlyAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSTrustedAdvisorServiceRolePolicy |
|
AWS policy AWSTrustedAdvisorServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSEC2SpotServiceRolePolicy |
|
AWS policy AWSEC2SpotServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubServiceRolePolicy |
|
AWS policy AWSSecurityHubServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AdministratorAccess |
|
AWS policy AdministratorAccess is attached and allows '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSSupportServiceRolePolicy |
|
AWS policy AWSSupportServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/CloudWatchLogsFullAccess |
|
AWS policy CloudWatchLogsFullAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/SecretsManagerReadWrite |
|
AWS policy SecretsManagerReadWrite is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/service-role/AmazonRDSEnhancedMonitoringRole |
|
AWS policy AmazonRDSEnhancedMonitoringRole is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSClusterPolicy |
|
AWS policy AmazonEKSClusterPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonMacieServiceRolePolicy |
|
AWS policy AmazonMacieServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSConfigServiceRolePolicy |
|
AWS policy AWSConfigServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy |
|
AWS policy AmazonEKS_CNI_Policy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly |
|
AWS policy AmazonEC2ContainerRegistryReadOnly is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/SecurityAudit |
|
AWS policy SecurityAudit is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/IAMUserChangePassword |
|
AWS policy IAMUserChangePassword is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/CloudTrailServiceRolePolicy |
|
AWS policy CloudTrailServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy |
|
AWS policy AmazonEKSWorkerNodePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonS3FullAccess |
|
AWS policy AmazonS3FullAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk |
|
AWS policy AdministratorAccess-AWSElasticBeanstalk is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonEKSServiceRolePolicy |
|
AWS policy AmazonEKSServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSWorkerNodeMinimalPolicy |
|
AWS policy AmazonEKSWorkerNodeMinimalPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/ServiceQuotasServiceRolePolicy |
|
AWS policy ServiceQuotasServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonGuardDutyMalwareProtectionServiceRolePolicy |
|
AWS policy AmazonGuardDutyMalwareProtectionServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSGlobalAcceleratorSLRPolicy |
|
AWS policy AWSGlobalAcceleratorSLRPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSDashboardConsoleReadOnly |
|
AWS policy AmazonEKSDashboardConsoleReadOnly is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonDevOpsGuruFullAccess |
|
AWS policy AmazonDevOpsGuruFullAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryPullOnly |
|
AWS policy AmazonEC2ContainerRegistryPullOnly is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonSSMManagedEC2InstanceDefaultPolicy |
|
AWS policy AmazonSSMManagedEC2InstanceDefaultPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSNetworkingPolicy |
|
AWS policy AmazonEKSNetworkingPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSComputePolicy |
|
AWS policy AmazonEKSComputePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AWSQuickSetupDevOpsGuruPermissionsBoundary |
|
AWS policy AWSQuickSetupDevOpsGuruPermissionsBoundary is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSResourceExplorerServiceRolePolicy |
|
AWS policy AWSResourceExplorerServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSServiceRoleForAmazonEKSNodegroup |
|
AWS policy AWSServiceRoleForAmazonEKSNodegroup is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSBlockStoragePolicy |
|
AWS policy AmazonEKSBlockStoragePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonDevOpsGuruOrganizationsAccess |
|
AWS policy AmazonDevOpsGuruOrganizationsAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonInspector2ServiceRolePolicy |
|
AWS policy AmazonInspector2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSLoadBalancingPolicy |
|
AWS policy AmazonEKSLoadBalancingPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonEKSVPCResourceController |
|
AWS policy AmazonEKSVPCResourceController is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AmazonInspector2AgentlessServiceRolePolicy |
|
AWS policy AmazonInspector2AgentlessServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSUserNotificationsServiceLinkedRolePolicy |
|
AWS policy AWSUserNotificationsServiceLinkedRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AdministratorAccess-Amplify |
|
AWS policy AdministratorAccess-Amplify is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubV2ServiceRolePolicy |
|
AWS policy AWSSecurityHubV2ServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/service-role/AmazonEBSCSIDriverPolicy |
|
AWS policy AmazonEBSCSIDriverPolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonDevOpsGuruReadOnlyAccess |
|
AWS policy AmazonDevOpsGuruReadOnlyAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/AmazonDevOpsGuruConsoleFullAccess |
|
AWS policy AmazonDevOpsGuruConsoleFullAccess is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_aws_attached_policy_no_administrative_privileges |
Attached AWS-managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::aws:policy/aws-service-role/AccessAnalyzerServiceRolePolicy |
|
AWS policy AccessAnalyzerServiceRolePolicy is attached but does not allow '*:*' administrative privileges. |
Unrestricted *:* access enables any action on any resource, risking:
- Data exfiltration (confidentiality)
- Unauthorized changes and policy tampering (integrity)
- Service deletion or shutdown (availability)
Attackers can disable logging, create backdoor principals, and expand lateral movement. |
Apply least privilege: avoid attaching AWS-managed policies that grant *:*.
- Use customer-managed, scoped policies per role
- Enforce separation of duties and permissions boundaries
- Prefer temporary, time-bound elevation for emergencies with MFA
- Regularly review access and use conditions to constrain context |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
low |
iam |
us-east-2 |
iam_check_saml_providers_sts |
IAM SAML provider exists in the account |
arn:aws:iam::716468089330:root |
|
No SAML Providers found. |
Without SAML federation, users rely on long-lived IAM keys. Compromised keys enable persistent API access, causing data exfiltration (C), unauthorized resource or policy changes (I), and difficult revocation. Lack of IdP controls (e.g., MFA, session limits) weakens accountability and access governance. |
Adopt SAML federation to issue short-lived STS credentials. Map users to roles with least privilege, enforce MFA at the IdP, and set conservative session durations. Retire IAM user access keys for interactive use and monitor role sessions as defense in depth. If federation isn't possible, tightly scope, rotate, and audit keys. |
•CIS-7.0: 2.19
•CIS-1.4: 1.21
•CIS-1.5: 1.21
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•CIS-2.0: 1.21
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.20
•CIS-3.0: 1.21
•ENS-RD2022: op.acc.1.aws.iam.2
•CIS-6.0: 2.20
•CCC-v2025.10: CCC.Core.CN05.AR06, CCC.IAM.CN09.AR01
•ProwlerThreatScore-1.0: 1.2.7
•CIS-4.0.1: 1.21
|
| PASS |
high |
iam |
us-east-2 |
iam_customer_attached_policy_no_administrative_privileges |
Attached IAM customer-managed policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 is attached but does not allow '*:*' administrative privileges. |
Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account. |
Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_customer_attached_policy_no_administrative_privileges |
Attached IAM customer-managed policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 is attached but does not allow '*:*' administrative privileges. |
Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account. |
Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_customer_attached_policy_no_administrative_privileges |
Attached IAM customer-managed policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom policy VPCFlowLogs-CloudWatch-Policy-1781174377138 is attached but does not allow '*:*' administrative privileges. |
Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account. |
Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_customer_attached_policy_no_administrative_privileges |
Attached IAM customer-managed policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom policy scrivas-s3-storage-policy is attached but does not allow '*:*' administrative privileges. |
Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account. |
Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_customer_attached_policy_no_administrative_privileges |
Attached IAM customer-managed policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom policy gitlab-ci-ecr-push is attached but does not allow '*:*' administrative privileges. |
Unrestricted admin access lets any attached principal perform any action on any resource, enabling data exfiltration, policy tampering, credential creation, logging disablement, and destructive deletions-compromising confidentiality, integrity, and availability across the account. |
Enforce least privilege: replace wildcards with specific actions, scope Resource to needed ARNs, and add restrictive Conditions. Prefer role-based access and separation of duties. Use permissions boundaries and organization guardrails, and regularly review policies with policy validation and Access Analyzer. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.14
•SOC2: cc_1_3, cc_6_3
•CIS-1.4: 1.16
•CIS-1.5: 1.16
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•CIS-2.0: 1.16
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4, ac_6
•CIS-5.0: 1.15
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•CIS-3.0: 1.16
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.15
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.3.1
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_customer_unattached_policy_no_administrative_privileges |
Unattached customer managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/sai |
|
Custom policy sai is unattached and does not allow '*:*' administrative privileges. |
An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement. |
Remove or redesign these policies to enforce least privilege:
- Avoid * in actions/resources; scope precisely and use conditions
- Apply permissions boundaries and SCPs as guardrails
- Require peer review and policy validation before attachment
- Use analysis tools to refine permissions and delete unused policies |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: po_1, ac_4, ac_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•ISO27001-2022: A.8.2
|
| PASS |
medium |
iam |
us-east-2 |
iam_customer_unattached_policy_no_administrative_privileges |
Unattached customer managed IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:policy/EnforceMFAdilbag |
|
Custom policy EnforceMFAdilbag is unattached and does not allow '*:*' administrative privileges. |
An unattached policy with *:* can be attached accidentally or maliciously, granting account-wide control. Attackers could read sensitive data (confidentiality), alter or delete resources (integrity), and disrupt services (availability), enabling rapid privilege escalation and lateral movement. |
Remove or redesign these policies to enforce least privilege:
- Avoid * in actions/resources; scope precisely and use conditions
- Apply permissions boundaries and SCPs as guardrails
- Require peer review and policy validation before attachment
- Use analysis tools to refine permissions and delete unused policies |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02, SEC03-BP04
•NIST-CSF-2.0: po_1, ac_4, ac_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02, CCC.IAM.CN04.AR01
•ISO27001-2022: A.8.2
|
| FAIL |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/Admin |
|
IAM Group Admin has AdministratorAccess policy attached. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/devops |
|
IAM Group devops does not have AdministratorAccess policy. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/ecr-push-group |
|
IAM Group ecr-push-group does not have AdministratorAccess policy. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/otherpermission |
|
IAM Group otherpermission does not have AdministratorAccess policy. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/secertmanageraccess |
|
IAM Group secertmanageraccess does not have AdministratorAccess policy. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_group_administrator_access_policy |
IAM group does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:group/storage-access |
|
IAM Group storage-access does not have AdministratorAccess policy. |
Group-wide AdministratorAccess gives all members unrestricted control. A stolen or misused account can:
- Read/exfiltrate sensitive data (C)
- Modify or delete resources and configs (I/A)
- Disable logging and weaken defenses, enabling persistence and lateral movement |
Remove AdministratorAccess from groups. Apply least privilege with task-scoped, customer-managed policies and separation of duties. Use roles for admin tasks with MFA, time-bound elevation, and auditing. Regularly review group membership and permissions; prefer defense-in-depth guardrails. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:group/Admin |
|
Inline policy sai-admin attached to group Admin does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:group/devops |
|
Inline policy kms attached to group devops does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:group/devops |
|
Inline policy sai-devops attached to group devops does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy custommfa attached to group otherpermission does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy loggingaccess attached to group otherpermission does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_allows_privilege_escalation |
IAM inline policy does not allow privilege escalation |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow privilege escalation. |
Excessive inline policy permissions let identities escalate to admin, compromising CIA:
- Confidentiality: read secrets and data
- Integrity: alter policies, code, and configs
- Availability: delete or stop resources, disable logging
Attackers can persist by creating keys/users or assuming powerful roles. |
Apply least privilege and remove escalation paths:
- Avoid wildcards and sensitive actions like sts:AssumeRole, iam:PassRole, or policy modification without tight scope
- Restrict by resource and Condition
- Prefer managed, versioned policies; use permissions boundaries/SCPs
- Require reviews and MFA for admins |
•SOC2: cc_3_3
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: SP-01.04B, AM-09.04AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•ProwlerThreatScore-1.0: 1.3.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:group/Admin |
|
Inline policy sai-admin attached to group Admin does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy kms attached to group devops does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy sai-devops attached to group devops does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy custommfa attached to group otherpermission does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy loggingaccess attached to group otherpermission does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_inline_policy_no_administrative_privileges |
Inline IAM policy does not allow '*:*' administrative privileges |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow '*:*' administrative privileges. |
Granting *:* to an identity collapses least privilege, enabling total control over AWS. A compromised principal can exfiltrate data (confidentiality), alter configs or disable logging (integrity), and delete resources or keys (availability), enabling rapid lateral movement and persistent takeover. |
Remove Action:"*" with Resource:"*" from inline policies. Apply least privilege with granular actions scoped to specific resources and conditions. Prefer versioned customer-managed policies over broad inline ones, enforce separation of duties, and use permissions boundaries or guardrails to prevent accidental admin grants. |
•CISA: your-systems-3, your-surroundings-3
•SOC2: cc_1_3, cc_6_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1040, T1580, T1538, T1619, T1201
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.1
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.01AC, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_i, 164_308_a_4_ii_b, 164_308_a_4_ii_c, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: rr_1, rr_2, po_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6, 3_13_3
•ASD-Essential-Eight-Nov 2023: E8-4.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_5, ac_6, sc_2
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_5_b, ac_6, ac_6_2, ac_6_3, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.acc.4.aws.iam.9, op.exp.8.r4.aws.ct.8
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.RDMS.CN04.AR01, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02, CCC.IAM.CN04.AR01
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-16, d3-pc-am-b-2, d3-pc-am-b-3, d3-pc-am-b-6, d3-pc-im-b-7
•ISO27001-2022: A.5.18, A.8.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•NIS2: 6.7.2.e, 11.3.2.c, 11.4.2.b
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:group/Admin |
|
Inline policy sai-admin attached to group Admin does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy kms attached to group devops does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy sai-devops attached to group devops does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy custommfa attached to group otherpermission does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy loggingaccess attached to group otherpermission does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
high |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_cloudtrail |
Inline IAM policy does not allow 'cloudtrail:*' privileges |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'cloudtrail:*' privileges. |
Full CloudTrail access allows stopping trails, modifying configurations, or deleting audit data, compromising log integrity and availability. It also exposes event data, impacting confidentiality. Adversaries could hide activity, evade detection, and obstruct investigations. |
Enforce least privilege and separation of duties: avoid cloudtrail:*; grant only specific actions needed (prefer read-only where possible). Add guardrails or boundaries to block destructive actions. Use managed, centrally governed policies and periodically right-size permissions based on usage. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B, COM-04.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: po_1, ac_7
•ASD-Essential-Eight-Nov 2023: E8-4.4
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:group/Admin |
|
Inline policy sai-admin attached to group Admin does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy kms attached to group devops does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:group/devops |
|
Inline policy sai-devops attached to group devops does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy custommfa attached to group otherpermission does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy loggingaccess attached to group otherpermission does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_full_access_to_kms |
Inline IAM policy does not allow kms:* privileges |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'kms:*' privileges. |
Granting kms:* enables decryption of protected data, modification of key policies and grants, and disabling or deleting keys.
Impacts:
- Confidentiality via unauthorized decryption
- Integrity through key/grant tampering
- Availability if keys are disabled or deleted, breaking encrypted workloads |
Replace kms:* with least-privilege, action-scoped permissions limited to required operations and specific key ARNs. Enforce separation of duties for key admins vs users. Prefer managed policies over inline and apply guardrails (permissions boundaries/SCPs). Add conditions to constrain service, region, and encryption context. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.8, 3.5.1.3.16, 3.6.1.2.8, 3.6.1.3.8, 3.6.1.4.8, 3.6.1.8, 3.7.1.9, 3.7.2.8, 3.7.4.9, 3.7.6.8, 3.7.7.8, 4.2.1.1.21, 7.2.1.10, 7.2.2.10, 7.2.3.6, 7.2.5.6, 7.3.1.6, 7.3.2.6, 7.3.3.6, 8.2.7.6, 8.2.8.8, 8.3.4.6
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:group/Admin |
|
Inline policy sai-admin attached to group Admin does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:group/devops |
|
Inline policy kms attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:group/devops |
|
Inline policy sai-devops attached to group devops does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy custommfa attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:group/otherpermission |
|
Inline policy loggingaccess attached to group otherpermission does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
Inline policy scrivas-db-backup-s3-policy attached to role EC2-CloudWatchAgent-Role does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
Inline policy FlowLogsToCloudWatchPolicy attached to role FlowLogsToCloudWatch does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
Inline policy scrivas-staging-cluster attached to role scrivas-staging-cluster-20251007184855668200000001 does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_inline_policy_no_wildcard_marketplace_subscribe |
Inline IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
Inline policy SecureframeAdditionalPermissions attached to role SecureframeRole-f983f1e89008 does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources via inline policies allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Prefer managed policies over inline and apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_no_custom_policy_permissive_role_assumption |
Custom IAM policy does not allow STS role assumption on wildcard resources |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow permissive STS Role assumption. |
Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane. |
Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties |
•CISA: your-systems-3, your-surroundings-3
•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_no_custom_policy_permissive_role_assumption |
Custom IAM policy does not allow STS role assumption on wildcard resources |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow permissive STS Role assumption. |
Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane. |
Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties |
•CISA: your-systems-3, your-surroundings-3
•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_no_custom_policy_permissive_role_assumption |
Custom IAM policy does not allow STS role assumption on wildcard resources |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow permissive STS Role assumption. |
Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane. |
Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties |
•CISA: your-systems-3, your-surroundings-3
•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_no_custom_policy_permissive_role_assumption |
Custom IAM policy does not allow STS role assumption on wildcard resources |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom Policy scrivas-s3-storage-policy does not allow permissive STS Role assumption. |
Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane. |
Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties |
•CISA: your-systems-3, your-surroundings-3
•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_no_custom_policy_permissive_role_assumption |
Custom IAM policy does not allow STS role assumption on wildcard resources |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom Policy gitlab-ci-ecr-push does not allow permissive STS Role assumption. |
Broad AssumeRole rights let principals obtain temporary credentials for many roles, enabling privilege escalation, lateral movement, and cross-account access where trusts allow. This jeopardizes confidentiality and integrity of data and the control plane. |
Apply least privilege to sts:AssumeRole:
- Scope Resource to exact role ARNs
- Require MFA and, for third parties, ExternalId
- Enforce permissions boundaries and SCPs to block wildcards
- Regularly remove unused role-assumption rights and separate duties |
•CISA: your-systems-3, your-surroundings-3
•MITRE-ATTACK: T1078, T1098, T1606, T1040, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-06.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_no_root_access_key |
Root account has no active access keys |
arn:aws:iam::716468089330:root |
|
Root account does not have access keys. |
Root access keys provide unrestricted API access. If exposed or misused, attackers can:
- Turn off logging and alter policies (integrity)
- Read or export data (confidentiality)
- Delete resources and lock out admins (availability)
Long-lived keys can persist and may bypass console-only MFA. |
Delete and prohibit root access keys. Use IAM roles and temporary credentials with least privilege for all automation. Enable MFA on root, limit root to break-glass use, and continuously monitor for any new root keys. Where applicable, apply organization-wide controls to enforce this. |
•CISA: your-systems-3, your-surroundings-3
•CIS-7.0: 2.4
•CIS-1.4: 1.4
•CIS-1.5: 1.4
•MITRE-ATTACK: T1078, T1550
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.4
•ISO27001-2013: A.9.2.N, A.9.4.N
•KISA-ISMS-P-2023: 2.5.5, 2.7.2, 2.10.2
•C5-2025: IAM-03.01B, IAM-03.03B, IAM-06.02B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_312_a_2_i
•CIS-2.0: 1.4
•KISA-ISMS-P-2023-korean: 2.5.5, 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.3
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_1_6, 3_1_7, 3_4_6
•PCI-4.0: 7.2.1.17, 7.2.2.17, 7.2.3.8, 8.2.1.4, 8.2.2.6, 8.2.4.4, 8.2.5.4, 8.3.11.4
•NIST-800-53-Revision-4: ac_2, ac_3, ac_6_10, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_2, ac_6_10, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2, ia_4_b, ia_4_4, ia_4_8, ia_5_8, mp_2, sc_23_3, sc_25
•AWS-Account-Security-Onboarding: Block root user
•CIS-3.0: 1.4
•ENS-RD2022: op.acc.4.aws.iam.7
•CIS-6.0: 2.3
•AWS-Foundational-Technical-Review: ARC-004
•NIST-CSF-1.1: ac_1, ac_4, pt_3
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.Core.CN05.AR06, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.6
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-am-b-3, d3-pc-am-b-8
•ProwlerThreatScore-1.0: 1.1.13
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-04
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, ac-6-10, ac-6, ia-2
•FedRAMP-Low-Revision-4: ac-2, ac-3, ia-2
•CIS-4.0.1: 1.4
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_expires_passwords_within_90_days_or_less |
IAM account password policy enforces password expiration within 90 days or less |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
Password expiration is not set. |
Without rotation, stale passwords persist, enabling credential stuffing, brute force, and password reuse attacks. A compromised IAM user can retain console access, enabling data exfiltration, privilege escalation, and loss of confidentiality and integrity. |
Enforce password rotation at <= 90 days and prevent reuse. Pair with MFA, strong length/complexity, and prefer federation/SSO to reduce static passwords. Apply least privilege, monitor sign-ins, and remove inactive console passwords to limit exposure. |
•MITRE-ATTACK: T1078, T1110
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.A, A.9.3.A, A.9.4.A
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-03.02B, IAM-08.03B, IAM-08.05B, PSS-07.01B
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP06
•NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 8.3.6.1, 8.6.3.2
•ENS-RD2022: op.acc.6.aws.iam.3
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5
•ProwlerThreatScore-1.0: 1.1.12
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•NIS2: 1.1.1.d, 1.1.2, 9.2.c.v, 11.6.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
low |
iam |
us-east-2 |
iam_password_policy_lowercase |
IAM password policy requires at least one lowercase letter |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy does not require at least one lowercase letter. |
Without a lowercase requirement, passwords have reduced entropy, making brute force and password spraying more effective. Compromised IAM users can enable unauthorized access and changes, risking confidentiality, integrity, and availability of AWS resources. |
Adopt a strong password policy that:
- Enables Require at least one lowercase letter plus uppercase, number, and symbol
- Sets sufficient length and blocks reuse
- Requires MFA for all users
- Applies least privilege to limit blast radius |
•CISA: your-systems-3, your-surroundings-4
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.F, A.9.3.F, A.9.4.F
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-08.03B, PSS-07.01B
•HIPAA: 164_308_a_5_ii_d
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-800-171-Revision-2: 3_5_7
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7
•ProwlerThreatScore-1.0: 1.1.8
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•NIS2: 9.2.c.v, 11.6.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_minimum_length_14 |
IAM password policy requires passwords to be at least 14 characters long |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy does not require minimum length of 14 characters. |
Low minimum length reduces entropy, easing brute force and credential stuffing. Compromised IAM users enable console access, unauthorized changes, and lateral movement, leading to data exposure (confidentiality) and tampering (integrity). |
Set the minimum password length to >= 14 (prefer 16+).
- Require mixed character types and prevent reuse
- Enforce MFA for all console users
- Prefer SSO over local IAM users
- Apply least privilege and monitor authentication events |
•CISA: your-systems-3, your-surroundings-4
•CIS-7.0: 2.8
•CIS-1.4: 1.8
•CIS-1.5: 1.8
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.C, A.9.3.C, A.9.4.C
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-08.03B, PSS-07.01B
•HIPAA: 164_308_a_5_ii_d
•CIS-2.0: 1.8
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.7
•NIST-800-171-Revision-2: 3_5_7
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_d_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, cm_12_b, ia_4_d, ia_5, ia_5_b, ia_5_c, ia_5_d, ia_5_f, ia_5_h, ia_5_1_f, ia_5_1_g, ia_5_1_h, ia_5_1_h, ia_5_18_a, ia_5_18_b, ia_8_2_b, ma_4_c, sc_23_3
•CIS-3.0: 1.8
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•CIS-6.0: 2.7
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5, 10.3
•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7
•ProwlerThreatScore-1.0: 1.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-5-c, ia-2, ia-5-1-a-d-e, ia-5-4
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.8
•NIS2: 9.2.c.v
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_number |
IAM password policy requires at least one number |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy does not require at least one number. |
Passwords without numbers have lower entropy, making brute-force and credential-stuffing more effective. A compromised IAM user can gain console access, enabling data exposure (confidentiality), configuration changes (integrity), and resource abuse or deletion (availability). |
Enforce the password policy option to require at least one number. Combine with strong length, mixed case, and symbols, and prevent reuse. Enable MFA for all users and prefer federated access to limit static credentials, supporting defense in depth against guessing attacks. |
•CISA: your-systems-3, your-surroundings-4
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.D, A.9.3.D, A.9.4.D
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B
•HIPAA: 164_308_a_5_ii_d
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-800-171-Revision-2: 3_5_7
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5, 10.3
•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7
•ProwlerThreatScore-1.0: 1.1.6
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•NIS2: 9.2.c.v
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_reuse_24 |
IAM password policy prevents reuse of the last 24 passwords |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy reuse prevention is less than 24 or not set. |
If fewer than 24 passwords are remembered, users can cycle back to recent secrets, undermining rotation. Attackers with previously exposed passwords can regain console access after a change, reducing confidentiality and integrity and increasing success of credential-stuffing with known credentials. |
Set the password policy to remember 24 previous passwords to block reuse. Combine with MFA, strong length and complexity, and avoid rotation practices that encourage predictable patterns. Apply least privilege and monitor authentication events as part of defense in depth. |
•CIS-7.0: 2.9
•CIS-1.4: 1.9
•CIS-1.5: 1.9
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.B, A.9.3.B, A.9.4.B
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-01.03B, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-08.03B, IAM-08.05B, IAM-08.07B, PSS-07.01B
•HIPAA: 164_308_a_4_ii_c, 164_308_a_5_ii_d, 164_312_d
•CIS-2.0: 1.9
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.8
•NIST-800-171-Revision-2: 3_5_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2, ia_2, ia_5_1, ia_5_4
•CIS-3.0: 1.9
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•CIS-6.0: 2.8
•AWS-Foundational-Technical-Review: IAM-003
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5
•RBI-Cyber-Security-Framework: annex_i_7_2
•PCI-3.2.1: 8.1, 8.1.4, 8.2, 8.2.3, 8.2.3.a, 8.2.3.b, 8.2.4, 8.2.4.a, 8.2.4.b, 8.2.5, 8.2.5.a, 8.2.5.b
•ProwlerThreatScore-1.0: 1.1.5
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•CIS-4.0.1: 1.9
•NIS2: 9.2.c.v
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_symbol |
IAM password policy requires at least one symbol |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy does not require at least one symbol. |
Missing a symbol requirement lowers password entropy, increasing success of brute force and credential stuffing against console logins. A compromised IAM user can gain unauthorized access and modify resources, threatening confidentiality and integrity across the account. |
Enforce the Require at least one non-alphanumeric character rule in the IAM password policy, alongside strong minimum length, mixed character sets, and password reuse prevention. Apply MFA for all human users and uphold least privilege to limit impact. Consider periodic rotation based on risk. |
•CISA: your-systems-3, your-surroundings-4
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.E, A.9.3.E, A.9.4.E
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-08.03B, PSS-07.01B
•HIPAA: 164_308_a_5_ii_d
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-800-171-Revision-2: 3_5_7
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5, 10.3
•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7
•ProwlerThreatScore-1.0: 1.1.7
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•NIS2: 9.2.c.v
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_password_policy_uppercase |
IAM password policy requires at least one uppercase letter |
arn:aws:iam:us-east-2:716468089330:password-policy |
|
IAM password policy does not require at least one uppercase letter. |
Without an uppercase requirement, passwords have lower entropy, enabling brute force, credential stuffing, and offline cracking. Compromised IAM users can access the console, threatening confidentiality (data exposure), integrity (unauthorized changes), and availability (resource deletion). |
Enable the uppercase rule within a strong password policy that also requires length, lowercase, numbers, and symbols. Pair with MFA and least privilege to reduce blast radius. Regularly review policy effectiveness and prefer federated SSO to minimize long-lived IAM passwords. |
•CISA: your-systems-3, your-surroundings-4
•MITRE-ATTACK: T1078, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.7, IAM.10
•ISO27001-2013: A.9.2.G, A.9.3.G, A.9.4.G
•KISA-ISMS-P-2023: 2.5.4, 2.10.2
•C5-2025: IAM-08.03B, IAM-08.05B, PSS-07.01B
•HIPAA: 164_308_a_5_ii_d
•KISA-ISMS-P-2023-korean: 2.5.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-800-171-Revision-2: 3_5_7
•ENS-RD2022: op.acc.6.r1.aws.iam.1
•AWS-Foundational-Technical-Review: IAM-003
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN05.AR01
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-6, d3-pc-am-b-7
•ProwlerThreatScore-1.0: 1.1.9
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-06
•NIS2: 9.2.c.v
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_policy_allows_privilege_escalation |
Customer managed IAM policy does not allow actions that can lead to privilege escalation |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom Policy arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow privilege escalation. |
Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls |
Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 11.2.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_policy_allows_privilege_escalation |
Customer managed IAM policy does not allow actions that can lead to privilege escalation |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom Policy arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow privilege escalation. |
Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls |
Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 11.2.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_policy_allows_privilege_escalation |
Customer managed IAM policy does not allow actions that can lead to privilege escalation |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom Policy arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow privilege escalation. |
Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls |
Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 11.2.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_policy_allows_privilege_escalation |
Customer managed IAM policy does not allow actions that can lead to privilege escalation |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom Policy arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy does not allow privilege escalation. |
Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls |
Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 11.2.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_policy_allows_privilege_escalation |
Customer managed IAM policy does not allow actions that can lead to privilege escalation |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom Policy arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push does not allow privilege escalation. |
Privilege-escalation permissions let principals assume higher-privilege roles or attach admin policies, impacting:
- Confidentiality via unauthorized data access/exfiltration
- Integrity by modifying policies, configs, or logs
- Availability through resource deletion or disabling controls |
Apply least privilege to customer policies:
- Avoid wildcards in Action and Resource
- Remove or tightly scope iam:PassRole, policy attach/update, and trust-policy changes
- Use conditions like iam:PassedToService and tags to constrain use
- Enforce permissions boundaries and SCPs
- Separate duties with change review |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1606, T1040, T1580, T1619, T1201
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-06.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, ra_1, ac_1, ac_4, ac_6, ac_7, ip_1
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.2, op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR02, CCC.IAM.CN02.AR01, CCC.IAM.CN02.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 11.2.2.a
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_policy_attached_only_to_group_or_roles |
IAM user has no inline or attached policies |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor has no inline or attached policies. |
Directly attached user policies hinder centralized control and cause privilege creep. If a user is compromised, excessive rights enable data exposure, resource tampering, and lateral movement, harming confidentiality and integrity. Revocation is error-prone, weakening separation of duties and auditability. |
Assign permissions to groups (humans) and roles (workloads); avoid user-attached policies. Enforce least privilege, prefer federation and temporary credentials, and use tags or permissions boundaries to constrain scope. Review regularly to remove direct user policies and right-size access. |
•CIS-7.0: 2.13
•SOC2: cc_1_3
•CIS-1.4: 1.15
•CIS-1.5: 1.15
•ISO27001-2013: A.9.2.I, A.9.4.I
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, PSS-09.01AC
•CIS-2.0: 1.15
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP06
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_1, ac_4, ac_6, ac_7, ip_1
•CIS-5.0: 1.14
•NIST-800-171-Revision-2: 3_4_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 7.2.1.12, 7.2.1.13, 7.2.2.12, 7.2.2.13, 7.2.5.8, 7.2.5.9, 7.3.1.8, 7.3.1.9, 7.3.2.8, 7.3.2.9, 7.3.3.8, 7.3.3.9, 8.2.1.3, 8.2.2.5, 8.2.4.3, 8.2.5.3, 8.2.7.8, 8.2.7.9, 8.2.8.10, 8.2.8.11, 8.3.11.3, 8.3.4.8, 8.3.4.9
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_6, ac_2_i_2, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_6_3, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.15
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•CIS-6.0: 2.14
•AWS-Foundational-Technical-Review: IAM-006, IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.1
•RBI-Cyber-Security-Framework: annex_i_7_1
•FFIEC: d3-pc-am-b-1, d3-pc-im-b-7
•ProwlerThreatScore-1.0: 1.2.1, 1.2.2
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-3, ac-5-c, sc-2
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.15
•NIS2: 1.2.1, 2.1.2.f, 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_cloudshell_admin_not_attached |
No IAM users, groups, or roles have the AWSCloudShellFullAccess policy attached |
arn:aws:iam::aws:policy/AWSCloudShellFullAccess |
|
AWS CloudShellFullAccess policy is not attached to any IAM entity. |
Granting cloudshell:* enables an interactive shell with Internet egress and file upload/download, degrading confidentiality and integrity.
Compromised principals can exfiltrate data, stage tooling with sudo, persist artifacts in CloudShell, and operate from AWS IP space to bypass endpoint controls. |
Detach AWSCloudShellFullAccess from identities.
Apply least privilege: permit CloudShell only when necessary via narrowly scoped permissions, restricted roles, short-lived sessions, and approvals. Prefer controlled alternatives (local CLI, bastion, or Session Manager). Enforce separation of duties and monitor usage. |
•CIS-7.0: 2.20
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-02.01B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-06.01B
•CIS-2.0: 1.22
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•CIS-5.0: 1.21
•PCI-4.0: 7.2.1.14, 7.2.1.15, 7.2.1.16, 7.2.2.14, 7.2.2.15, 7.2.2.16, 7.2.3.7, 7.2.5.10, 7.2.5.11, 7.2.5.12, 7.3.1.10, 7.3.1.11, 7.3.1.12, 7.3.2.10, 7.3.2.11, 7.3.2.12, 7.3.3.10, 7.3.3.11, 7.3.3.12, 8.2.7.10, 8.2.7.11, 8.2.7.12, 8.2.8.12, 8.2.8.13, 8.2.8.14, 8.3.4.10, 8.3.4.11, 8.3.4.12
•CIS-6.0: 2.21
•ProwlerThreatScore-1.0: 1.3.2
•CIS-4.0.1: 1.22
•NIS2: 1.2.1
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_cloudtrail |
Customer managed IAM policy does not allow cloudtrail:* privileges |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'cloudtrail:*' privileges. |
Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection. |
Apply least privilege: avoid cloudtrail:* and allow only required actions.
Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes. |
•SOC2: cc_3_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_cloudtrail |
Customer managed IAM policy does not allow cloudtrail:* privileges |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'cloudtrail:*' privileges. |
Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection. |
Apply least privilege: avoid cloudtrail:* and allow only required actions.
Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes. |
•SOC2: cc_3_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_cloudtrail |
Customer managed IAM policy does not allow cloudtrail:* privileges |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'cloudtrail:*' privileges. |
Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection. |
Apply least privilege: avoid cloudtrail:* and allow only required actions.
Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes. |
•SOC2: cc_3_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_cloudtrail |
Customer managed IAM policy does not allow cloudtrail:* privileges |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom Policy scrivas-s3-storage-policy does not allow 'cloudtrail:*' privileges. |
Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection. |
Apply least privilege: avoid cloudtrail:* and allow only required actions.
Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes. |
•SOC2: cc_3_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_cloudtrail |
Customer managed IAM policy does not allow cloudtrail:* privileges |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom Policy gitlab-ci-ecr-push does not allow 'cloudtrail:*' privileges. |
Unrestricted CloudTrail control lets principals stop or alter logging, delete or modify trails, and query events.
This enables log evasion, audit tampering, and reconnaissance, undermining the integrity, availability, and confidentiality of audit evidence and detection. |
Apply least privilege: avoid cloudtrail:* and allow only required actions.
Enforce separation of duties for trail management. Use permissions boundaries or SCPs to block broad CloudTrail access, and validate policies regularly to refine scopes. |
•SOC2: cc_3_3
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: IAM-10.01B, SIM-03.07B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•ENS-RD2022: op.exp.8.r4.aws.ct.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_kms |
Custom IAM policy does not allow 'kms:*' privileges |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'kms:*' privileges. |
Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation. |
Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5
•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_kms |
Custom IAM policy does not allow 'kms:*' privileges |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'kms:*' privileges. |
Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation. |
Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5
•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_kms |
Custom IAM policy does not allow 'kms:*' privileges |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'kms:*' privileges. |
Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation. |
Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5
•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_kms |
Custom IAM policy does not allow 'kms:*' privileges |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom Policy scrivas-s3-storage-policy does not allow 'kms:*' privileges. |
Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation. |
Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5
•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_full_access_to_kms |
Custom IAM policy does not allow 'kms:*' privileges |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom Policy gitlab-ci-ecr-push does not allow 'kms:*' privileges. |
Allowing kms:* lets principals decrypt data, change key policies, and disable or delete keys. Impact: Confidentiality-unauthorized decryption; Integrity-manipulation of cryptographic controls; Availability-data unreadable if keys are disabled/deleted. It can also enable privilege escalation. |
Adopt least privilege and separation of duties:
- Replace kms:* with only needed actions scoped to specific key ARNs
- Apply policy conditions (e.g., kms:ViaService) and guardrails (permissions boundaries/SCPs)
- Monitor KMS usage and refine access based on activity |
•MITRE-ATTACK: T1078, T1648, T1098, T1578, T1550, T1580
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-08.02B, IAM-10.01B, CRY-05.02B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, po_1, ac_1, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.4
•PCI-4.0: 3.5.1.1.7, 3.5.1.3.15, 3.6.1.2.7, 3.6.1.3.7, 3.6.1.4.7, 3.6.1.7, 3.7.1.8, 3.7.2.7, 3.7.4.8, 3.7.6.7, 3.7.7.7, 4.2.1.1.20, 7.2.1.9, 7.2.2.9, 7.2.3.5, 7.2.5.5, 7.3.1.5, 7.3.2.5, 7.3.3.5, 8.2.7.5, 8.2.8.7, 8.3.4.5
•ENS-RD2022: op.exp.10.aws.cmk.1, op.exp.10.aws.cmk.2
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Core.CN05.AR04, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04, CCC.KeyMgmt.CN02.AR01, CCC.IAM.CN04.AR01
•NIS2: 11.2.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_wildcard_marketplace_subscribe |
Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:policy/service-role/Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 |
|
Custom Policy Cloudtrail-CW-access-policy-us-east-2-c81ee68c-bf1c-47c5-8b2e-ef7555445771 does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_wildcard_marketplace_subscribe |
Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:policy/scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 |
|
Custom Policy scrivas-staging-cluster-ClusterEncryption20251007184919089700000012 does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_wildcard_marketplace_subscribe |
Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:policy/service-role/VPCFlowLogs-CloudWatch-Policy-1781174377138 |
|
Custom Policy VPCFlowLogs-CloudWatch-Policy-1781174377138 does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_wildcard_marketplace_subscribe |
Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:policy/scrivas-s3-storage-policy |
|
Custom Policy scrivas-s3-storage-policy does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_policy_no_wildcard_marketplace_subscribe |
Custom IAM policy does not allow 'aws-marketplace:Subscribe' on all resources |
arn:aws:iam::716468089330:policy/gitlab-ci-ecr-push |
|
Custom Policy gitlab-ci-ecr-push does not allow 'aws-marketplace:Subscribe' on all resources. |
Granting aws-marketplace:Subscribe on all resources allows subscribing to any Marketplace product, including expensive Bedrock foundation models, leading to uncontrolled costs, shadow AI usage, and compliance violations from unapproved deployments. |
Replace Resource: "*" with specific, approved AWS Marketplace product ARNs. Apply the principle of least privilege to aws-marketplace:Subscribe permissions to prevent unauthorized subscriptions to costly Bedrock models and other Marketplace products. |
•CISA: your-surroundings-3
•SOC2: cc_6_3
•KISA-ISMS-P-2023: 2.5.5
•C5-2025: IAM-01.01B, IAM-01.04B
•HIPAA: 164_308_a_4_ii_b
•KISA-ISMS-P-2023-korean: 2.5.5
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP02
•NIST-CSF-2.0: ac_4
•NIST-800-171-Revision-2: 3_1_5
•NIST-800-53-Revision-4: ac_6
•NIST-800-53-Revision-5: ac_6
•NIST-CSF-1.1: ac_4
•FFIEC: d3-pc-am-b-1
•ISO27001-2022: A.5.18, A.8.2
•FedRamp-Moderate-Revision-4: ac-6
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_role_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM roles retain only actively used permissions |
arn:aws:iam::716468089330:role/aws-service-role/config.amazonaws.com/AWSServiceRoleForConfig |
|
IAM Role AWSServiceRoleForConfig accessed Bedrock 0 days ago (threshold: 60 days). |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_role_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM roles retain only actively used permissions |
arn:aws:iam::716468089330:role/aws-service-role/resource-explorer-2.amazonaws.com/AWSServiceRoleForResourceExplorer |
|
IAM Role AWSServiceRoleForResourceExplorer accessed Bedrock 1 days ago (threshold: 60 days). |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_role_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM roles retain only actively used permissions |
arn:aws:iam::716468089330:role/aws-service-role/support.amazonaws.com/AWSServiceRoleForSupport |
|
IAM Role AWSServiceRoleForSupport has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_role_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM roles retain only actively used permissions |
arn:aws:iam::716468089330:role/IntruderReadOnlyRole |
|
IAM Role IntruderReadOnlyRole has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_role_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM roles retain only actively used permissions |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
IAM Role SecureframeRole-f983f1e89008 has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who assumes a role with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
high |
iam |
us-east-2 |
iam_role_administratoraccess_policy |
IAM role does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole |
|
IAM Role AmazonEKS_EBS_CSI_DriverRole does not have AdministratorAccess policy. |
Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover. |
Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 1.2.1, 11.3.1
|
| PASS |
high |
iam |
us-east-2 |
iam_role_administratoraccess_policy |
IAM role does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:role/IntruderReadOnlyRole |
|
IAM Role IntruderReadOnlyRole does not have AdministratorAccess policy. |
Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover. |
Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 1.2.1, 11.3.1
|
| PASS |
high |
iam |
us-east-2 |
iam_role_administratoraccess_policy |
IAM role does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
IAM Role SecureframeRole-f983f1e89008 does not have AdministratorAccess policy. |
Granting full administrative permissions on a role undermines confidentiality, integrity, and availability. If the role is assumed or its credentials are stolen, an attacker can read sensitive data, change policies, disable auditing, delete resources and backups, and create new privileged identities, enabling swift account takeover. |
Apply least privilege: avoid attaching AdministratorAccess to roles. Grant only task-scoped permissions with custom policies and enforce separation of duties.
Use permissions boundaries, SCPs, and policy conditions to constrain power. Require MFA for break-glass admins, time-bound elevation with approval, and refine access using Access Analyzer. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-02.01B, OIS-04.03B, SP-01.04B, HR-01.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-06.01B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, ac_1, ac_4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02, CCC.Vector.CN02.AR01
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
•NIS2: 1.2.1, 11.3.1
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_account_readonlyaccess_policy |
IAM role does not grant ReadOnlyAccess to external AWS accounts |
arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole |
|
IAM Role AmazonEKS_EBS_CSI_DriverRole does not have ReadOnlyAccess policy. |
Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths. |
Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_2, am_6, ac_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_account_readonlyaccess_policy |
IAM role does not grant ReadOnlyAccess to external AWS accounts |
arn:aws:iam::716468089330:role/IntruderReadOnlyRole |
|
IAM Role IntruderReadOnlyRole does not have ReadOnlyAccess policy. |
Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths. |
Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_2, am_6, ac_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_account_readonlyaccess_policy |
IAM role does not grant ReadOnlyAccess to external AWS accounts |
arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008 |
|
IAM Role SecureframeRole-f983f1e89008 does not have ReadOnlyAccess policy. |
Granting cross-account read access can expose sensitive data and metadata, impacting confidentiality. External principals can read S3/DynamoDB contents and enumerate resources, policies, and logs, enabling targeted recon and easier privilege escalation paths. |
Avoid attaching ReadOnlyAccess to roles trusted by other accounts. Apply least privilege with custom, tightly scoped policies. Restrict trust to explicit principals, avoid *, and use conditions like aws:PrincipalOrgID and sts:ExternalId for defense in depth. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, IAM-01.01B, IAM-01.04B, IAM-06.02B, IAM-10.01B, PSS-09.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_2, am_6, ac_6
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/AmazonEKSAutoClusterRole |
|
IAM Service Role AmazonEKSAutoClusterRole prevents against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/AmazonEKSAutoNodeRole |
|
IAM Service Role AmazonEKSAutoNodeRole does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonEBSCSIDriverRole |
|
IAM Service Role AmazonEKSPodIdentityAmazonEBSCSIDriverRole does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonVPCCNIRole |
|
IAM Service Role AmazonEKSPodIdentityAmazonVPCCNIRole does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/applications-eks-node-group-20251007184911320300000008 |
•Environment=scrivas-staging
•Architecture=x64
•ManagedBy=terraform
•Repository=devops-terraform
•Service=applications
•Purpose=workloads
|
IAM Service Role applications-eks-node-group-20251007184911320300000008 does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/service-role/AWSSystemsManagerDefaultEC2InstanceManagementRole |
|
IAM Service Role AWSSystemsManagerDefaultEC2InstanceManagementRole does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/service-role/CloudTrailRoleForCloudWatchLogs_MainTrail |
|
IAM Service Role CloudTrailRoleForCloudWatchLogs_MainTrail prevents against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role |
|
IAM Service Role EC2-CloudWatchAgent-Role does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/EC2-SSM-Access |
|
IAM Service Role EC2-SSM-Access does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/EC2SSMRole |
•scrivas=
|
IAM Service Role EC2SSMRole does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/FlowLogsToCloudWatch |
|
IAM Service Role FlowLogsToCloudWatch does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/gpu-eks-node-group-20251007184911320100000007 |
•Architecture=x64
•Service=gpu
•Environment=scrivas-staging
•ManagedBy=terraform
•Repository=devops-terraform
•Purpose=ml-workloads
|
IAM Service Role gpu-eks-node-group-20251007184911320100000007 does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/infrastructure-eks-node-group-20251007184911319500000006 |
•Environment=scrivas-staging
•Service=infrastructure
•ManagedBy=terraform
•Repository=devops-terraform
•Architecture=x64
•Purpose=infrastructure
|
IAM Service Role infrastructure-eks-node-group-20251007184911319500000006 does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/rds-monitoring-role |
|
IAM Service Role rds-monitoring-role does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001 |
|
IAM Service Role scrivas-staging-cluster-20251007184855668200000001 prevents against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/vpc-flow-logs-role |
|
IAM Service Role vpc-flow-logs-role does not prevent against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| PASS |
high |
iam |
us-east-2 |
iam_role_cross_service_confused_deputy_prevention |
IAM service role prevents cross-service confused deputy attack |
arn:aws:iam::716468089330:role/service-role/VPCFlowLogs-Cloudwatch-1781174191538 |
|
IAM Service Role VPCFlowLogs-Cloudwatch-1781174191538 prevents against a cross-service confused deputy attack. |
Unrestricted service-principal trust lets outsiders trigger a cross-service confused deputy, causing unintended sts:AssumeRole.
This can enable data exfiltration, unauthorized changes, and lateral movement, impacting confidentiality and integrity. |
Constrain service-role trust to expected callers using aws:SourceArn/aws:SourceAccount to bind service principals to specific resources or accounts. If unsupported, apply equivalent limits in resource-based policies or org-level controls. Apply least privilege and review trust relationships regularly. |
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.1, 2.5.6, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP04
•ASD-Essential-Eight-Nov 2023: E8-4.4
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•ENS-RD2022: op.exp.8.r4.aws.ct.8, op.exp.8.r4.aws.ct.1
•AWS-Foundational-Technical-Review: IAM-0012
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR06, CCC.IAM.CN03.AR01, CCC.IAM.CN03.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•NIS2: 3.1.2.c, 6.8.2.a
|
| FAIL |
high |
iam |
us-east-2 |
iam_root_credentials_management_enabled |
AWS Organization has centralized root credentials management enabled |
arn:aws:iam::716468089330:root |
|
Root credentials management is not enabled. |
Without central control, member accounts can retain or recover long-term root credentials, weakening confidentiality and integrity.
Threats include:
- Account takeover via root email recovery
- Persistent access through root keys
- Unfixable lockouts from misconfigured policies
- Bypass of separation of duties |
Enable centralized root access with root credentials management and assign a delegated administrator.
Apply least privilege and separation of duties by deleting long-term root credentials in members, limiting privileged tasks to short-lived sessions, enforcing MFA, and auditing root-related activity for defense in depth. |
•CIS-7.0: 2.1.1
•C5-2025: IAM-03.01B, IAM-08.02B
•NIST-CSF-2.0: rr_1, rr_2, po_4, ac_1
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN05.AR06
•AWS-AI-Security-Framework-1.0: AISF-IAM-04
|
| FAIL |
critical |
iam |
us-east-2 |
iam_root_hardware_mfa_enabled |
Root account has a hardware MFA device enabled |
arn:aws:iam::716468089330:mfa |
|
Root account has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA on the root user:
- No MFA: stolen password/keys enable full account takeover.
- Virtual MFA: device compromise or backup restoration weakens second-factor assurance.
An attacker could delete resources, change policies, and disable logging, harming confidentiality, integrity, and availability. |
Require a hardware MFA token for the root user and remove any virtual MFA. Apply least privilege: avoid using root, disable access keys, and eliminate long-term credentials. In organizations, centralize root management. Keep a controlled break-glass process with strict recovery checks and continuous monitoring. |
•CISA: your-systems-3, your-surroundings-2
•CIS-7.0: 2.6
•CIS-1.4: 1.6
•CIS-1.5: 1.6
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.6
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_d
•CIS-2.0: 1.6
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02
•CIS-5.0: 1.5
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•PCI-4.0: 8.4.1.3, 8.4.2.3, 8.4.3.3
•NIST-800-53-Revision-4: ia_2_1, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•AWS-Account-Security-Onboarding: Root user - distribution email + MFA
•CIS-3.0: 1.6
•ENS-RD2022: op.acc.6.r4.aws.iam.1
•CIS-6.0: 2.5
•AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.2
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.6
•NIS2: 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
critical |
iam |
us-east-2 |
iam_root_mfa_enabled |
Root account has MFA enabled |
arn:aws:iam::716468089330:root |
|
MFA is enabled for root account. |
Without MFA, compromise of the root password or access keys can lead to full account takeover. An attacker with root can disable protections, steal or delete data, change billing, and create persistent admins, undermining confidentiality, integrity, and availability. |
Enable MFA for the root user, preferably hardware-based or a dedicated, managed device. Remove root access keys and avoid using root for daily tasks. Apply least privilege with IAM Identity Center for admins, and use Organizations to centralize root access and eliminate long-lived root credentials. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.5
•CIS-1.4: 1.5
•CIS-1.5: 1.5
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•GDPR: article_25
•ISO27001-2013: A.9.2.K, A.9.4.K
•KISA-ISMS-P-2023: 2.5.3, 2.5.5, 2.10.2
•C5-2025: OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-05.02B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_d
•CIS-2.0: 1.5
•KISA-ISMS-P-2023-korean: 2.5.3, 2.5.5, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP02
•NIST-CSF-2.0: rr_1, po_4, ac_1, ac_6, ac_7, ip_1
•CIS-5.0: 1.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.4, 8.4.2.4, 8.4.3.4
•NIST-800-53-Revision-4: ac_2, ia_2_1, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•AWS-Account-Security-Onboarding: Root user - distribution email + MFA
•CIS-3.0: 1.5
•ENS-RD2022: op.acc.6.r2.aws.iam.1
•CIS-6.0: 2.4
•AWS-Foundational-Technical-Review: ARC-003, IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-3, d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.1
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.5
•NIS2: 11.3.2.a, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:root |
|
User <root_account> does not have access keys. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has not rotated access key 1 in over 90 days (322 days). |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has not rotated access key 2 in over 90 days (319 days). |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya does not have access keys. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat does not have access keys. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag does not have access keys. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have access keys older than 90 days. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has not rotated access key 1 in over 90 days (316 days). |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis does not have access keys older than 90 days. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user has not rotated access key 1 in over 90 days (161 days). |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has not rotated access key 1 in over 90 days (147 days). |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_rotate_access_key_90_days |
IAM user does not have active access keys older than 90 days |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor does not have access keys. |
Long-lived access keys widen the attack window. If a key is leaked in code, logs, or tooling, lack of rotation keeps it valid for abuse, enabling unauthorized API calls, data exfiltration, and tampering. This degrades confidentiality and integrity and can impact availability and cost through destructive or excessive operations. |
Apply least privilege and limit static credentials:
- Rotate active access keys at or before 90 days
- Prefer IAM roles with short-lived tokens
- Maintain only one active key during rotation; delete the old one
- Monitor last_used and remove dormant keys
- Automate alerts and periodic reviews of key age |
•CISA: your-systems-3
•CIS-7.0: 2.12
•CIS-1.4: 1.14
•CIS-1.5: 1.14
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.3
•ISO27001-2013: A.9.2.L, A.9.3.I, A.9.4.L
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B, CRY-09.02B
•HIPAA: 164_308_a_3_ii_c, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.14
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP02, SEC02-BP05
•NIST-CSF-2.0: ac_6
•CIS-5.0: 1.13
•PCI-4.0: 8.3.10.1.1, 8.3.5.1, 8.3.7.1, 8.3.9.1, 8.6.3.1
•NIST-800-53-Revision-4: ac_2_1, ac_2
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, cm_6_a, cm_9_b, sc_23_3
•CIS-3.0: 1.14
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3
•CIS-6.0: 2.13
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.IAM.CN06.AR01
•SecNumCloud-3.2: 9.4
•FFIEC: d3-pc-am-b-6
•ProwlerThreatScore-1.0: 1.1.11
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j
•FedRAMP-Low-Revision-4: ac-2
•CIS-4.0.1: 1.14
•NIS2: 1.1.1.d, 1.1.2, 2.1.4, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.xii, 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
low |
iam |
us-east-2 |
iam_securityaudit_role_created |
At least one IAM role has the SecurityAudit AWS managed policy attached |
arn:aws:iam::aws:policy/SecurityAudit |
|
SecurityAudit policy attached to role IntruderReadOnlyRole. |
Without a dedicated read-only audit role, security teams lack safe visibility into configs and logs, enabling undetected misconfigurations, slower incident triage, and reliance on over-privileged access. This erodes confidentiality and integrity by letting exposure persist unnoticed. |
Establish a dedicated audit role and attach the AWS managed SecurityAudit policy. Enforce least privilege and separation of duties: restrict who can assume it, require MFA, monitor usage, and avoid write permissions. Prefer federated access and regularly review and rotate access. |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-02.01B, OIS-02.02B, OIS-04.01B, HR-04.01B, IAM-01.01B, IAM-01.04B, IAM-05.02B, IAM-06.06B, DEV-15.01B, SIM-01.02B, SIM-01.03B, COM-02.02B, COM-03.02B, INQ-02.01B, PSS-09.01AC
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•ENS-RD2022: op.acc.3.r2.aws.iam.1
•ISO27001-2022: A.5.3
•NIS2: 1.2.4, 2.1.1, 2.1.2.a, 2.1.2.e, 2.1.2.f, 2.2.1, 2.3.1, 3.1.2.c, 3.1.3, 6.2.2.a, 7.2.d, 7.2.e, 7.2.f
|
| FAIL |
low |
iam |
us-east-2 |
iam_support_role_created |
At least one IAM role has the AWSSupportAccess managed policy attached |
arn:aws:iam::aws:policy/AWSSupportAccess |
|
AWS Support Access policy is not attached to any role. |
Without a dedicated support role:
- Case creation and escalation can be delayed, prolonging outages (availability)
- Teams may use admin/root, increasing blast radius (confidentiality/integrity)
- Audit trails of support actions are weaker, hindering investigations |
Create a dedicated IAM role for AWS Support with AWSSupportAccess and:
- Restrict who can assume it; require MFA and time-bound access
- Enforce least privilege and separation of duties
- Monitor usage via audit logs and review assignments regularly |
•CIS-7.0: 2.15
•CIS-1.4: 1.17
•CIS-1.5: 1.17
•GDPR: article_25
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1
•C5-2025: OIS-02.01B, OIS-02.02B, HR-04.01B, OPS-13.02B, OPS-13.03AC, OPS-17.02B, OPS-24.01B, OPS-24.02B, IAM-01.01B, IAM-01.04B, IAM-06.06B, DEV-15.01B, SSO-05.06B, SIM-01.02B, SIM-01.03B
•CIS-2.0: 1.17
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2, 2.11.1
•AWS-Well-Architected-Framework-Security-Pillar: SEC10-BP01
•CIS-5.0: 1.16
•AWS-Account-Security-Onboarding: Predefine IAM Roles
•CIS-3.0: 1.17
•ENS-RD2022: op.acc.3.r1.aws.iam.1
•CIS-6.0: 2.16
•ProwlerThreatScore-1.0: 1.2.3
•CIS-4.0.1: 1.17
•NIS2: 2.1.1, 2.1.2.a, 2.2.1, 3.1.2.d, 4.3.2.a, 5.1.7.b
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM users retain only actively used permissions |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
IAM User admin has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM users retain only actively used permissions |
arn:aws:iam::716468089330:user/aksinya |
|
IAM User aksinya has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM users retain only actively used permissions |
arn:aws:iam::716468089330:user/Dilbag |
|
IAM User Dilbag has not accessed Bedrock in 106 days (threshold: 60 days). |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM users retain only actively used permissions |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
IAM User igor@devteamspace.com has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_access_not_stale_to_bedrock |
Regular Bedrock access ensures IAM users retain only actively used permissions |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
IAM User louis has Bedrock permissions but has never used them. |
Stale Bedrock permissions widen the blast radius of a credential compromise.
An attacker who gains access to a user with unused Bedrock permissions can invoke foundation models, exfiltrate data through model responses, or incur significant costs — all without triggering expected usage patterns. |
Apply the principle of least privilege by regularly reviewing IAM Access Advisor data and revoking Bedrock permissions that are no longer actively used.
Establish a periodic access review process and automate alerts for stale permissions to maintain a minimal attack surface. |
•MITRE-ATTACK: T1078
•ISO27001-2013: A.9.2.M
•C5-2025: IAM-03.02B, IAM-10.01B
•NIST-CSF-2.0: ac_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_5, 3_5_6
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_g, ac_2_j, ac_3_8, ac_6
•ENS-RD2022: op.acc.6.r7.aws.iam.1
•NIST-CSF-1.1: ac_1, ac_4
•SecNumCloud-3.2: 9.2, 9.4
•PCI-3.2.1: 8.1.4
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-05
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-6
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:root |
|
User <root_account> does not have access keys. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has not used access key 1 in the last 45 days (294 days). |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has not used access key 2 in the last 45 days (318 days). |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya does not have access keys. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat does not have access keys. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag does not have access keys. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have unused access keys for 45 days. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has not used access key 1 in the last 45 days (292 days). |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis does not have unused access keys for 45 days. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user has not used access key 1 in the last 45 days (154 days). |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii does not have unused access keys for 45 days. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_accesskey_unused |
IAM user does not have unused access keys older than 45 days |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor does not have access keys. |
Active yet unused keys expand the attack surface. If leaked, adversaries gain API access for data exfiltration, unauthorized changes, and resource abuse, harming confidentiality, integrity, and availability. Stale credentials also enable persistence and unexpected cost spikes. |
Disable or delete unused access keys promptly and prefer IAM roles with temporary credentials. Enforce least privilege, rotation, and time-bounded access. Monitor last-used metadata and automate deactivation of idle keys. Use federation/SSO to avoid long-lived user keys. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B, CRY-03.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•PCI-4.0: 7.2.4.2, 7.2.5.1.2, 8.2.6.2, A3.4.1.10
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
IAM User admin does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/aksinya |
|
IAM User aksinya does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/Azamat |
|
IAM User Azamat does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/Dilbag |
|
IAM User Dilbag does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
IAM User gitlab-ci-ecr-push does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
IAM User igor@devteamspace.com does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
IAM User louis does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
IAM User scrivas-storage-user does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/Vasilii |
|
IAM User Vasilii does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| PASS |
critical |
iam |
us-east-2 |
iam_user_administrator_access_policy |
IAM user does not have AdministratorAccess policy attached |
arn:aws:iam::716468089330:user/Yegor |
|
IAM User Yegor does not have AdministratorAccess policy. |
Assigning an IAM user full admin rights concentrates power in long-lived credentials. If compromised, attackers gain:
- Confidentiality: read/export all data
- Integrity: change configs, policies, code
- Availability: delete resources, disrupt services
Also enables persistence and uncontrolled spend. |
Remove direct AdministratorAccess from users.
- Apply least privilege with scoped policies
- Use federation and roles for temporary admin access
- Enforce separation of duties and approvals
- Add guardrails (SCPs, permissions boundaries)
- Require MFA and rotate any remaining long-lived credentials |
•KISA-ISMS-P-2023: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B, IAM-10.01B
•KISA-ISMS-P-2023-korean: 2.5.1, 2.5.5, 2.5.6, 2.10.2
•NIST-CSF-2.0: rr_1, rr_2, po_1, am_6, ac_4
•ASD-Essential-Eight-Nov 2023: E8-4.2
•PCI-4.0: 7.2.1.19, 7.2.2.19, 7.2.5.13, 7.3.1.13, 7.3.2.13, 7.3.3.13, 8.2.7.13, 8.2.8.15, 8.3.4.13
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-02
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has not logged in to the console in the past 45 days (113 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya has not logged in to the console in the past 45 days (98 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat has logged in to the console in the past 45 days (2 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag has logged in to the console in the past 45 days (2 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have console access enabled or is unused. |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has not logged in to the console in the past 45 days (289 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis has logged in to the console in the past 45 days (-1 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user does not have console access enabled or is unused. |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has logged in to the console in the past 45 days (0 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_console_access_unused |
IAM user console access is disabled, used within the configured inactivity period, or never used |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor has logged in to the console in the past 45 days (1 days). |
Dormant console credentials stay valid and invite password spraying, credential stuffing, and breach reuse. Compromise yields interactive access for data discovery/exfiltration and unauthorized IAM or resource changes, degrading confidentiality and integrity, and risking availability. |
Remove or disable console passwords for users inactive beyond your window (e.g., 45 days). Prefer roles or federation over long-lived IAM users. Enforce least privilege, require MFA for remaining console users, and run periodic reviews and deprovisioning to prevent unused credentials. |
•CISA: your-systems-3
•CIS-7.0: 2.11
•SOC2: cc_1_3
•CIS-1.4: 1.12
•CIS-1.5: 1.12
•MITRE-ATTACK: T1078, T1550, T1110
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.8, IAM.22, IAM.26
•ISO27001-2013: A.9.2.M, A.9.3.J, A.9.4.M
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, IAM-03.02B, IAM-03.03B, IAM-03.01AS, IAM-05.04B, IAM-10.01B
•HIPAA: 164_308_a_3_ii_b, 164_308_a_4_ii_c, 164_308_a_5_ii_d
•CIS-2.0: 1.12
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•NIST-CSF-2.0: ac_1
•CIS-5.0: 1.11
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_4, 3_1_5, 3_5_6, 3_5_7, 3_5_8
•NIST-800-53-Revision-4: ac_2_1, ac_2_3, ac_2, ac_3, ac_6
•NIST-800-53-Revision-5: ac_2_1, ac_2_3_a, ac_2_3_b, ac_2_3_c, ac_2_3_d, ac_2_3, ac_2_6, ac_2_g, ac_2_j, ac_3, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_7, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_6, ac_24, cm_5_1_a, cm_6_a, cm_9_b, mp_2, sc_23_3
•CIS-3.0: 1.12
•ENS-RD2022: op.acc.6.aws.iam.2, op.acc.6.aws.iam.3, op.acc.6.r7.aws.iam.1
•CIS-6.0: 2.11
•NIST-CSF-1.1: ac_1, ac_4
•CCC-v2025.10: CCC.IAM.CN07.AR01, CCC.IAM.CN08.AR01
•SecNumCloud-3.2: 9.2, 9.4
•FFIEC: d3-pc-am-b-6
•PCI-3.2.1: 8.1, 8.1.4
•ProwlerThreatScore-1.0: 1.1.10
•ISO27001-2022: A.5.15
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ac-2-3, ac-3, ac-5-c, ac-6
•FedRAMP-Low-Revision-4: ac-2, ac-3
•CIS-4.0.1: 1.12
•NIS2: 11.3.2.d, 11.5.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-iam-07
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat has hardware MFA enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have any type of MFA enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user does not have any type of MFA enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_hardware_mfa_enabled |
IAM user has hardware MFA enabled |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor has a virtual MFA instead of a hardware MFA device enabled. |
Without hardware MFA, authentication is weaker:
- SIM-swap can bypass SMS
- Phishing can steal TOTP from virtual apps
- No MFA allows password-only takeover
This enables unauthorized console/API access, causing data exfiltration (C), privilege abuse (I), and service disruption (A). |
Require hardware-backed MFA for all IAM users. Prefer FIDO2 security keys for phishing resistance over TOTP or SMS. Disallow SMS/virtual MFA for privileged roles. Enforce MFA for all access paths, apply least privilege, and provision multiple MFA devices per user for continuity. |
•CISA: booting-up-thing-to-do-first-2
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-16.01B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•ASD-Essential-Eight-Nov 2023: E8-3.1, E8-3.7
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.6
•ISO27001-2022: A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRAMP-Low-Revision-4: ac-2
•NIS2: 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have Console Password enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user does not have Console Password enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
high |
iam |
us-east-2 |
iam_user_mfa_enabled_console_access |
IAM user has MFA enabled for console access or no console password is set |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor has Console Password enabled and MFA enabled. |
Without MFA, a stolen or brute-forced password grants full interactive access. Attackers can: - Change policies or keys - Exfiltrate data - Create backdoor users - Disable logging. This enables account takeover, threatens confidentiality and integrity, and can disrupt availability. |
Enforce MFA for all console-capable IAM users; prefer phishing-resistant authenticators (FIDO2/security keys) and register backups. Remove console passwords for users that don't need them and favor federation/SSO. Apply least privilege and require MFA for sensitive actions to prevent unauthorized changes. |
•CISA: your-systems-3, your-surroundings-2, booting-up-thing-to-do-first-2
•CIS-7.0: 2.10
•CIS-1.4: 1.10
•CIS-1.5: 1.10
•MITRE-ATTACK: T1078, T1098, T1556, T1550, T1110, T1040, T1538
•GDPR: article_25
•AWS-Foundational-Security-Best-Practices: IAM.5, IAM.19
•ISO27001-2013: A.9.2.J, A.9.3.H, A.9.4.J
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: OPS-05.02AC, OPS-16.01B, IAM-04.06B, IAM-06.09B, IAM-08.02B, IAM-08.05B, IAM-09.02B, IAM-09.01AC, IAM-10.01B, PSS-05.01B, PSS-07.01B, PSS-07.02B
•HIPAA: 164_308_a_3_ii_a, 164_312_a_1, 164_312_d
•CIS-2.0: 1.10
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.200
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_7
•CIS-5.0: 1.9
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_14, 3_5_2, 3_5_3
•ASD-Essential-Eight-Nov 2023: E8-3.1
•PCI-4.0: 8.4.1.1, 8.4.1.2, 8.4.2.1, 8.4.2.2, 8.4.3.1, 8.4.3.2
•NIST-800-53-Revision-4: ia_2_1, ia_2_2, ia_2_11
•NIST-800-53-Revision-5: ac_2_1, ac_3_2, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_7_4, ac_7_4_a, ac_24, cm_5_1_a, cm_6_a, cm_9_b, ia_2_1, ia_2_2, ia_2_6, ia_2_6_a, ia_2_8, sc_23_3
•CIS-3.0: 1.10
•ENS-RD2022: op.acc.6.r2.aws.iam.1, op.acc.6.r4.aws.iam.1, op.acc.6.r8.aws.iam.1
•CIS-6.0: 2.9
•AWS-Foundational-Technical-Review: IAM-001, IAM-0012
•NIST-CSF-1.1: ac_3, ac_7
•AWS-Audit-Manager-Control-Tower-Guardrails: 3.0.1, 3.0.2, 3.0.3
•CCC-v2025.10: CCC.Core.CN03.AR01, CCC.Core.CN03.AR03, CCC.Core.CN05.AR02, CCC.Core.CN05.AR06
•SecNumCloud-3.2: 9.5
•FFIEC: d3-pc-am-b-15, d3-pc-am-b-6
•PCI-3.2.1: 8.3, 8.3.1, 8.3.1.a, 8.3.2, 8.3.2.a, 8.6, 8.6.c
•ProwlerThreatScore-1.0: 1.1.3
•ISO27001-2022: A.5.15, A.5.17, A.8.5
•AWS-AI-Security-Framework-1.0: AISF-IAM-01
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-f, ac-2-j, ia-2-1-2, ia-2-1
•FedRAMP-Low-Revision-4: ac-2, ia-2
•CIS-4.0.1: 1.10
•NIS2: 11.1.2.c, 11.3.2.a, 11.4.2.c, 11.6.1, 11.7.2
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:root |
|
User <root_account> does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_no_setup_initial_access_key |
IAM user does not have active access keys that have never been used |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor does not have access keys or uses the access keys configured. |
Active yet unused access keys expand the attack surface. If exposed, attackers gain programmatic access for unauthorized API calls, causing data exfiltration (confidentiality), unauthorized changes (integrity), and service disruption (availability). Dormant keys also bloat credential inventory, delaying detection and rotation. |
Apply least privilege to programmatic access:
- Do not provision access keys by default for console users
- Prefer IAM roles and temporary credentials
- Require justification and time-bounded key creation
- Regularly review usage and disable/delete unused keys
- Limit to one active key per user and enforce rotation with monitoring |
•CIS-1.4: 1.11
•CIS-1.5: 1.11
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OPS-05.02AC, IAM-10.01B, CRY-03.01B, PSS-07.01B
•CIS-2.0: 1.11
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•CIS-5.0: 1.1
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.11
•ENS-RD2022: op.acc.6.aws.iam.4
•CIS-6.0: 2.10
•CCC-v2025.10: CCC.Core.CN03.AR02, CCC.Core.CN03.AR04, CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.11
•NIS2: 9.2.c, 9.2.c.iii
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:root |
|
User <root_account> does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| PASS |
medium |
iam |
us-east-2 |
iam_user_two_active_access_key |
IAM user has at most one active access key |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor does not have 2 active access keys. |
Two active keys per user widen exposure and weaken credential governance.
- Any leaked key enables unauthorized API actions, risking data exfiltration and resource changes
- Rotation and response become error-prone, allowing attacker persistence if one key remains unnoticed |
Maintain one Active access key per IAM user; permit only a brief overlap for rotation, then promptly deactivate and delete the old key. Prefer temporary credentials via roles/federation over long-lived keys. Apply least privilege, periodic rotation, and monitor for unused or aged keys. |
•CIS-1.4: 1.13
•CIS-1.5: 1.13
•MITRE-ATTACK: T1078, T1550
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-10.01B, CRY-03.01B
•CIS-2.0: 1.13
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP01
•NIST-CSF-2.0: ac_1, ac_6
•CIS-5.0: 1.12
•ASD-Essential-Eight-Nov 2023: E8-4.2
•CIS-3.0: 1.13
•ENS-RD2022: op.acc.6.aws.iam.1
•CIS-6.0: 2.12
•CCC-v2025.10: CCC.IAM.CN01.AR01, CCC.IAM.CN01.AR02
•SecNumCloud-3.2: 9.3
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
•CIS-4.0.1: 1.13
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/admin |
•AKIA2NUGTOHZOD7T5KWA=Deployment-Installation
•AKIA2NUGTOHZBDLCH7XN=sai
•AKIA2NUGTOHZO45UBFNB=aksinya
|
User admin has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| PASS |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/aksinya |
|
User aksinya doesn't have long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| PASS |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/Azamat |
|
User Azamat doesn't have long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| PASS |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/Dilbag |
|
User Dilbag doesn't have long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/gitlab-ci-ecr-push |
•AKIA2NUGTOHZL6Y45Y4W=full be added in gitlab variable to do push pull ecr
|
User gitlab-ci-ecr-push has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/igor@devteamspace.com |
•AKIA2NUGTOHZPMTQ6YNU=LocalComputer
|
User igor@devteamspace.com has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/louis |
•AKIA2NUGTOHZGJX4RESB=Review Key
|
User louis has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/scrivas-storage-user |
•AKIA2NUGTOHZGGN6AXMK=scrivas external server S3 access
|
User scrivas-storage-user has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| FAIL |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/Vasilii |
|
User Vasilii has long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| PASS |
high |
iam |
us-east-2 |
iam_user_with_temporary_credentials |
IAM user does not use long-lived credentials to access services other than IAM or STS |
arn:aws:iam::716468089330:user/Yegor |
|
User Yegor doesn't have long lived credentials with access to other services than IAM or STS. |
Persistent access keys enable attacker persistence and replay. Stolen keys allow off-network API calls for data exfiltration, privilege changes, and destructive actions, impacting confidentiality, integrity, and availability. Without expiry, the blast radius grows and containment is harder. |
Adopt temporary credentials via IAM roles and federation for humans and workloads. Remove or restrict long-term keys; if unavoidable, apply least privilege, require MFA, rotate aggressively, and monitor usage. Prefer short session durations and session conditions to limit blast radius. |
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: IAM-01.01B, IAM-01.04B, IAM-03.01B, IAM-03.03B, IAM-03.01AS, IAM-06.01B, IAM-08.02B
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•NIST-CSF-2.0: ac_6
•AWS-Foundational-Technical-Review: IAM-002, IAM-0012
•AWS-AI-Security-Framework-1.0: AISF-IAM-03
|
| PASS |
high |
inspector2 |
us-east-1 |
inspector2_active_findings_exist |
Inspector2 is enabled with no active findings |
arn:aws:inspector2:us-east-1:716468089330:inspector2 |
|
Inspector2 is enabled with no active findings. |
Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.
This enables:
- Unauthorized access and data exfiltration (C)
- Code tampering and privilege escalation (I)
- Service disruption via exploitation or malware (A) |
Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.
Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention. |
•MITRE-ATTACK: T1190, T1562, T1110, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: AM-09.04AC, OPS-04.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: ov_2, ip_7, ip_12
•ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1
•AWS-Foundational-Technical-Review: SECOPS-001
•SecNumCloud-3.2: 12.11
•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr
|
| FAIL |
high |
inspector2 |
us-east-2 |
inspector2_active_findings_exist |
Inspector2 is enabled with no active findings |
arn:aws:inspector2:us-east-2:716468089330:inspector2 |
|
There are active Inspector2 findings. |
Unremediated Inspector2 findings mean known vulnerabilities or exposures persist on workloads.
This enables:
- Unauthorized access and data exfiltration (C)
- Code tampering and privilege escalation (I)
- Service disruption via exploitation or malware (A) |
Prioritize and remediate Active findings quickly: patch hosts and runtimes, update/rebuild images, fix vulnerable code, and close unintended exposure.
Apply least privilege, use defense in depth, and avoid broad suppressions. Integrate findings into CI/CD and vulnerability management for continuous prevention. |
•MITRE-ATTACK: T1190, T1562, T1110, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: AM-09.04AC, OPS-04.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•NIST-CSF-2.0: ov_2, ip_7, ip_12
•ASD-Essential-Eight-Nov 2023: E8-1.3, E8-1.5, E8-2.3, E8-2.5
•AWS-Account-Security-Onboarding: Scan images for vulnerability on upload to ECR
•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1
•AWS-Foundational-Technical-Review: SECOPS-001
•SecNumCloud-3.2: 12.11
•NIS2: 2.1.2.g, 2.1.2.h, 5.1.4.f, 5.1.7.d
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-tpr
|
| PASS |
medium |
inspector2 |
us-east-1 |
inspector2_is_enabled |
Inspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda code |
arn:aws:inspector2:us-east-1:716468089330:inspector2 |
|
Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code. |
Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.
Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability. |
Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.
Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings. |
•MITRE-ATTACK: T1190, T1562, T1110, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2
•C5-2025: OPS-32.01B, PSS-11.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2
•NIST-CSF-2.0: ip_7, ip_12, cm_1
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4
•AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR
•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1
•AWS-Foundational-Technical-Review: SECOPS-001
•SecNumCloud-3.2: 12.11, 14.6, 18.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07
|
| PASS |
medium |
inspector2 |
us-east-2 |
inspector2_is_enabled |
Inspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda code |
arn:aws:inspector2:us-east-2:716468089330:inspector2 |
|
Inspector2 is enabled for EC2 instances, ECR container images, Lambda functions and code. |
Absent or partial coverage leaves unpatched vulnerabilities, risky code dependencies, and unintended network exposure undetected.
Attackers can exploit known CVEs for remote code execution, lateral movement, and data exfiltration, degrading confidentiality, integrity, and availability. |
Enable Amazon Inspector 2 across all regions and activate scans for EC2, ECR, Lambda, and Lambda code.
Apply defense in depth: auto-enable coverage for new workloads, integrate findings with patching and CI/CD gates, enforce remediation SLAs, and grant only least privilege to process and act on findings. |
•MITRE-ATTACK: T1190, T1562, T1110, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.2
•C5-2025: OPS-32.01B, PSS-11.01B
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.2
•NIST-CSF-2.0: ip_7, ip_12, cm_1
•ASD-Essential-Eight-Nov 2023: E8-1.1, E8-1.2, E8-1.3, E8-2.1, E8-2.2, E8-2.3, E8-2.4
•AWS-Account-Security-Onboarding: Enable and configure AWS Inspector, Scan images for vulnerability on upload to ECR
•ENS-RD2022: op.exp.4.r4.aws.insp.1, op.mon.3.r2.aws.insp.1, op.mon.3.r6.aws.insp.1
•AWS-Foundational-Technical-Review: SECOPS-001
•SecNumCloud-3.2: 12.11, 14.6, 18.4
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-mla, ksi-tpr, ksi-mla-07
|
| PASS |
low |
kms |
us-east-2 |
kms_cmk_are_used |
KMS customer managed key is enabled or scheduled for deletion |
arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d |
|
KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is being used. |
Keeping unused CMKs increases attack surface and cost.
If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability. |
Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.
Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01
•CCC-v2025.10: CCC.Core.CN11.AR03
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.5, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
|
| PASS |
low |
kms |
us-east-2 |
kms_cmk_are_used |
KMS customer managed key is enabled or scheduled for deletion |
arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 |
|
KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is being used. |
Keeping unused CMKs increases attack surface and cost.
If such keys are re-enabled or misconfigured, they can grant unintended decryption, impacting confidentiality. Deleting a key mistakenly thought unused can cause irrecoverable data loss, harming availability. |
Adopt a key lifecycle: confirm actual usage with logs, owners, and tags; keep keys Enabled only when required; otherwise schedule deletion with a waiting period.
Enforce least privilege to enable/disable or delete keys, require approvals, and monitor KMS activity with separation of duties. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, CRY-03.01B, CRY-05.02B, CRY-19.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP01
•CCC-v2025.10: CCC.Core.CN11.AR03
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.5, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
|
| PASS |
critical |
kms |
us-east-2 |
kms_cmk_not_deleted_unintentionally |
AWS KMS customer managed key is not scheduled for deletion |
arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d |
|
KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not scheduled for deletion. |
A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window. |
Prevent unintended deletion:
- Enforce least privilege and separation of duties for key admins
- Require change approvals and alerts on deletion events
- Prefer disabling unused keys over deleting
- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization |
•AWS-Foundational-Security-Best-Practices: KMS.3
•KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1
•C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1
•NIST-CSF-2.0: ra_1, ds_3
•PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
|
| PASS |
critical |
kms |
us-east-2 |
kms_cmk_not_deleted_unintentionally |
AWS KMS customer managed key is not scheduled for deletion |
arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 |
|
KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not scheduled for deletion. |
A key scheduled for deletion can lead to permanent loss of decryption capability, degrading availability and integrity of data and workloads. Accidental or malicious scheduling enables cryptographic erasure, causing outages, failed restores, and broken integrations during and after the wait window. |
Prevent unintended deletion:
- Enforce least privilege and separation of duties for key admins
- Require change approvals and alerts on deletion events
- Prefer disabling unused keys over deleting
- Set sufficient waiting periods and review keys in PendingDeletion to verify authorization |
•AWS-Foundational-Security-Best-Practices: KMS.3
•KISA-ISMS-P-2023: 2.7.2, 2.9.2, 2.10.1
•C5-2025: OIS-08.02B, AM-07.02B, CRY-03.01B, CRY-05.02B, CRY-16.02B, CRY-19.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.9.2, 2.10.1
•NIST-CSF-2.0: ra_1, ds_3
•PCI-4.0: 3.5.1.1.9, 3.5.1.3.17, 3.6.1.2.9, 3.6.1.3.9, 3.6.1.4.9, 3.6.1.9, 3.7.1.10, 3.7.2.9, 3.7.4.10, 3.7.6.9, 3.7.7.9, 4.2.1.1.22
•CCC-v2025.10: CCC.Core.CN11.AR04, CCC.KeyMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
|
| PASS |
medium |
kms |
us-east-2 |
kms_cmk_not_multi_region |
AWS KMS customer managed key is single-Region |
arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d |
|
KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is a single-region key. |
Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability. |
Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary. |
•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC
•NIST-CSF-2.0: ra_1
•ISO27001-2022: A.8.11, A.8.24
|
| PASS |
medium |
kms |
us-east-2 |
kms_cmk_not_multi_region |
AWS KMS customer managed key is single-Region |
arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 |
|
KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is a single-region key. |
Shared key material across Regions lets access in one Region decrypt data from another, eroding confidentiality and data residency. A misconfigured policy or weaker controls in a replica expand the blast radius. For signing/HMAC keys, compromise enables cross-Region signature forgery, impacting integrity and auditability. |
Prefer single-Region keys by default; use multi-Region only with a documented need. Apply least privilege and separation of duties; limit who can create or replicate such keys. Isolate per Region/tenant/workload, standardize policy and logging across Regions, and retire multi-Region keys where unnecessary. |
•C5-2025: OIS-08.02B, PS-02.01B, PS-02.01AS, PS-02.02AS, CRY-03.01B, CRY-05.02B, CRY-10.01B, CRY-19.01B, PSS-12.02AC
•NIST-CSF-2.0: ra_1
•ISO27001-2022: A.8.11, A.8.24
|
| FAIL |
high |
kms |
us-east-2 |
kms_cmk_rotation_enabled |
KMS customer-managed symmetric CMK has automatic rotation enabled |
arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d |
|
KMS CMK 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d has automatic rotation disabled. |
Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies. |
Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected. |
•CISA: your-systems-3
•CIS-7.0: 4.6
•SOC2: pi_1_5
•CIS-1.4: 3.8
•CIS-1.5: 3.8
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: KMS.4
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B
•HIPAA: 164_312_a_2_iv
•CIS-2.0: 3.8
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•CIS-5.0: 3.6
•PCI-4.0: 3.7.4.5, 3.7.5.2
•NIST-800-53-Revision-4: sc_12
•NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6
•CIS-3.0: 3.6
•ENS-RD2022: op.exp.10.aws.cmk.3
•CIS-6.0: 4.6
•CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01
•SecNumCloud-3.2: 10.5
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 3.2.1
•ISO27001-2022: A.8.5, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
•FedRamp-Moderate-Revision-4: sc-12
•FedRAMP-Low-Revision-4: sc-12
•CIS-4.0.1: 3.6
•NIS2: 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
high |
kms |
us-east-2 |
kms_cmk_rotation_enabled |
KMS customer-managed symmetric CMK has automatic rotation enabled |
arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 |
|
KMS CMK 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 has automatic rotation disabled. |
Without automatic rotation, long-lived key material increases confidentiality and integrity risk. If a KMS key is exposed, attackers can unwrap data keys and decrypt stored data until the key changes. It also reduces crypto agility and may conflict with mandated rotation policies. |
Enable automatic rotation on customer-managed symmetric KMS keys and choose a rotation period that meets policy. Enforce least privilege and separation of duties for key administration versus usage. Monitor key lifecycle events and use on-demand rotation when compromise is suspected. |
•CISA: your-systems-3
•CIS-7.0: 4.6
•SOC2: pi_1_5
•CIS-1.4: 3.8
•CIS-1.5: 3.8
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: KMS.4
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, CRY-05.02B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-19.01B
•HIPAA: 164_312_a_2_iv
•CIS-2.0: 3.8
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•CIS-5.0: 3.6
•PCI-4.0: 3.7.4.5, 3.7.5.2
•NIST-800-53-Revision-4: sc_12
•NIST-800-53-Revision-5: cm_6_a, cm_9_b, sa_9_6, sc_12, sc_12_2, sc_12_6
•CIS-3.0: 3.6
•ENS-RD2022: op.exp.10.aws.cmk.3
•CIS-6.0: 4.6
•CCC-v2025.10: CCC.Core.CN11.AR02, CCC.Core.CN11.AR05, CCC.Core.CN11.AR06, CCC.KeyMgmt.CN03.AR01
•SecNumCloud-3.2: 10.5
•RBI-Cyber-Security-Framework: annex_i_1_3
•ProwlerThreatScore-1.0: 3.2.1
•ISO27001-2022: A.8.5, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
•FedRamp-Moderate-Revision-4: sc-12
•FedRAMP-Low-Revision-4: sc-12
•CIS-4.0.1: 3.6
•NIS2: 11.6.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| MANUAL |
medium |
kms |
us-east-2 |
kms_key_enclave_attestation_unknown_image |
No enclave with an unknown image identity has called this KMS key |
arn:aws:kms:us-east-2:716468089330:enclave-debug-attestation |
|
Cannot verify unknown-image attestation activity: no 'enclave_golden_pcr_values' configured. Set a golden PCR list in audit_config and re-run this check. |
An attestation event whose PCRs cannot be traced back to a known-good enclave build indicates either a stale golden list, a policy broad enough to accept unaudited images, or a compromise scenario in which an unknown image is being executed with legitimate KMS access. Materiality depends on the operator's threat model. |
Treat the enclave_golden_pcr_values list as a live registry of trusted enclave images. Any runtime attestation from a PCR outside that list is either a documentation gap (extend the list) or a suspected incident (investigate). |
•SOC2: cc_7_2
•MITRE-ATTACK: T1078
•HIPAA: 164_312_c_2
•NIST-CSF-2.0: cm_1
•PCI-4.0: 10.4.1.7
•NIST-800-53-Revision-5: si_4_2
•ISO27001-2022: A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-03
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| MANUAL |
high |
kms |
us-east-2 |
kms_key_enclave_debug_attestation_detected |
No Nitro Enclave debug-mode attestation observed against this KMS key |
arn:aws:kms:us-east-2:716468089330:enclave-debug-attestation |
|
No KMS-from-enclave attestation events found in the last 2160h. Debug-mode status cannot be determined from available data; enclaves that never call KMS in the window are not observable via this check. |
Debug mode zeros the image, kernel and application PCRs (PCR0/1/2) in the attestation document, so PCR-bound key policies release material to enclaves whose measurement cannot be trusted. A debug enclave calling this KMS key is functionally equivalent to no enclave at all. |
Never run production Nitro Enclaves with --debug-mode. Enforce non-debug launch flags in the enclave orchestration pipeline and pair with strict PCR bindings on KMS policies so debug enclaves are rejected at the key-policy layer. |
•SOC2: cc_7_2
•MITRE-ATTACK: T1562
•HIPAA: 164_308_a_1_ii_d, 164_312_b
•NIST-CSF-2.0: cm_1
•PCI-4.0: 3.5.1.36
•NIST-800-53-Revision-5: sc_28_1, si_4_2
•PCI-3.2.1: 10.2
•ISO27001-2022: A.8.16
•AWS-AI-Security-Framework-1.0: AISF-DETECT-03
•FedRamp-Moderate-Revision-4: sc-28, si-4-2
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
critical |
kms |
us-east-2 |
kms_key_not_publicly_accessible |
Cloud KMS key does not grant access to allUsers or allAuthenticatedUsers |
arn:aws:kms:us-east-2:716468089330:key/3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d |
|
KMS key 3fbb121b-c5a0-488b-9a0b-c0ae9a079e6d is not exposed to Public. |
Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key. |
Apply least privilege to KMS keys:
- Restrict principals to specific roles and accounts
- Prefer narrow, time-bound grants
- Separate key administration from usage
- Use conditions to limit context
- Review regularly and remove wildcard or cross-account exposure |
•CIS-7.0: 2.21
•AWS-Foundational-Security-Best-Practices: KMS.5
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.5
•ProwlerThreatScore-1.0: 2.2.14
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
critical |
kms |
us-east-2 |
kms_key_not_publicly_accessible |
Cloud KMS key does not grant access to allUsers or allAuthenticatedUsers |
arn:aws:kms:us-east-2:716468089330:key/65c0c9a2-1be0-48bb-b371-6c99c13c1b72 |
|
KMS key 65c0c9a2-1be0-48bb-b371-6c99c13c1b72 is not exposed to Public. |
Broad access to a KMS key enables unauthorized kms:Decrypt and data-key generation, breaking confidentiality. With admin rights, attackers can change policies or schedule deletion, undermining control integrity and threatening availability of data dependent on the key. |
Apply least privilege to KMS keys:
- Restrict principals to specific roles and accounts
- Prefer narrow, time-bound grants
- Separate key administration from usage
- Use conditions to limit context
- Review regularly and remove wildcard or cross-account exposure |
•CIS-7.0: 2.21
•AWS-Foundational-Security-Best-Practices: KMS.5
•KISA-ISMS-P-2023: 2.7.2, 2.10.1, 2.10.2
•C5-2025: OIS-08.02B, PS-03.02B, IAM-10.01B, CRY-03.01B, CRY-05.02B, CRY-19.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•CCC-v2025.10: CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.5
•ProwlerThreatScore-1.0: 2.2.14
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-07
•NIS2: 9.2.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
high |
macie |
us-east-2 |
macie_automated_sensitive_data_discovery_enabled |
Macie automated sensitive data discovery is enabled |
arn:aws:macie:us-east-2:716468089330:session |
|
Macie has automated sensitive data discovery enabled. |
Without continuous discovery, sensitive S3 objects remain unclassified and unnoticed, weakening confidentiality. Over-permissive or public access can persist undetected, enabling data exfiltration and delaying containment and forensic response. |
Enable and maintain automated sensitive data discovery for the Macie administrator across required Regions. Include relevant buckets, tune identifiers and allow lists to reduce noise, and route findings to monitoring. Complement with least privilege on S3 and defense in depth for data protection. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•PCI-4.0: A3.2.5.1.1, A3.2.5.1.3
•AWS-AI-Security-Framework-1.0: AISF-DATA-01
|
| FAIL |
medium |
macie |
us-east-1 |
macie_is_enabled |
Amazon Macie is enabled |
arn:aws:macie:us-east-1:716468089330:session |
|
Macie is not enabled. |
Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides. |
Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls. |
•CIS-7.0: 3.1.3
•CIS-1.4: 2.1.4
•CIS-1.5: 2.1.4
•MITRE-ATTACK: T1552, T1537, T1530
•AWS-Foundational-Security-Best-Practices: Macie.1
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•CIS-2.0: 2.1.3
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•CIS-5.0: 2.1.3
•PCI-4.0: A3.2.5.1.2, A3.2.5.1.4
•AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only
•CIS-3.0: 2.1.3
•CIS-6.0: 3.1.3
•ProwlerThreatScore-1.0: 2.2.2
•AWS-AI-Security-Framework-1.0: AISF-DATA-01
•CIS-4.0.1: 2.1.3
|
| PASS |
medium |
macie |
us-east-2 |
macie_is_enabled |
Amazon Macie is enabled |
arn:aws:macie:us-east-2:716468089330:session |
|
Macie is enabled. |
Without active Macie, sensitive data in S3 can remain unclassified and exposed. Misconfigured access and public buckets may go undetected, enabling data exfiltration and secret leakage. This degrades confidentiality and widens breach blast radius by reducing visibility into where sensitive data resides. |
Enable and maintain Amazon Macie in all regions hosting S3 data. Use continuous sensitive data discovery, apply custom classifications for your data types, and route findings to monitoring. Enforce least privilege for Macie access and strengthen defense in depth with restrictive bucket policies and access controls. |
•CIS-7.0: 3.1.3
•CIS-1.4: 2.1.4
•CIS-1.5: 2.1.4
•MITRE-ATTACK: T1552, T1537, T1530
•AWS-Foundational-Security-Best-Practices: Macie.1
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•CIS-2.0: 2.1.3
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•CIS-5.0: 2.1.3
•PCI-4.0: A3.2.5.1.2, A3.2.5.1.4
•AWS-Account-Security-Onboarding: Enabled security services, Consider enabling for critical buckets only
•CIS-3.0: 2.1.3
•CIS-6.0: 3.1.3
•ProwlerThreatScore-1.0: 2.2.2
•AWS-AI-Security-Framework-1.0: AISF-DATA-01
•CIS-4.0.1: 2.1.3
|
| FAIL |
medium |
networkfirewall |
us-east-2 |
networkfirewall_in_all_vpc |
VPC has Network Firewall enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 |
|
VPC vpc-027f26d26f17ab361 does not have Network Firewall enabled. |
Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic. |
Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies. |
•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•ENS-RD2022: mp.com.1.aws.nfw.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-02
•NIS2: 6.2.1, 6.7.2.b
|
| FAIL |
medium |
networkfirewall |
us-east-2 |
networkfirewall_in_all_vpc |
VPC has Network Firewall enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c |
•Name=Scrivas_prod_vpc
|
VPC Scrivas_prod_vpc does not have Network Firewall enabled. |
Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic. |
Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies. |
•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•ENS-RD2022: mp.com.1.aws.nfw.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-02
•NIS2: 6.2.1, 6.7.2.b
|
| FAIL |
medium |
networkfirewall |
us-east-2 |
networkfirewall_in_all_vpc |
VPC has Network Firewall enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 |
•Name=Scrivas_vpc
|
VPC Scrivas_vpc does not have Network Firewall enabled. |
Without a Network Firewall, VPC traffic can bypass deep inspection and centralized policy enforcement, enabling data exfiltration, command-and-control, and lateral movement. Confidentiality is reduced by unmonitored flows; integrity and availability are threatened by malware and disruptive traffic. |
Deploy AWS Network Firewall in each VPC or centralize inspection through a dedicated hub VPC.
Adopt a default-deny posture with least-privilege rules, restrict egress to required destinations, segment workloads (defense in depth, zero trust), and enable logging to monitor and tune network policies. |
•MITRE-ATTACK: T1048, T1530, T1499, T1498, T1046
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•C5-2025: AM-12.01AC, COS-07.04B, PI-01.01AC
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•ENS-RD2022: mp.com.1.aws.nfw.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-02
•NIS2: 6.2.1, 6.7.2.b
|
| PASS |
medium |
organizations |
us-east-2 |
organizations_account_part_of_organizations |
AWS account is a member of an active AWS Organization |
arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 |
|
AWS Organization o-qfj0pvhhv7 contains this AWS account. |
Absence of AWS Organizations weakens governance across accounts. Without SCP guardrails and centralized policy, excessive permissions, unsafe network settings, or risky services may be enabled, threatening confidentiality and integrity. Fragmented logging and response slow containment, impacting availability and increasing cost exposure. |
Operate all accounts under AWS Organizations (preferably with all features). Structure OUs, enforce SCPs for least privilege, and apply separation of duties between management and member accounts. Centralize logging and billing to support defense-in-depth, and routinely review org membership and policies. |
•MITRE-ATTACK: T1078, T1087, T1580, T1538
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC01-BP01, SEC03-BP05, SEC08-BP04
•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, am_6
•PCI-4.0: 7.2.1.1, 7.2.2.1, 7.2.5.1, 7.3.1.1, 7.3.2.1, 7.3.3.1, 8.2.7.1, 8.2.8.1, 8.3.4.1
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8
•SecNumCloud-3.2: 9.6, 12.3, 14.4
•RBI-Cyber-Security-Framework: annex_i_1_1
•ISO27001-2022: A.8.3
•AWS-AI-Security-Framework-1.0: AISF-GOV-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-piy
|
| PASS |
critical |
organizations |
us-east-2 |
organizations_delegated_administrators |
AWS Organization has only trusted delegated administrators |
arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 |
|
AWS Organization o-qfj0pvhhv7 has no Delegated Administrators. |
Unapproved delegated administrators can alter SCPs, invite/move accounts, and create privileged roles, enabling privilege escalation. This undermines guardrails, risking loss of integrity, exposure of confidentiality across accounts, and impacts availability through organization-wide policy changes. |
Restrict delegation to vetted accounts using least privilege and separation of duties. Maintain a centrally governed approved allowlist, review it regularly, and remove unused delegations. Enforce strong authentication for admin roles and monitor Organizations policy changes for defense in depth. |
•CIS-7.0: 2.1.5, 2.1.6
•MITRE-ATTACK: T1078
•KISA-ISMS-P-2023: 2.5.5, 2.10.2
•C5-2025: OIS-04.03B, SP-01.04B, HR-01.01B, IAM-01.01B, IAM-01.04B
•KISA-ISMS-P-2023-korean: 2.5.5, 2.10.2
•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, ov_3, am_6
•AWS-AI-Security-Framework-1.0: AISF-GOV-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-iam-07
|
| FAIL |
medium |
organizations |
us-east-2 |
organizations_opt_out_ai_services_policy |
AWS Organization has opted out of all AI services and child accounts cannot override the policy |
arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 |
|
AWS Organization o-qfj0pvhhv7 has no opt-out policy for AI services. |
Without an enforced opt-out, AI services may store and use your content for model training, weakening confidentiality and data sovereignty. If child accounts can override, they can re-enable data use, risking unintended cross-Region retention and exposure of logs, documents, or code processed by these services. |
Establish an org-wide AI services opt-out: set the default to optOut and prohibit child policy overrides (@@none). Apply at the highest scope, gate exceptions through change control, and review periodically. Align with least privilege and data minimization to prevent unintended content sharing with managed AI services. |
•KISA-ISMS-P-2023: 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.2
•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3
•AWS-AI-Security-Framework-1.0: AISF-DATA-06
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam
|
| FAIL |
high |
organizations |
us-east-2 |
organizations_scp_check_deny_regions |
AWS Organization restricts operations to only the configured AWS Regions with SCP policies |
arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 |
|
AWS Organization o-qfj0pvhhv7 has SCP policies but don't restrict AWS Regions. |
Without comprehensive Region limits, users or attackers can deploy resources in ungoverned locations, bypassing monitoring and guardrails.
Impacts:
- Data outside approved jurisdictions (confidentiality)
- Policy gaps and drift (integrity)
- IR blind spots and unexpected cost (availability) |
Enforce Region governance with SCPs that allow only approved regions via aws:RequestedRegion conditions (deny-by-default).
Apply across relevant OUs and accounts, with narrow exceptions for required global services. Review often; align to least privilege, data residency, and continuous monitoring. |
•MITRE-ATTACK: T1078, T1535
•KISA-ISMS-P-2023: 2.10.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS, PSS-12.02AC
•KISA-ISMS-P-2023-korean: 2.10.2
•NIST-CSF-2.0: rm_1, rr_1, rr_2, po_3, po_4, ov_3
•AWS-Account-Security-Onboarding: Block unused regions
•ENS-RD2022: op.acc.4.aws.iam.1, op.acc.4.aws.iam.8
•CCC-v2025.10: CCC.Core.CN06.AR01, CCC.Core.CN06.AR02
•SecNumCloud-3.2: 9.1, 19.2
•AWS-AI-Security-Framework-1.0: AISF-GOV-02
•FedRAMP-20x-KSI-Low-25.05C: ksi-iam, ksi-piy
|
| FAIL |
low |
organizations |
us-east-2 |
organizations_tags_policies_enabled_and_attached |
AWS Organization has tag policies enabled and attached |
arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7 |
|
AWS Organizations o-qfj0pvhhv7 does not have tag policies. |
Absent or unattached tag policies cause inconsistent or missing tags, undermining:
- Confidentiality via bypassed tag-based access conditions
- Integrity through misclassified resources and drift
- Availability when automation, cost routing, or incident scoping that rely on tags break |
Enable tag policies and attach them to relevant roots/OUs/accounts. Define mandatory keys (e.g., Environment, CostCenter) with allowed values. Apply defense in depth by using tags in IAM conditions and SCPs. Start with validation-only, then enforce, and continuously monitor compliance across accounts. |
•KISA-ISMS-P-2023: 2.1.3
•C5-2025: AM-09.01B
•KISA-ISMS-P-2023-korean: 2.1.3
•NIST-CSF-2.0: rm_1, po_3, ov_3
•ENS-RD2022: op.exp.1.aws.sys.2, op.exp.1.aws.tag.1, op.exp.10.aws.tag.1, mp.info.6.aws.tag.1
•ISO27001-2022: A.5.13
•AWS-AI-Security-Framework-1.0: AISF-GOV-02
•NIS2: 11.5.2.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-piy
|
| PASS |
high |
rds |
us-east-2 |
rds_snapshots_encrypted |
RDS DB instance snapshot or DB cluster snapshot is encrypted |
arn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frame |
|
RDS Instance Snapshot for-secure-frame is encrypted. |
Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances. |
Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted. |
•AWS-Foundational-Security-Best-Practices: RDS.4
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: ds_1
•ASD-Essential-Eight-Nov 2023: E8-8.3
•PCI-4.0: 3.5.1.26, 8.3.2.43
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl
|
| PASS |
high |
rds |
us-east-2 |
rds_snapshots_encrypted |
RDS DB instance snapshot or DB cluster snapshot is encrypted |
arn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshot |
|
RDS Instance Snapshot scrivas-encounter-dev-snapshot is encrypted. |
Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances. |
Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted. |
•AWS-Foundational-Security-Best-Practices: RDS.4
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: ds_1
•ASD-Essential-Eight-Nov 2023: E8-8.3
•PCI-4.0: 3.5.1.26, 8.3.2.43
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl
|
| PASS |
high |
rds |
us-east-2 |
rds_snapshots_encrypted |
RDS DB instance snapshot or DB cluster snapshot is encrypted |
arn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot |
•Owner=DevTeamSpace
•Purpose=BackupRestoreTest
•Date=2025-10-20
|
RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is encrypted. |
Unencrypted snapshots enable direct access to full database data if backups are leaked, cross-account shared, or stolen. Adversaries can harvest data offline, bypassing network controls, leading to loss of confidentiality. Restores from such snapshots propagate the exposure to new instances. |
Encrypt all RDS snapshots at rest using KMS, preferably customer-managed keys. Apply least privilege to key usage, enforce encryption via templates and automation, and prevent sharing of unencrypted backups. Use key rotation, separation of duties, and ensure copies and cross-account shares remain encrypted. |
•AWS-Foundational-Security-Best-Practices: RDS.4
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: ds_1
•ASD-Essential-Eight-Nov 2023: E8-8.3
•PCI-4.0: 3.5.1.26, 8.3.2.43
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•FedRAMP-20x-KSI-Low-25.05C: ksi-rpl
|
| PASS |
critical |
rds |
us-east-2 |
rds_snapshots_public_access |
RDS snapshot is not publicly shared |
arn:aws:rds:us-east-2:716468089330:snapshot:for-secure-frame |
|
RDS Instance Snapshot for-secure-frame is not shared. |
Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks. |
Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data. |
•CISA: your-systems-3, your-data-2
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: RDS.1
•ISO27001-2013: A.12.6.H, A.13.1.G
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5
•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5
•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2
•CCC-v2025.10: CCC.RDMS.CN05.AR01
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
rds |
us-east-2 |
rds_snapshots_public_access |
RDS snapshot is not publicly shared |
arn:aws:rds:us-east-2:716468089330:snapshot:scrivas-encounter-dev-snapshot |
|
RDS Instance Snapshot scrivas-encounter-dev-snapshot is not shared. |
Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks. |
Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data. |
•CISA: your-systems-3, your-data-2
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: RDS.1
•ISO27001-2013: A.12.6.H, A.13.1.G
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5
•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5
•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2
•CCC-v2025.10: CCC.RDMS.CN05.AR01
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
rds |
us-east-2 |
rds_snapshots_public_access |
RDS snapshot is not publicly shared |
arn:aws:rds:us-east-2:716468089330:cluster-snapshot:restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot |
•Owner=DevTeamSpace
•Purpose=BackupRestoreTest
•Date=2025-10-20
|
RDS Cluster Snapshot restoretest-scrivas-encounter-dev-2025-10-20-final-snapshot is not shared. |
Public RDS snapshots expose full database copies to all AWS accounts, risking:
- Loss of confidentiality via data exfiltration (PII, secrets)
- Offline cracking of hashes and schema reconnaissance
- Credential harvesting from dumps enabling lateral movement
This directly compromises confidentiality and fuels targeted attacks. |
Keep RDS snapshots and cluster snapshots private. Share only with explicit AWS account IDs using least privilege and time-bound access.
Enforce guardrails to block public visibility, require approvals for sharing, and audit snapshot permissions. Use encryption with strict key policies to control who can restore data. |
•CISA: your-systems-3, your-data-2
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: RDS.1
•ISO27001-2013: A.12.6.H, A.13.1.G
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_4_6, 3_13_5
•ASD-Essential-Eight-Nov 2023: E8-8.3, E8-8.5
•PCI-4.0: 10.3.2.16, 3.5.1.3.21, A1.1.2.12, A3.4.1.14
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.0.2
•CCC-v2025.10: CCC.RDMS.CN05.AR01
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.6, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
low |
resourceexplorer2 |
ap-northeast-1 |
resourceexplorer2_indexes_found |
Resource Explorer indexes exist |
arn:aws:resource-explorer-2:ap-northeast-1:716468089330:index/d4aa7318-d5e6-473d-b3c0-8328855a8bdc |
|
Resource Explorer Indexes found: 12. |
Absent indexes reduce asset visibility, creating blind spots where misconfigured or orphaned resources go unnoticed. This degrades confidentiality (unseen public exposure), integrity (unauthorized changes undetected), and availability (slower containment and recovery), prolonging incident response and enabling lateral movement. |
Create Resource Explorer indexes in all active Regions and designate an aggregator index for cross-Region search. Apply least-privilege access to views, align with tagging standards, and routinely verify indexing status. This improves inventory accuracy, supports defense-in-depth, and speeds detection and remediation. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•ENS-RD2022: op.exp.1.aws.re.1
|
| FAIL |
high |
s3 |
us-east-2 |
s3_account_level_public_access_blocks |
S3 account-level Block Public Access ignores public ACLs and restricts public buckets |
arn:aws:s3:us-east-2:716468089330:account |
|
Block Public Access is not configured for the account 716468089330. |
Absent these settings, public ACLs and broad bucket policies may grant internet or cross-account access. This risks:
- Confidentiality: bulk data exfiltration
- Integrity: object overwrite/tampering
- Availability: malicious deletions or malware hosting, triggering takedowns |
Turn on account-level Block Public Access (prefer enabling all four: block_public_acls, ignore_public_acls, block_public_policy, restrict_public_buckets) to enforce least privilege. For legitimate access, use private buckets with CloudFront, VPC endpoints, or presigned URLs. Regularly review policies with IAM Access Analyzer. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.1
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_1_14, 3_1_20, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.31, 1.2.8.32, 1.3.1.35, 1.3.1.36, 1.3.2.35, 1.3.2.36, 1.4.2.33, 1.4.2.34, 1.5.1.31, 1.5.1.32, 10.3.2.19, 10.3.2.20, 3.5.1.3.24, 3.5.1.3.25, A1.1.2.15, A1.1.2.16, A1.1.3.31, A1.1.3.32, A3.4.1.17, A3.4.1.18
•NIST-800-53-Revision-4: sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.3, 2.2, 2.2.2, 7.2, 7.2.1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
•CIS-4.0.1: 2.1.4
|
| PASS |
medium |
s3 |
us-east-1 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_acl_prohibited |
S3 bucket has bucket ACLs disabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has bucket ACLs disabled. |
With ACLs enabled, access can bypass centralized policy controls, impacting confidentiality and integrity.
- Unintended public or cross-account reads/writes
- Object-writer ownership blocking bucket-owner governance
- Per-object grants hinder auditing, enabling data exfiltration or tampering |
Disable ACLs by setting Object Ownership to BucketOwnerEnforced and manage access with IAM and bucket policies under least privilege. Centralize authorization, review policies regularly, and use organizational guardrails to prevent re-enabling ACLs. Migrate ACL-based grants into policies before the change. |
•CISA: your-data-2
•AWS-Foundational-Security-Best-Practices: S3.12
•KISA-ISMS-P-2023: 2.6.2, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•NIST-CSF-2.0: ds_5
•PCI-4.0: 7.2.1.24, 7.2.2.24, 7.2.5.18, 7.3.1.18, 7.3.2.18, 7.3.3.18, 8.2.7.18, 8.2.8.20, 8.3.4.18
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.ObjStor.CN02.AR01, CCC.ObjStor.CN02.AR02
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-1 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| FAIL |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has a bucket policy allowing cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| FAIL |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has a bucket policy allowing cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have a bucket policy. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_cross_account_access |
S3 bucket policy does not allow cross-account access |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has a bucket policy but it does not allow cross account access. |
Cross-account grants can let external principals read, write, or administer the bucket, impacting:
- Confidentiality: unauthorized object access/exfiltration
- Integrity: object tampering, policy or encryption changes
- Availability: deletions, versioning changes, or lockouts causing data loss and downtime |
Enforce least privilege: limit bucket policy Principal to your account or approved org IDs with fixed values; avoid wildcards.
Use role-based cross-account access with scoped permissions when needed. Add defense-in-depth conditions (private networks, TLS), and periodically review for unintended external access. |
•AWS-Foundational-Security-Best-Practices: S3.6, S3.7
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: IAM-10.01B, IAM-10.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5, ip_1
•PCI-4.0: 10.6.3.33, 10.6.3.35, 7.2.1.25, 7.2.1.26, 7.2.1.27, 7.2.2.25, 7.2.2.26, 7.2.2.27, 7.2.5.19, 7.2.5.20, 7.2.5.21, 7.2.6.4, 7.2.6.5, 7.3.1.19, 7.3.1.20, 7.3.1.21, 7.3.2.19, 7.3.2.20, 7.3.2.21, 7.3.3.19, 7.3.3.20, 7.3.3.21, 8.2.7.19, 8.2.7.20, 8.2.7.21, 8.2.8.21, 8.2.8.22, 8.2.8.23, 8.3.4.19, 8.3.4.20, 8.3.4.21
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR03, CCC.Core.CN05.AR04
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
|
| FAIL |
low |
s3 |
us-east-1 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_cross_region_replication |
S3 bucket has cross-region replication configured to a bucket in a different region |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas does not have correct cross region replication configuration. |
Single-Region storage creates an availability gap: a Regional outage, control-plane isolation, or denial of service can make data unreachable.
Lack of replication raises RPO/RTO, delaying recovery and disrupting multi-Region workloads. Missing replicas also weaken data integrity during restore from corruption or deletion. |
Enable CRR to a different Region with versioning and least-privilege roles.
- Replicate needed prefixes and metadata
- Consider
S3 Replication Time Control for tighter RPO
- Protect deletes via
delete marker strategy and Object Lock
- Monitor replication metrics and test DR regularly
Align with defense in depth and availability by design. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ds_4, pt_5
•ASD-Essential-Eight-Nov 2023: E8-8.3
•CCC-v2025.10: CCC.Core.CN08.AR01, CCC.Core.CN08.AR02, CCC.Core.CN10.AR01, CCC.AuditLog.CN05.AR01
•SecNumCloud-3.2: 12.5
•PCI-3.2.1: 2.2, 3.1, 3.1.c, 10.5, 10.5.3
•ISO27001-2022: A.8.14
|
| PASS |
medium |
s3 |
us-east-1 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_default_encryption |
[DEPRECATED] S3 bucket has default server-side encryption (SSE) enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has Server Side Encryption with AES256. |
Without default encryption, older objects may remain unencrypted and new uploads won't be forced to use SSE-KMS. This reduces confidentiality and governance by limiting key audit logs, rotation, and cross-account controls, and increases exposure if data is copied, replicated, or accessed outside intended paths. |
Enable default encryption on all buckets, preferring SSE-KMS for sensitive data to retain key control and auditing. Enforce encryption with restrictive bucket policies, apply least privilege to KMS keys with rotation, and re-encrypt existing objects. Use defense in depth monitoring to detect drift and noncompliant uploads. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•CIS-1.4: 2.1.1
•CIS-1.5: 2.1.1
•MITRE-ATTACK: T1119, T1530
•GDPR: article_32
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•C5-2025: OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01AC, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP03
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: ds_1, ds_3
•NIST-800-171-Revision-2: 3_3_8, 3_5_10, 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.30, 8.3.2.48
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cm_6_a, cm_9_b, cp_9_d, cp_9_8, pm_11_b, sc_8_3, sc_8_4, sc_13_a, sc_16_1, sc_28_1, si_19_4
•ENS-RD2022: mp.si.2.aws.s3.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
low |
s3 |
us-east-1 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_event_notifications_enabled |
S3 bucket has event notifications enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas does not have event notifications enabled. |
Missing notifications leaves object and bucket changes unseen, weakening integrity and availability oversight. Undetected deletions, policy drift, or replication issues can stall data pipelines (S3 to Lambda/SQS), slow incident response, and allow tampering or exfiltration to persist longer. |
Enable S3 event notifications for relevant events (e.g., s3:ObjectCreated:*, s3:ObjectRemoved:*) and route to controlled destinations (SNS, SQS, Lambda, EventBridge).
Use prefix/suffix filters, avoid recursive triggers, and enforce least privilege on targets. Pair with object-level logging for defense in depth. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.3
•C5-2025: OPS-13.01AC, OPS-13.03AC
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.3
•NIST-CSF-2.0: dp_4
•PCI-4.0: 11.5.2.5, 11.6.1.5, 12.10.5.5, A3.3.1.8, A3.5.1.8
|
| FAIL |
medium |
s3 |
us-east-1 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::config-bucket-716468089330 |
|
Server Side Encryption is not configured with kms for S3 Bucket config-bucket-716468089330. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
Server Side Encryption is not configured with kms for S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::maciedata1902 |
|
Server Side Encryption is not configured with kms for S3 Bucket maciedata1902. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::scrivas-access-logs |
|
Server Side Encryption is not configured with kms for S3 Bucket scrivas-access-logs. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
Server Side Encryption is not configured with kms for S3 Bucket scrivas-tf-statefile. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
Server Side Encryption is not configured with kms for S3 Bucket scrivasbackendstorage. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::scrivasbackupsdb |
|
Server Side Encryption is not configured with kms for S3 Bucket scrivasbackupsdb. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::scrivasloggsbucket |
|
Server Side Encryption is not configured with kms for S3 Bucket scrivasloggsbucket. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_kms_encryption |
S3 bucket has server-side encryption with AWS KMS |
arn:aws:s3:::vulnerability-reports-scrivas |
|
Server Side Encryption is not configured with kms for S3 Bucket vulnerability-reports-scrivas. |
Without KMS-based encryption, data relies only on SSE-S3, reducing confidentiality controls. Missing key policies and grants weakens least privilege, cross-account scoping, and the ability to disable or rotate keys. Lack of KMS audit trails obscures key usage, hindering detection of misuse and defense in depth. |
Enable default SSE-KMS (or DSSE-KMS for highly sensitive data). Use a customer-managed key, enforce least privilege and separation of duties for key usage, and require KMS encryption via bucket policy (specify aws:kms and a designated key). Monitor key activity in CloudTrail and consider S3 Bucket Keys to control cost. |
•SOC2: pi_1_4
•AWS-Foundational-Security-Best-Practices: S3.17
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.02B, CRY-05.01AC, PSS-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ds_1, ds_3, ds_5, pt_4
•PCI-4.0: 3.5.1.31, 8.3.2.50
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.ObjStor.CN01.AR01, CCC.ObjStor.CN01.AR02, CCC.ObjStor.CN01.AR03, CCC.ObjStor.CN01.AR04
•SecNumCloud-3.2: 10.1
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 3.4.d, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05, AISF-DATA-04
|
| PASS |
high |
s3 |
us-east-1 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::config-bucket-716468089330 |
|
Block Public Access is configured for the S3 Bucket config-bucket-716468089330. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
Block Public Access is configured for the S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::maciedata1902 |
|
Block Public Access is configured for the S3 Bucket maciedata1902. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::scrivas-access-logs |
|
Block Public Access is configured for the S3 Bucket scrivas-access-logs. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
Block Public Access is configured for the S3 Bucket scrivas-tf-statefile. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
Block Public Access is configured for the S3 Bucket scrivasbackendstorage. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::scrivasbackupsdb |
|
Block Public Access is configured for the S3 Bucket scrivasbackupsdb. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::scrivasloggsbucket |
|
Block Public Access is configured for the S3 Bucket scrivasloggsbucket. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| PASS |
high |
s3 |
us-east-2 |
s3_bucket_level_public_access_block |
S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account level |
arn:aws:s3:::vulnerability-reports-scrivas |
|
Block Public Access is configured for the S3 Bucket vulnerability-reports-scrivas. |
Absent S3 Block Public Access, public ACLs or broad policies can grant Internet or cross-account access.
- Data disclosure (confidentiality)
- Object overwrite or uploads (integrity)
- Deletion or outages from misuse (availability) |
Enable Block Public Access at account and bucket levels with block_public_acls, ignore_public_acls, block_public_policy, and restrict_public_buckets set to true. Apply least privilege and defense in depth. If public access is required, narrowly scope policies to fixed principals and conditions. |
•CIS-7.0: 3.1.4
•CIS-1.4: 2.1.5
•CIS-1.5: 2.1.5
•MITRE-ATTACK: T1530
•AWS-Foundational-Security-Best-Practices: S3.8
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•CIS-2.0: 2.1.4
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•NIST-CSF-2.0: ac_3
•CIS-5.0: 2.1.4
•AWS-Account-Security-Onboarding: S3 Block Public Access
•CIS-3.0: 2.1.4
•CIS-6.0: 3.1.4
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Logging.CN05.AR01
•SecNumCloud-3.2: 9.7
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•CIS-4.0.1: 2.1.4
|
| FAIL |
low |
s3 |
us-east-1 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_lifecycle_enabled |
S3 bucket has a lifecycle configuration enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas does not have a lifecycle configuration enabled. |
Without lifecycle rules, objects persist indefinitely, driving costs and retaining sensitive data beyond policy. Unchecked log/version growth strains operations and recovery. Long-lived data increases exposure if the account is compromised and can break required deletion timelines, affecting confidentiality and availability. |
Define Lifecycle policies by data classification: set Expiration to enforce retention, use Transitions to lower-cost classes, and enable AbortIncompleteMultipartUpload. For critical logs, keep versioning and, if required, Object Lock. Limit who can change lifecycle using least privilege and separation of duties. |
•AWS-Foundational-Security-Best-Practices: S3.13
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-32.02B
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•NIST-CSF-2.0: ds_3, ds_4
•PCI-4.0: 10.5.1.12, 10.5.1.13, 3.2.1.8, 3.2.1.9, 3.3.1.1.8, 3.3.1.1.9, 3.3.1.3.8, 3.3.1.3.9, 3.3.2.8, 3.3.2.9, 3.3.3.8, 3.3.3.9
•CCC-v2025.10: CCC.AuditLog.CN06.AR01
•PCI-3.2.1: 3.1, 3.1.a, 3.2, 3.2.c, 10.7, 10.7.a
•ISO27001-2022: A.8.10
•NIS2: 12.2.2.a
|
| FAIL |
medium |
s3 |
us-east-1 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_no_mfa_delete |
S3 bucket has MFA Delete enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has MFA Delete disabled. |
Without MFA Delete, a compromised or over-privileged identity can irrevocably purge object history or change versioning.
This erases recovery points, degrading data availability, weakening integrity, and increasing the blast radius of account compromise or ransomware. |
Enable MFA Delete on sensitive, versioned buckets so permanent deletions and Versioning changes require a second factor. Apply least privilege to restrict version purge actions, enforce change control, and combine with Object Lock or immutable backups for defense in depth. |
•CIS-7.0: 3.1.2
•CIS-1.4: 2.1.3
•CIS-1.5: 2.1.3
•MITRE-ATTACK: T1485
•AWS-Foundational-Security-Best-Practices: S3.20
•KISA-ISMS-P-2023: 2.5.3, 2.10.2
•C5-2025: AM-07.02B, OPS-16.01B, IAM-04.06B, IAM-09.02B, IAM-09.01AC, PSS-05.01B, PSS-07.02B
•CIS-2.0: 2.1.2
•KISA-ISMS-P-2023-korean: 2.5.3, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP02
•CIS-5.0: 2.1.2
•PCI-4.0: 10.3.2.22, 3.5.1.3.27, 8.4.1.5, 8.4.2.5, 8.4.3.5, A1.1.2.18, A3.4.1.20
•CIS-3.0: 2.1.2
•CIS-6.0: 3.1.2
•CCC-v2025.10: CCC.ObjStor.CN07.AR01, CCC.ObjStor.CN07.AR02, CCC.ObjStor.CN07.AR03
•ProwlerThreatScore-1.0: 2.2.1
•CIS-4.0.1: 2.1.2
•NIS2: 11.7.2
|
| FAIL |
low |
s3 |
us-east-1 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
low |
s3 |
us-east-2 |
s3_bucket_object_lock |
S3 bucket has Object Lock enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has Object Lock disabled. |
Without Object Lock, object versions can be deleted or overwritten, undermining data integrity and availability.
Threats include ransomware erasing backups, insider or mistaken deletions, and tampering that defeats recovery. Inability to enforce retention or legal holds increases exposure to data loss and compliance gaps. |
Enable Object Lock for critical data and set appropriate default retention in GOVERNANCE or COMPLIANCE mode.
Apply immutability and least privilege by restricting permissions that bypass retention, and use legal holds when you need indefinite protection for investigations or regulatory requirements. |
•SOC2: pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.15
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•PCI-4.0: 10.3.4.7
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.AuditLog.CN08.AR01, CCC.Logging.CN03.AR01, CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN03.AR02, CCC.ObjStor.CN04.AR01, CCC.ObjStor.CN04.AR02
|
| FAIL |
medium |
s3 |
us-east-1 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has versioning enabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_object_versioning |
S3 bucket has object versioning enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has versioning disabled. |
Without versioning, deletions and overwrites remove the only copy, undermining availability and integrity.
- Compromised identities or buggy apps can mass-delete/corrupt data
- No historical versions means limited rollback and irrecoverable loss |
Enable S3 versioning for buckets holding important or shared data.
- Enforce least privilege to limit delete/overwrite
- Use Object Lock and/or MFA Delete for stronger protection
- Apply lifecycle rules to manage noncurrent versions and costs
- Layer with backups/replication for defense in depth |
•CISA: your-systems-3, your-data-4, booting-up-thing-to-do-first-1
•SOC2: cc_7_4, cc_a_1_1, cc_c_1_2, pi_1_5
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.14
•KISA-ISMS-P-2023: 2.9.3, 2.12.1
•C5-2025: OPS-13.01AC, OPS-33.02B, DEV-07.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_7_i, 164_308_a_7_ii_a, 164_308_a_7_ii_b, 164_308_a_7_ii_c, 164_312_a_2_ii, 164_312_c_1, 164_312_c_2
•KISA-ISMS-P-2023-korean: 2.9.3, 2.12.1
•GxP-21-CFR-Part-11: 11.10-a, 11.10-c
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 5-data, 7.1-data-storage-damage-protection, 7.2-data-storage-backups, 16-business-continuity, 17-archiving, 4.8-validation-data-transfer
•NIST-800-171-Revision-2: 3_3_8
•ASD-Essential-Eight-Nov 2023: E8-8.2
•PCI-4.0: 10.3.4.9
•NIST-800-53-Revision-4: cp_10, si_12
•NIST-800-53-Revision-5: au_9_2, cp_1_2, cp_2_5, cp_6_a, cp_6_1, cp_6_2, cp_9_a, cp_9_b, cp_9_c, cp_10, cp_10_2, pm_11_b, pm_17_b, sc_5_2, sc_16_1, si_1_a_2, si_13_5
•NIST-CSF-1.1: be_5, ds_4, ip_4, ip_9, pt_5, rp_1, rp_1
•AWS-Audit-Manager-Control-Tower-Guardrails: 5.1.1
•CCC-v2025.10: CCC.ObjStor.CN03.AR01, CCC.ObjStor.CN05.AR01, CCC.ObjStor.CN05.AR02, CCC.ObjStor.CN05.AR03, CCC.ObjStor.CN05.AR04
•SecNumCloud-3.2: 12.5, 17.6
•RBI-Cyber-Security-Framework: annex_i_12
•FFIEC: d5-ir-pl-b-6
•PCI-3.2.1: 3.1, 3.1.c, 10.5, 10.5.2, 10.5.3, 10.5.5
•ISO27001-2022: A.8.3, A.8.10
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: au-9-2, cp-9-b, cp-10, sc-5, si-12
•FedRAMP-Low-Revision-4: au-9, cp-9, cp-10, sc-5
|
| PASS |
critical |
s3 |
us-east-1 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 public access blocked at bucket level for config-bucket-716468089330. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 public access blocked at bucket level for aws-cloudtrail-logs-716468089330-fb4a4f88. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::maciedata1902 |
|
S3 public access blocked at bucket level for maciedata1902. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::scrivas-access-logs |
|
S3 public access blocked at bucket level for scrivas-access-logs. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 public access blocked at bucket level for scrivas-tf-statefile. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 public access blocked at bucket level for scrivasbackendstorage. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have a bucket policy. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::scrivasloggsbucket |
|
S3 public access blocked at bucket level for scrivasloggsbucket. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_policy_public_write_access |
S3 bucket policy does not allow public write access |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 public access blocked at bucket level for vulnerability-reports-scrivas. |
Public write access lets anyone upload, overwrite, or delete objects, undermining integrity and availability. Attackers can plant malware, stage phishing content, poison data, or wipe buckets, causing outages and potential legal and cost impacts from storage abuse and content hosting. |
Restrict writes to trusted principals using least privilege; avoid Principal: "*". Enable Public Access Block at account and bucket levels for defense in depth. Prefer IAM roles over broad bucket policies, require private access paths, and enable versioning to recover from unwanted changes. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 2.21
•MITRE-ATTACK: T1485, T1486
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•ENS-RD2022: op.acc.4.aws.iam.1, op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.2
•CCC-v2025.10: CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR02
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.15
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-1 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_access |
S3 bucket is not publicly accessible to Everyone or Authenticated Users |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas is not public. |
Publicly accessible buckets jeopardize confidentiality through unauthenticated reads, integrity through write or ACL changes, and availability via object deletion or overwrite. Attackers can mass-exfiltrate data, host malware, or pivot after discovering secrets stored in objects. |
Enforce defense in depth: enable S3 Block Public Access at org/account and bucket levels (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets). Apply least privilege with explicit principals; avoid ACLs via Object Ownership. Use private access patterns (e.g., CloudFront OAC or presigned URLs) and monitor with analyzers. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_6_1
•MITRE-ATTACK: T1530
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_3_i, 164_312_a_1, 164_312_a_2_i
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.10-d, 11.10-g, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•NIST-CSF-2.0: ra_1, ac_3, ds_5, ip_1
•NIST-800-171-Revision-2: 3_1_1, 3_1_2, 3_1_3, 3_3_8, 3_4_6, 3_13_2, 3_13_5
•PCI-4.0: 1.2.8.33, 1.2.8.34, 1.3.1.37, 1.3.1.38, 1.3.2.37, 1.3.2.38, 1.4.2.35, 1.4.2.36, 1.5.1.33, 1.5.1.34, 10.3.2.21, 10.3.2.23, 10.3.3.23, 10.3.4.8, 3.5.1.3.26, 3.5.1.3.28, A1.1.2.17, A1.1.2.19, A1.1.3.33, A1.1.3.34, A1.2.1.31, A3.4.1.19, A3.4.1.21
•NIST-800-53-Revision-4: ac_3, ac_4, ac_6, ac_21, sc_7_3, sc_7
•NIST-800-53-Revision-5: ac_2_6, ac_3, ac_3_7, ac_4_21, ac_6, ac_17_b, ac_17_1, ac_17_4_a, ac_17_9, ac_17_10, cm_6_a, cm_9_b, mp_2, sc_7_2, sc_7_3, sc_7_7, sc_7_9_a, sc_7_11, sc_7_12, sc_7_16, sc_7_20, sc_7_21, sc_7_24_b, sc_7_25, sc_7_26, sc_7_27, sc_7_28, sc_7_a, sc_7_b, sc_7_c, sc_25
•AWS-Account-Security-Onboarding: S3 Block Public Access
•ENS-RD2022: op.exp.8.r4.aws.ct.2
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ac_3, ac_5, ds_5, ip_8, pt_3
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-im-b-1
•ISO27001-2022: A.8.1
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-3, ac-4, ac-6, ac-17-1, ac-21-b, cm-2, sc-4, sc-7-3, sc-7
•FedRAMP-Low-Revision-4: ac-3, ac-17, cm-2, sc-7
|
| PASS |
critical |
s3 |
us-east-1 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_list_acl |
S3 bucket is not publicly listable by Everyone or any authenticated AWS user |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas is not publicly listable. |
Public listability reveals object names, counts, and structure, enabling reconnaissance and targeted scraping. READ_ACP exposes permission details for further abuse. With FULL_CONTROL, attackers could alter ACLs and disrupt access, undermining confidentiality and risking integrity and availability. |
Enable account-level S3 Block Public Access (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets).
- Remove ACL grants to AllUsers/AuthenticatedUsers; apply least privilege with IAM/bucket policies.
- Favor private patterns (VPC endpoints, CloudFront OAC, presigned URLs) and disable ACLs via Object Ownership. |
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ds_5
•AWS-Foundational-Technical-Review: S3-001
•AWS-Audit-Manager-Control-Tower-Guardrails: 4.1.1
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•ProwlerThreatScore-1.0: 2.2.16
|
| PASS |
critical |
s3 |
us-east-1 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| PASS |
critical |
s3 |
us-east-2 |
s3_bucket_public_write_acl |
S3 bucket ACL does not grant write access to Everyone or any AWS customer |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas is not publicly writable. |
Public or cross-account writes enable object tampering, log poisoning, and ACL changes via WRITE_ACP, undermining integrity and causing covert data exposure. Attackers can plant malware, deface content, and inflate costs, impacting availability through overwrites or prefix flooding. |
Apply least privilege to S3 writes. Enable account-level Block Public Access and use Object Ownership to disable ACLs. Grant write only to fixed principals via bucket policies with tight conditions (e.g., org IDs, VPC endpoints). Add versioning and monitoring for defense-in-depth. |
•AWS-Foundational-Security-Best-Practices: S3.3
•KISA-ISMS-P-2023: 2.5.6, 2.6.2, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.6.2, 2.10.2
•NIST-CSF-2.0: ra_1, ds_5
•PCI-4.0: 1.2.8.35, 1.3.1.39, 1.3.2.39, 1.4.2.37, 1.5.1.35, 10.3.2.24, 3.5.1.3.29, A1.1.2.20, A1.1.3.35, A3.4.1.22
•AWS-Foundational-Technical-Review: S3-001
•CCC-v2025.10: CCC.Core.CN05.AR01, CCC.AuditLog.CN10.AR01, CCC.AuditLog.CN10.AR02, CCC.Logging.CN05.AR01, CCC.Logging.CN05.AR02
•PCI-3.2.1: 1.2, 1.2.1, 1.2.1.a, 1.2.1.b, 1.2.1.c, 1.3, 1.3.1, 1.3.2, 1.3.4, 1.3.6, 7.2, 7.2.1
•ProwlerThreatScore-1.0: 2.2.17
|
| FAIL |
medium |
s3 |
us-east-1 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has a bucket policy to deny requests over insecure transport. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb does not have a bucket policy, thus it allows HTTP requests. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| FAIL |
medium |
s3 |
us-east-2 |
s3_bucket_secure_transport_policy |
S3 bucket policy denies requests over insecure transport |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas allows requests over insecure transport in the bucket policy. |
HTTP access exposes object data and auth details to eavesdropping and man-in-the-middle attacks. Captured pre-signed URLs can be replayed to exfiltrate data. Traffic can be intercepted or altered, undermining confidentiality and integrity of S3 content. |
Enforce HTTPS-only access with a bucket policy that denies requests when aws:SecureTransport=false.
Prefer private access (VPC endpoints or CloudFront with TLS), avoid S3 website endpoints, apply least privilege, use short-lived HTTPS pre-signed URLs, and monitor logs for insecure access attempts. |
•CISA: your-systems-3, your-data-2
•CIS-7.0: 3.1.1
•CIS-1.4: 2.1.2
•CIS-1.5: 2.1.2
•MITRE-ATTACK: T1040
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: S3.5
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•HIPAA: 164_308_a_1_ii_b, 164_312_a_2_iv, 164_312_c_1, 164_312_c_2, 164_312_e_1, 164_312_e_2_i, 164_312_e_2_ii
•CIS-2.0: 2.1.1
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•GxP-21-CFR-Part-11: 11.10-c, 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC09-BP02
•NIST-CSF-2.0: ds_2, pt_4
•CIS-5.0: 2.1.1
•NIST-800-171-Revision-2: 3_1_13, 3_5_10, 3_13_1, 3_13_5, 3_13_8, 3_13_11, 3_13_16
•PCI-4.0: 1.2.5.15, 2.2.5.15, 2.2.7.19, 4.2.1.1.27, 4.2.1.19, 8.3.2.49
•NIST-800-53-Revision-4: ac_17_2, sc_7, sc_8_1, sc_8
•NIST-800-53-Revision-5: ac_4, ac_4_22, ac_17_2, ac_24_1, au_9_3, ca_9_b, cm_6_a, cm_9_b, ia_5_1_c, pm_11_b, pm_17_b, sc_7_4_b, sc_7_4_g, sc_7_5, sc_8, sc_8_1, sc_8_2, sc_8_3, sc_8_4, sc_8_5, sc_13_a, sc_16_1, sc_23, si_1_a_2
•CIS-3.0: 2.1.1
•ENS-RD2022: mp.com.1.aws.s3.1, mp.com.3.aws.s3.1
•CIS-6.0: 3.1.1
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ds_2
•CCC-v2025.10: CCC.Core.CN01.AR01, CCC.Core.CN01.AR03
•SecNumCloud-3.2: 10.2
•RBI-Cyber-Security-Framework: annex_i_1_3
•FFIEC: d3-pc-am-b-12, d3-pc-am-b-13, d3-pc-am-b-15
•ProwlerThreatScore-1.0: 4.1.1
•AWS-AI-Security-Framework-1.0: AISF-INFRA-06, AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-17-2, sc-7, sc-8-1, sc-8, sc-23
•FedRAMP-Low-Revision-4: ac-17, sc-7
•CIS-4.0.1: 2.1.1
•FedRAMP-20x-KSI-Low-25.05C: ksi-svc
|
| PASS |
medium |
s3 |
us-east-1 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::config-bucket-716468089330 |
|
S3 Bucket config-bucket-716468089330 has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::aws-cloudtrail-logs-716468089330-fb4a4f88 |
|
S3 Bucket aws-cloudtrail-logs-716468089330-fb4a4f88 has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::maciedata1902 |
|
S3 Bucket maciedata1902 has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::scrivas-access-logs |
|
S3 Bucket scrivas-access-logs has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::scrivas-tf-statefile |
•Purpose=terraform-backend
•ManagedBy=terraform
|
S3 Bucket scrivas-tf-statefile has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::scrivasbackendstorage |
•Project = =scrivas Service
|
S3 Bucket scrivasbackendstorage has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::scrivasbackupsdb |
|
S3 Bucket scrivasbackupsdb has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::scrivasloggsbucket |
|
S3 Bucket scrivasloggsbucket has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
s3 |
us-east-2 |
s3_bucket_server_access_logging_enabled |
S3 bucket has server access logging enabled |
arn:aws:s3:::vulnerability-reports-scrivas |
|
S3 Bucket vulnerability-reports-scrivas has server access logging enabled. |
Without access logs, object reads, writes, and deletions may go untracked, hindering detection of unauthorized access and data exfiltration. This degrades forensic visibility, delays incident response, and weakens evidence integrity, impacting confidentiality and integrity. |
Enable server access logging and send logs to a dedicated log bucket with least privilege, retention, and monitoring. Complement with CloudTrail data events for object-level visibility. Apply defense in depth by centralizing logs and protecting them from tampering. |
•CISA: your-systems-3, your-data-2
•SOC2: cc_7_2, cc_7_3, cc_a_1_1
•AWS-Foundational-Security-Best-Practices: S3.9
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, IAM-06.04B, IAM-07.04B, IAM-10.01B, SSO-05.01AC, PSS-04.05B
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_e_2_i
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e, 11.10-k
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_2, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.30, 10.2.1.2.27, 10.2.1.3.27, 10.2.1.4.27, 10.2.1.5.27, 10.2.1.6.27, 10.2.1.7.27, 10.2.1.27, 10.2.2.27, 10.3.1.27, 10.6.3.34, 5.3.4.32, A1.2.1.32
•NIST-800-53-Revision-4: ac_2, au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_2_4, ac_3_1, ac_3_10, ac_4_26, ac_6_9, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_3_f, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_10, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, sc_7_9_b, si_1_1_c, si_3_8_b, si_4_2, si_4_17, si_4_20, si_7_8, si_10_1_c
•AWS-Foundational-Technical-Review: S3-001
•NIST-CSF-1.1: ae_1, ae_3, ae_4, cm_1, cm_3, cm_6, cm_7, am_3, ac_6, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR03, CCC.AuditLog.CN04.AR01
•SecNumCloud-3.2: 12.6
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d5-dr-de-b-3
•PCI-3.2.1: 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.6, 10.2.7, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.5, 10.5.4
•ISO27001-2022: A.8.15
•AWS-AI-Security-Framework-1.0: AISF-DATA-04
•FedRamp-Moderate-Revision-4: ac-2-4, ac-2-g, au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: ac-2, au-2
•NIS2: 1.1.1.h, 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| FAIL |
low |
sagemaker |
us-east-1 |
sagemaker_clarify_exists |
Amazon SageMaker Clarify processing jobs exist in the region |
arn:aws:sagemaker:us-east-1:716468089330:processing-job |
|
No SageMaker Clarify processing jobs found in region us-east-1. |
Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
- Regulatory non-compliance with AI governance frameworks
- Undetected bias in model predictions affecting protected groups
- Lack of accountability for ML model decisions in production |
Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices. |
|
| FAIL |
low |
sagemaker |
us-east-2 |
sagemaker_clarify_exists |
Amazon SageMaker Clarify processing jobs exist in the region |
arn:aws:sagemaker:us-east-2:716468089330:processing-job |
|
No SageMaker Clarify processing jobs found in region us-east-2. |
Without SageMaker Clarify processing jobs, ML models may be deployed without bias analysis or explainability reports. This can lead to:
- Regulatory non-compliance with AI governance frameworks
- Undetected bias in model predictions affecting protected groups
- Lack of accountability for ML model decisions in production |
Create SageMaker Clarify processing jobs to evaluate models for bias and explainability before deployment. Integrate Clarify into your ML pipeline to ensure responsible AI practices. |
|
| FAIL |
low |
sagemaker |
us-east-1 |
sagemaker_models_monitor_enabled |
Amazon SageMaker has a monitoring schedule scheduled |
arn:aws:sagemaker:us-east-1:716468089330:monitoring-schedule/unknown |
|
No SageMaker monitoring schedules found in region us-east-1. |
Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model. |
Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline. |
|
| FAIL |
low |
sagemaker |
us-east-2 |
sagemaker_models_monitor_enabled |
Amazon SageMaker has a monitoring schedule scheduled |
arn:aws:sagemaker:us-east-2:716468089330:monitoring-schedule/unknown |
|
No SageMaker monitoring schedules found in region us-east-2. |
Without an active monitoring schedule, data drift, model quality issues, and bias drift go undetected, so model quality degrades silently while downstream decisions such as fraud detection, access control, and pricing keep relying on a degrading model. |
Enable Amazon SageMaker Model Monitor and keep at least one monitoring schedule in the Scheduled state so data quality, model quality, and bias drift are continuously evaluated against a baseline. |
|
| FAIL |
low |
sagemaker |
us-east-1 |
sagemaker_models_registry_in_use |
Amazon SageMaker Model Registry should have at least one approved model package |
arn:aws:sagemaker:us-east-1:716468089330:model-registry/unknown |
|
SageMaker Model Registry in region us-east-1 has no Model Package Groups. |
An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows. |
Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration. |
•AWS-AI-Security-Framework-1.0: AISF-ML-04
|
| FAIL |
low |
sagemaker |
us-east-2 |
sagemaker_models_registry_in_use |
Amazon SageMaker Model Registry should have at least one approved model package |
arn:aws:sagemaker:us-east-2:716468089330:model-registry/unknown |
|
SageMaker Model Registry in region us-east-2 has no Model Package Groups. |
An empty Model Registry, or one with no approved packages, indicates that models are being deployed outside any review process. This breaks provenance and accountability for production ML workloads, making it impossible to enforce governance controls such as auditing, versioning, and approval workflows. |
Register all production models in the SageMaker Model Registry and enforce an approval workflow before deployment. Ensure at least one model package per group reaches Approved status. Use IAM policies to restrict who can approve model packages and integrate with CI/CD pipelines to automate registration. |
•AWS-AI-Security-Framework-1.0: AISF-ML-04
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz |
|
SecretsManager secret ScrivasML_post_processor_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc |
|
SecretsManager secret ScrivasML_post_processor_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC |
|
SecretsManager secret ScrivasML_post_processor_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 |
|
SecretsManager secret ScrivasML_patient_summary_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a |
|
SecretsManager secret ScrivasML_patient_summary_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF |
|
SecretsManager secret ScrivasML_patient_summary_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj |
|
SecretsManager secret ScrivasML_patient_document_parser_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD |
|
SecretsManager secret ScrivasML_patient_document_parser_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib |
|
SecretsManager secret ScrivasML_patient_document_parser_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF |
|
SecretsManager secret ScrivasML_sai_suggestions_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl |
|
SecretsManager secret ScrivasML_soniox_transcriber_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD |
|
SecretsManager secret ScrivasML_sai_suggestions_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq |
|
SecretsManager secret ScrivasML_sai_suggestions_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX |
|
SecretsManager secret ScrivasML_soniox_transcriber_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT |
|
SecretsManager secret ScrivasML_soniox_transcriber_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw |
|
SecretsManager secret ScrivasML_Monitoring_Dev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU |
|
SecretsManager secret ScrivasML_Monitoring_Stage has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 |
|
SecretsManager secret ScrivasML_Monitoring_Prod has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_automatic_rotation_enabled |
Secrets Manager secret has rotation enabled |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 |
|
SecretsManager secret ScrivasBKPatientDev has rotation disabled. |
Absent rotation, long-lived secrets widen the attack window:
- Valid after leakage in code, images, or logs
- Enable unauthorized access and lateral movement
- Complicate incident response and recovery
This impacts confidentiality and integrity, and can threaten availability if revocation lags. |
Enable automatic rotation for secrets and set schedules based on sensitivity (e.g., 30-90 days). Enforce least privilege for accessing and rotating secrets and apply separation of duties. Monitor rotation health. Avoid hardcoded credentials; retrieve secrets at runtime and support versioned updates. |
•CISA: your-systems-3
•MITRE-ATTACK: T1552
•AWS-Foundational-Security-Best-Practices: SecretsManager.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: CRY-06.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B
•HIPAA: 164_308_a_4_ii_c
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.10-d, 11.10-g, 11.300-b
•AWS-Well-Architected-Framework-Security-Pillar: SEC02-BP05
•NIST-CSF-2.0: ip_7
•PCI-4.0: 3.5.1.34, 8.2.2.8, 8.2.2.9, 8.2.2.10, 8.3.10.1.2, 8.3.10.1.3, 8.3.10.1.4, 8.3.2.53, 8.3.5.2, 8.3.5.3, 8.3.5.4, 8.3.7.2, 8.3.7.3, 8.3.7.4, 8.3.9.2, 8.3.9.3, 8.3.9.4, 8.6.3.3, 8.6.3.4, 8.6.3.5
•NIST-800-53-Revision-5: ac_2_1, ac_3_3, ac_3_3_a, ac_3_3_b_1, ac_3_3_b_2, ac_3_3_b_3, ac_3_3_b_4, ac_3_3_b_5, ac_3_3_c, ac_3_4, ac_3_4_a, ac_3_4_b, ac_3_4_c, ac_3_4_d, ac_3_4_e, ac_3_8, ac_3_12_a, ac_3_13, ac_3_15_a, ac_3_15_b, ac_4_28, ac_24, cm_5_1_a, sc_23_3
•NIST-CSF-1.1: ac_1
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv, 11.6.2.c
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz |
|
SecretsManager secret 'ScrivasML_post_processor_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc |
|
SecretsManager secret 'ScrivasML_post_processor_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC |
|
SecretsManager secret 'ScrivasML_post_processor_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 |
|
SecretsManager secret 'ScrivasML_patient_summary_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a |
|
SecretsManager secret 'ScrivasML_patient_summary_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF |
|
SecretsManager secret 'ScrivasML_patient_summary_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj |
|
SecretsManager secret 'ScrivasML_patient_document_parser_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD |
|
SecretsManager secret 'ScrivasML_patient_document_parser_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib |
|
SecretsManager secret 'ScrivasML_patient_document_parser_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF |
|
SecretsManager secret 'ScrivasML_sai_suggestions_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl |
|
SecretsManager secret 'ScrivasML_soniox_transcriber_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD |
|
SecretsManager secret 'ScrivasML_sai_suggestions_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq |
|
SecretsManager secret 'ScrivasML_sai_suggestions_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX |
|
SecretsManager secret 'ScrivasML_soniox_transcriber_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT |
|
SecretsManager secret 'ScrivasML_soniox_transcriber_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw |
|
SecretsManager secret 'ScrivasML_Monitoring_Dev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU |
|
SecretsManager secret 'ScrivasML_Monitoring_Stage' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 |
|
SecretsManager secret 'ScrivasML_Monitoring_Prod' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
high |
secretsmanager |
us-east-2 |
secretsmanager_has_restrictive_resource_policy |
Secrets Manager secret has a restrictive resource-based policy |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 |
|
SecretsManager secret 'ScrivasBKPatientDev' does not have a resource-based policy or access to the policy is denied for the role 'arn:aws:iam::716468089330:user/louis' |
Without a restrictive resource policy, any IAM principal in the account—or even cross-account entities—can read, modify, or delete the secret, compromising confidentiality and integrity. Overly broad policies enable lateral movement and privilege escalation through exposed credentials. |
Apply deny-by-default resource policies to every secret:
- Deny all principals except explicitly authorized roles via StringNotEquals on aws:PrincipalArn
- Deny access from outside the AWS Organization via aws:PrincipalOrgID
- Constrain AWS service access with aws:SourceAccount (additional restrictive conditions like ArnLike are accepted)
- Optionally, restrict each authorized principal to least-privilege actions using per-principal Deny/NotAction statements (defense-in-depth) |
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz |
|
Secret ScrivasML_post_processor_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc |
|
Secret ScrivasML_post_processor_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC |
|
Secret ScrivasML_post_processor_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 |
|
Secret ScrivasML_patient_summary_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a |
|
Secret ScrivasML_patient_summary_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF |
|
Secret ScrivasML_patient_summary_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj |
|
Secret ScrivasML_patient_document_parser_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD |
|
Secret ScrivasML_patient_document_parser_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib |
|
Secret ScrivasML_patient_document_parser_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF |
|
Secret ScrivasML_sai_suggestions_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl |
|
Secret ScrivasML_soniox_transcriber_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD |
|
Secret ScrivasML_sai_suggestions_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq |
|
Secret ScrivasML_sai_suggestions_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX |
|
Secret ScrivasML_soniox_transcriber_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT |
|
Secret ScrivasML_soniox_transcriber_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw |
|
Secret ScrivasML_Monitoring_Dev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU |
|
Secret ScrivasML_Monitoring_Stage has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 |
|
Secret ScrivasML_Monitoring_Prod has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| FAIL |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_rotated_periodically |
AWS Secrets Manager secret is rotated within the configured maximum number of days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 |
|
Secret ScrivasBKPatientDev has never been rotated. |
Long-lived or never-rotated secrets widen the attack window. Leaked or brute-forced credentials stay valid, enabling unauthorized access to databases and APIs, data exfiltration, and unauthorized changes-compromising confidentiality and integrity. |
Enable automatic rotation for all secrets with intervals aligned to sensitivity (90 days or more frequent). Ensure apps retrieve secrets at runtime. Apply least privilege to rotation roles and KMS keys, use separation of duties**, and monitor rotation health with alerts. Avoid hard-coded credentials and retire unused secrets. |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.07B, IAM-08.05B, CRY-06.01B, CRY-07.01B, CRY-09.02B, CRY-10.01AC, CRY-11.01B, CRY-14.01B, CRY-16.01B, DEV-07.01B, DEV-12.02B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•NIST-CSF-2.0: ip_7
•CCC-v2025.10: CCC.SecMgmt.CN01.AR01
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 1.1.1.d, 1.1.2, 2.1.2.f, 2.1.4, 2.2.3, 2.3.1, 3.1.3, 6.2.4, 9.2.c, 9.2.c.iv, 11.6.2.c
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Dev-JZghEz |
|
Secret ScrivasML_post_processor_Dev has been accessed recently, last accessed on August 17, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Stage-JaNIJc |
|
Secret ScrivasML_post_processor_Stage has been accessed recently, last accessed on August 16, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_post_processor_Prod-rirMpC |
|
Secret ScrivasML_post_processor_Prod has been accessed recently, last accessed on August 16, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Dev-2aDqS4 |
|
Secret ScrivasML_patient_summary_Dev has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Stage-4Jmx8a |
|
Secret ScrivasML_patient_summary_Stage has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_summary_Prod-3KOgFF |
|
Secret ScrivasML_patient_summary_Prod has been accessed recently, last accessed on August 13, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Dev-L4lQkj |
|
Secret ScrivasML_patient_document_parser_Dev has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Stage-1VNUOD |
|
Secret ScrivasML_patient_document_parser_Stage has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_patient_document_parser_Prod-Oj0Pib |
|
Secret ScrivasML_patient_document_parser_Prod has been accessed recently, last accessed on August 13, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Dev-mTx0UF |
|
Secret ScrivasML_sai_suggestions_Dev has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Dev-3pZpJl |
|
Secret ScrivasML_soniox_transcriber_Dev has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Stage-qm39mD |
|
Secret ScrivasML_sai_suggestions_Stage has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_sai_suggestions_Prod-8KXhSq |
|
Secret ScrivasML_sai_suggestions_Prod has been accessed recently, last accessed on August 13, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Stage-ZUIyYX |
|
Secret ScrivasML_soniox_transcriber_Stage has been accessed recently, last accessed on August 12, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_soniox_transcriber_Prod-Dd5vmT |
|
Secret ScrivasML_soniox_transcriber_Prod has been accessed recently, last accessed on August 13, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Dev-boCWWw |
|
Secret ScrivasML_Monitoring_Dev has been accessed recently, last accessed on July 19, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Stage-2nXCqU |
|
Secret ScrivasML_Monitoring_Stage has been accessed recently, last accessed on July 19, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasML_Monitoring_Prod-th9cV4 |
|
Secret ScrivasML_Monitoring_Prod has been accessed recently, last accessed on July 19, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| PASS |
medium |
secretsmanager |
us-east-2 |
secretsmanager_secret_unused |
Secrets Manager secret has been accessed within the last 90 days |
arn:aws:secretsmanager:us-east-2:716468089330:secret:ScrivasBKPatientDev-oTktB9 |
|
Secret ScrivasBKPatientDev has been accessed recently, last accessed on July 29, 2026. |
Unused yet valid secrets jeopardize confidentiality and integrity:
- Reuse by ex-users or leaked code enables unauthorized access
- Limited rotation/revocation increases stealth persistence and data exfiltration
- Secret sprawl adds operational risk and extra cost |
Apply a lifecycle policy for secrets:
- Require ownership tags and periodic reviews
- Rotate or disable, then retire secrets unused beyond policy
- Enforce least privilege and monitor retrievals with alerts
- Automate cleanup using recovery windows to prevent accidental loss |
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: IAM-03.02B, CRY-06.01B, CRY-10.01AC, CRY-11.01B
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•PCI-4.0: 7.2.4.3, 7.2.5.1.3, 8.2.2.11, 8.2.6.3, A3.4.1.24
•SecNumCloud-3.2: 10.5
•AWS-AI-Security-Framework-1.0: AISF-DATA-03
•NIS2: 9.2.c.iv
|
| FAIL |
high |
securityhub |
us-east-1 |
securityhub_delegated_admin_enabled_all_regions |
Security Hub has delegated admin configured and is enabled in all regions with organization auto-enable |
arn:aws:securityhub:us-east-1:716468089330:hub/default |
|
Security Hub in region us-east-1 has issues: no delegated administrator configured. |
Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization. |
Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization. |
|
| FAIL |
high |
securityhub |
us-east-2 |
securityhub_delegated_admin_enabled_all_regions |
Security Hub has delegated admin configured and is enabled in all regions with organization auto-enable |
arn:aws:securityhub:us-east-2:716468089330:hub/default |
|
Security Hub in region us-east-2 has issues: no delegated administrator configured. |
Without org-wide AWS Security Hub configuration, findings can be aggregated inconsistently, delegated admin may be missing in some regions, and new accounts will not be auto-enrolled. This fragments security posture visibility, delays incident response, and lets misconfigurations and compliance drift go undetected across the organization. |
Configure a delegated administrator for AWS Security Hub via AWS Organizations. Enable Security Hub in all opted-in regions and turn on auto-enable so new member accounts are automatically enrolled. This ensures uniform security posture monitoring across the entire organization. |
|
| PASS |
high |
securityhub |
us-east-1 |
securityhub_enabled |
Security Hub is enabled with standards or integrations configured |
arn:aws:securityhub:us-east-1:716468089330:hub/default |
|
Security Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices . |
Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions. |
- Enable in all required accounts/Regions
- Turn on relevant standards (
AWS FSBP, CIS)
- Connect AWS and third-party integrations
- Use central configuration and least privilege
- Automate triage and monitor continuously for defense in depth
|
•CISA: your-systems-3, your-crisis-response-2
•CIS-7.0: 5.16
•SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4
•CIS-1.5: 4.16
•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i
•CIS-2.0: 4.16
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•GxP-EU-Annex-11: 1-risk-management
•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3
•CIS-5.0: 4.16
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9
•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31
•AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account
•CIS-3.0: 4.16
•ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1
•CIS-6.0: 5.16
•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8
•SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.17
•ISO27001-2022: A.5.1, A.8.23
•AWS-AI-Security-Framework-1.0: AISF-DETECT-04
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4
•CIS-4.0.1: 4.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
securityhub |
us-east-2 |
securityhub_enabled |
Security Hub is enabled with standards or integrations configured |
arn:aws:securityhub:us-east-2:716468089330:hub/default |
|
Security Hub is enabled with standards: cis-aws-foundations-benchmark aws-foundational-security-best-practices . |
Absent Security Hub coverage or standards, security signals are fragmented and control checks don't run. High-risk findings can be missed or delayed, enabling data exfiltration, persistence, and lateral movement. This reduces visibility and undermines confidentiality, integrity, and availability across accounts/Regions. |
- Enable in all required accounts/Regions
- Turn on relevant standards (
AWS FSBP, CIS)
- Connect AWS and third-party integrations
- Use central configuration and least privilege
- Automate triage and monitor continuously for defense in depth
|
•CISA: your-systems-3, your-crisis-response-2
•CIS-7.0: 5.16
•SOC2: cc_3_1, cc_6_8, cc_7_1, cc_7_2, cc_7_3, cc_7_4
•CIS-1.5: 4.16
•MITRE-ATTACK: T1190, T1078, T1098, T1562, T1110, T1530, T1580
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_5_ii_c, 164_308_a_6_i, 164_308_a_6_ii, 164_308_a_8, 164_312_b, 164_312_e_2_i
•CIS-2.0: 4.16
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•GxP-21-CFR-Part-11: 11.300-d
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP04
•GxP-EU-Annex-11: 1-risk-management
•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3
•CIS-5.0: 4.16
•NIST-800-171-Revision-2: 3_1_12, 3_3_1, 3_3_4, 3_3_5, 3_6_1, 3_6_2, 3_11_2, 3_11_3, 3_12_4, 3_13_1, 3_14_1, 3_14_2, 3_14_3, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.31, 10.4.1.1.5, 10.4.1.4, 10.4.2.5, 10.6.3.36, 10.7.1.6, 10.7.2.6, A3.3.1.9, A3.5.1.9
•NIST-800-53-Revision-4: ac_2_1, ac_2_4, ac_2_12, ac_2, ac_17_1, au_6_1, au_6_3, ca_7, sa_10, si_4_2, si_4_4, si_4_5, si_4_16, si_4
•NIST-800-53-Revision-5: au_6_1, au_6_5, au_12_3, au_14_a, au_14_b, ca_2_d, ca_7, ca_7_b, pm_14_a_1, pm_14_b, pm_31
•AWS-Account-Security-Onboarding: Enabled security services, Verify that events are present in SecurityHub aggregated view, Deploy solution to alert on at least critical new findings, Apply SecurityHub Central Configuration for Organization, Enable/disable additional standards and controls, Confirm that findings are being visible in the aggregated view, Ensure that there are no critical (and considered critical) findings present in account
•CIS-3.0: 4.16
•ENS-RD2022: op.exp.7.aws.sh.1, op.mon.2.aws.sh.1, op.mon.3.r1.aws.sh.1, op.mon.3.r2.aws.sh.1
•CIS-6.0: 5.16
•NIST-CSF-1.1: ae_2, ae_4, cm_1, cm_2, cm_3, cm_4, cm_5, cm_6, cm_7, cp_4, ra_1, ra_2, ra_3, ra_5, sc_4, ds_5, ds_8
•SecNumCloud-3.2: 12.9, 16.2, 18.3, 18.4
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-is-is-b-1, d2-ti-ti-b-1, d2-ti-ti-b-2, d2-ti-ti-b-3, d3-dc-an-b-1, d3-dc-an-b-2, d3-dc-ev-b-3, d3-dc-th-b-1, d5-dr-de-b-1, d5-dr-de-b-3
•ProwlerThreatScore-1.0: 3.3.17
•ISO27001-2022: A.5.1, A.8.23
•AWS-AI-Security-Framework-1.0: AISF-DETECT-04
•FedRamp-Moderate-Revision-4: ac-2-1, ac-2-4, ac-2-12-a, ac-2-g, ac-17-1, au-6-1-3, ca-7-a-b, ir-4-1, ir-4-1, ir-6-1, ir-7-1, sa-10, si-4-16, si-4-2, si-4-4, si-4-5, si-4-a-b-c
•FedRAMP-Low-Revision-4: ac-2, ac-17, ca-7, ir-4
•CIS-4.0.1: 4.16
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr
|
| PASS |
high |
sns |
us-east-2 |
sns_subscription_not_using_http_endpoints |
SNS subscription uses an HTTPS endpoint |
arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8 |
|
Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3b49902d-a6fc-477d-b197-cba0893133b8 is using an HTTPS endpoint. |
Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions. |
Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth. |
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: dp_4
•CCC-v2025.10: CCC.Core.CN01.AR01
|
| PASS |
high |
sns |
us-east-2 |
sns_subscription_not_using_http_endpoints |
SNS subscription uses an HTTPS endpoint |
arn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93 |
|
Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:fa7b95a6-191d-4715-961d-eea591cd9d93 is using an HTTPS endpoint. |
Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions. |
Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth. |
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: dp_4
•CCC-v2025.10: CCC.Core.CN01.AR01
|
| PASS |
high |
sns |
us-east-2 |
sns_subscription_not_using_http_endpoints |
SNS subscription uses an HTTPS endpoint |
arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769ab |
|
Subscription arn:aws:sns:us-east-2:716468089330:scrivas-alerts:3cdb10f8-bdf6-4c9b-85dc-b3d7b15769ab is using an HTTPS endpoint. |
Using HTTP leaves SNS deliveries unencrypted, compromising confidentiality via eavesdropping. MITM attackers can modify payloads or headers, damaging integrity, inject malicious content into downstream systems, or capture subscription data for spoofing and unauthorized actions. |
Require HTTPS for all SNS subscription endpoints. Prefer domain-based endpoints, verify SNS message signatures, and apply least privilege. Enforce TLS using IAM conditions like aws:SecureTransport, and use private connectivity (VPC endpoints) where possible for defense in depth. |
•KISA-ISMS-P-2023: 2.7.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.7.1, 2.10.2
•NIST-CSF-2.0: dp_4
•CCC-v2025.10: CCC.Core.CN01.AR01
|
| FAIL |
high |
sns |
us-east-2 |
sns_topics_kms_encryption_at_rest_enabled |
SNS topic is encrypted at rest with KMS |
arn:aws:sns:us-east-2:716468089330:scrivas-alerts |
|
SNS topic scrivas-alerts is not encrypted. |
Without KMS-backed SSE, SNS stores message bodies unencrypted at rest, undermining confidentiality.
Privileged insiders or compromised service components could access plaintext during persistence windows, causing data exposure. You also lose KMS controls such as key policies, rotation, and detailed audit trails. |
Enable server-side encryption on all SNS topics with AWS KMS; prefer customer-managed keys for control.
Apply least privilege on key use, enforce rotation, and monitor key/access logs. Minimize sensitive data in messages and use end-to-end encryption where feasible to add defense in depth. |
•CISA: your-systems-3, your-data-1, your-data-2
•SOC2: pi_1_4
•MITRE-ATTACK: T1530
•GDPR: article_32
•AWS-Foundational-Security-Best-Practices: SNS.1
•KISA-ISMS-P-2023: 2.7.2, 2.10.2
•C5-2025: OIS-08.02B, OPS-31.01B, IAM-07.03B, CRY-01.02AC, CRY-05.01B, CRY-05.02B, CRY-05.01AC, PSS-10.01B, PSS-12.02B
•HIPAA: 164_308_a_1_ii_b, 164_308_a_4_ii_a, 164_312_a_2_iv, 164_312_e_2_ii
•KISA-ISMS-P-2023-korean: 2.7.2, 2.10.2
•GxP-21-CFR-Part-11: 11.30
•AWS-Well-Architected-Framework-Security-Pillar: SEC08-BP04
•GxP-EU-Annex-11: 7.1-data-storage-damage-protection
•NIST-CSF-2.0: be_5
•NIST-800-171-Revision-2: 3_13_11, 3_13_16
•PCI-4.0: 3.5.1.35, 8.3.2.54
•NIST-800-53-Revision-4: sc_28
•NIST-800-53-Revision-5: au_9_3, cp_9_d, sc_8_3, sc_8_4, sc_13_a, sc_28_1
•AWS-Foundational-Technical-Review: SDAT-002
•NIST-CSF-1.1: ds_1
•CCC-v2025.10: CCC.Core.CN02.AR01, CCC.Message.CN01.AR01
•SecNumCloud-3.2: 10.1
•RBI-Cyber-Security-Framework: annex_i_1_3
•PCI-3.2.1: 3.4, 3.4.1, 3.4.1.a, 3.4.1.c, 3.4.a, 3.4.b, 8.2, 8.2.1, 8.2.1.a
•ISO27001-2022: A.8.3, A.8.11, A.8.24
•AWS-AI-Security-Framework-1.0: AISF-INFRA-05
•FedRamp-Moderate-Revision-4: sc-13, sc-28
•FedRAMP-Low-Revision-4: sc-13
•FedRAMP-20x-KSI-Low-25.05C: ksi-inr, ksi-svc
|
| PASS |
high |
sns |
us-east-2 |
sns_topics_not_publicly_accessible |
SNS topic is not publicly accessible |
arn:aws:sns:us-east-2:716468089330:scrivas-alerts |
|
SNS topic scrivas-alerts is not public because its policy only allows access from the account 716468089330. |
Public SNS topics allow anyone or unknown accounts to:
- Subscribe and siphon messages (confidentiality)
- Publish spoofed payloads that alter workflows (integrity)
- Flood messages causing outages and costs (availability)
They also enable cross-account abuse and bypass expected trust boundaries. |
Restrict the topic policy to specific principals and minimal actions:
- Avoid Principal:*
- Allow only needed actions (e.g., sns:Publish)
- Add conditions like aws:SourceArn, aws:SourceAccount, aws:PrincipalOrgID, or sns:Endpoint
Apply least privilege, separate duties, and review policies regularly. |
•CIS-7.0: 2.21
•ISO27001-2013: A.12.6.F, A.13.1.E
•KISA-ISMS-P-2023: 2.5.6, 2.10.2
•C5-2025: PS-03.02B, IAM-10.01B, COS-02.01B
•KISA-ISMS-P-2023-korean: 2.5.6, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC03-BP07
•CCC-v2025.10: CCC.Core.CN05.AR05
•ProwlerThreatScore-1.0: 2.3.1
•ISO27001-2022: A.8.1
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-0055a6b877ba156e7 |
•Name=Ml_prod
|
EC2 managed instance i-0055a6b877ba156e7 is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-010066e6c9027aa6e |
•Name=Scrivas_dev_env
|
EC2 managed instance i-010066e6c9027aa6e is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| FAIL |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-02754e7ae419cd5db |
•Name=Netbird_scrivas
|
EC2 managed instance i-02754e7ae419cd5db is non-compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-046e7fc4677eaa796 |
•Name=ML_stage
|
EC2 managed instance i-046e7fc4677eaa796 is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-067bdb5e3e09fa4bb |
•Name=Scrivas_stage_env
|
EC2 managed instance i-067bdb5e3e09fa4bb is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-073154fb4fa773bbd |
•Name=scrivas_prod_env
|
EC2 managed instance i-073154fb4fa773bbd is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| PASS |
high |
ssm |
us-east-2 |
ssm_managed_compliant_patching |
EC2 managed instance is compliant with Systems Manager patching requirements |
arn:aws:ec2:us-east-2:716468089330:instance/i-095bd68aff22b103b |
•Name=ML_dev
|
EC2 managed instance i-095bd68aff22b103b is compliant. |
Unpatched instances expose known CVE vulnerabilities, enabling remote code execution, privilege escalation, and lateral movement.
This threatens confidentiality (data exfiltration), integrity (unauthorized changes), and availability (ransomware, crypto-mining, outages). |
Adopt automated patch management with Systems Manager: enroll EC2 as managed nodes, define strict patch baselines, run frequent compliance scans, and install critical updates promptly.
Apply defense in depth: least-privileged roles for patching, staged rollouts, maintenance windows, and centralized compliance reporting with alerting. |
•CISA: your-systems-1, your-systems-2, booting-up-thing-to-do-first-3
•SOC2: cc_3_2, cc_7_1
•AWS-Foundational-Security-Best-Practices: SSM.2, SSM.3
•KISA-ISMS-P-2023: 2.10.2, 2.10.8
•C5-2025: OIS-03.06B, OIS-08.09B, OPS-27.01B, OPS-33.01B, OPS-33.02B, OPS-33.03B, OPS-33.01AS, OPS-33.04B
•HIPAA: 164_308_a_5_ii_b
•KISA-ISMS-P-2023-korean: 2.10.2, 2.10.8
•GxP-21-CFR-Part-11: 11.10-a, 11.10-h
•AWS-Well-Architected-Framework-Security-Pillar: SEC06-BP01
•NIST-CSF-2.0: ac_3
•NIST-800-171-Revision-2: 3_4_1, 3_4_2, 3_4_6, 3_4_9, 3_14_2, 3_14_3
•ASD-Essential-Eight-Nov 2023: E8-1.6, E8-2.6, E8-2.7
•PCI-4.0: 11.3.1.1.2, 11.3.1.3.2, 11.3.1.2, 6.3.3.2
•NIST-800-53-Revision-4: cm_2, cm_7, cm_8_3, si_2_2, si_7_1
•NIST-800-53-Revision-5: cm_2_a, cm_2_b, cm_2_b_1, cm_2_b_2, cm_2_b_3, cm_2_2, cm_3_3, cm_6, cm_8_1, cm_8_3_a, cm_8_6, cm_8_a, cm_8_a_1, cm_8_a_2, cm_8_a_3, cm_8_a_4, cm_8_a_5, cm_8_b, ra_3_a_1, si_2_5, si_2_2, si_2_c, si_2_d, si_3_c_2
•ENS-RD2022: op.exp.1.aws.sys.1, op.exp.4.aws.sys.2
•NIST-CSF-1.1: am_2, ra_1, ds_3, ds_7, ip_1, ip_12
•SecNumCloud-3.2: 12.10
•RBI-Cyber-Security-Framework: annex_i_6
•FFIEC: d2-ti-ti-b-2, d3-cc-pm-b-1, d3-cc-pm-b-3, d3-dc-th-b-1, d3-pc-im-b-5
•PCI-3.2.1: 2.2, 2.2.4, 2.2.5, 2.2.5.b, 2.4, 5.1, 5.2, 5.2.c, 6.2, 6.2.b
•ISO27001-2022: A.8.27
•FedRamp-Moderate-Revision-4: cm-2, cm-7-a, cm-8-1, cm-8-3-a, si-2-2, si-7-1
•FedRAMP-Low-Revision-4: cm-2, cm-8
•NIS2: 6.6.1.a
•FedRAMP-20x-KSI-Low-25.05C: ksi-cmt, ksi-tpr
|
| FAIL |
medium |
ssmincidents |
us-east-2 |
ssmincidents_enabled_with_plans |
SSM Incidents replication set is ACTIVE and has at least one response plan |
arn:aws:ssm-incidents:us-east-2:716468089330:replication-set |
|
No SSM Incidents replication set exists. |
Without an ACTIVE replication set or response plans, incidents lack coordinated engagement and automation, raising MTTR and impacting availability and integrity.
Threats include prolonged outages, lateral movement, and data exfiltration from delayed containment and misrouted escalation. |
Establish an ACTIVE replication set and create response plans that define engagement, escalation, runbooks, severity, and communication.
Apply least privilege to automation roles, test plans regularly, integrate with monitoring to trigger them, and use defense in depth with redundant contacts and Regions. |
•KISA-ISMS-P-2023: 2.10.2, 2.11.1
•C5-2025: OIS-03.02B, OIS-03.05B, OIS-03.06B, OIS-05.03B, OIS-08.01B, OIS-08.09B, OPS-13.02B, OPS-13.03AC, OPS-22.08B, DEV-15.01B, SIM-01.02AC, SIM-02.01B, SIM-03.01B, SIM-03.04B, SIM-04.01B, SIM-06.01B, BCM-01.05B
•KISA-ISMS-P-2023-korean: 2.10.2, 2.11.1
•NIST-CSF-2.0: ip_9, rp_1
•ENS-RD2022: op.exp.9.aws.img.1
•NIS2: 2.1.1, 2.1.2.a, 2.1.2.i, 3.1.1, 3.1.2.a, 3.1.2.c, 3.1.2.d, 3.5.1, 3.6.1, 3.6.2, 3.6.3, 4.3.1, 5.1.7.b, 12.1.2.c, 12.2.2.b
|
| MANUAL |
medium |
trustedadvisor |
us-east-1 |
trustedadvisor_errors_and_warnings |
Trusted Advisor check has no errors or warnings |
arn:aws:trusted-advisor:us-east-1:716468089330:account |
|
Amazon Web Services Premium Support Subscription is required to use this service. |
Unaddressed warnings/errors can leave misconfigurations that impact CIA:
- Confidentiality: public access or weak auth exposes data
- Integrity: overly permissive settings allow unwanted changes
- Availability: limit exhaustion or poor resilience triggers outages
They can also increase unnecessary cost. |
Adopt a continuous process to remediate Trusted Advisor findings:
- Prioritize error then warning
- Assign ownership and SLAs
- Integrate alerts with workflows
- Enforce least privilege, segmentation, encryption, MFA, and tested backups
- Reassess regularly to confirm fixes and prevent regression |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2, 2.11.3
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2, 2.11.3
•NIST-CSF-2.0: rm_1, po_3, po_4, ov_2, ov_3
|
| FAIL |
low |
trustedadvisor |
us-east-1 |
trustedadvisor_premium_support_plan_subscribed |
AWS account is subscribed to an AWS Premium Support plan |
arn:aws:trusted-advisor:us-east-1:716468089330:account |
|
Amazon Web Services Premium Support Plan isn't subscribed. |
Without Premium Support, critical incidents face slower response, reducing availability and delaying containment of security events. Limited Trusted Advisor coverage lets misconfigurations persist, risking data exposure and privilege misuse. Lack of expert guidance increases change risk during production impacts. |
Adopt Business or higher for production and mission-critical accounts.
- Integrate Support into IR with defined contacts/severity
- Enforce least privilege for case access
- Use Trusted Advisor for proactive hardening
- If opting out, ensure an equivalent 24/7 support and escalation path |
•C5-2025: SSO-05.06B
•NIST-CSF-2.0: rm_1, po_3, po_4, ov_3
•FedRAMP-20x-KSI-Low-25.05C: ksi-piy, ksi-tpr
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_different_regions |
VPCs are present in more than one region |
arn:aws:ec2:us-east-2:716468089330:vpc |
|
VPCs found only in one region. |
Single-region VPC deployment weakens availability and resilience. A regional outage, service disruption, or network control misconfiguration can cause broad downtime, hinder recovery, and increase the blast radius of incidents impacting business continuity. |
Adopt a multi-region network design:
- Create VPCs in at least two regions for critical workloads
- Replicate routing, security controls, and endpoints consistently
- Apply fault tolerance and defense in depth with data replication and resilient DNS/failover to avoid single-region dependency |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.01AS, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1
•ISO27001-2022: A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
vpc |
us-east-2 |
vpc_endpoint_connections_trust_boundaries |
VPC endpoint policy allows access only from trusted AWS accounts |
arn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d |
•GuardDutyManaged=true
|
VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c can be accessed from non-trusted accounts. |
Non-trusted principals using your endpoint can access AWS services as if from your VPC, weakening segmentation. This enables unauthorized reads/writes and data exfiltration from resources tied to the endpoint, harming confidentiality and integrity, and potentially increasing costs. |
Apply least privilege: restrict endpoint policies to your account and an explicit allowlist of trusted accounts. Avoid * principals unless coupled with strict conditions. Prevent transitive trust across network links, and use resource policies and monitoring as defense in depth to limit endpoint use. |
•CISA: your-systems-3
•KISA-ISMS-P-2023: 2.6.1, 2.6.2, 2.10.2
•C5-2025: COS-03.01B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.6.2, 2.10.2
•AWS-Well-Architected-Framework-Security-Pillar: SEC05-BP01
•NIST-CSF-2.0: rr_1, po_3, ov_3, ra_5, ac_5, ae_1
•AWS-Foundational-Technical-Review: NETSEC-002
•CCC-v2025.10: CCC.Core.CN05.AR03, CCC.Core.CN05.AR04, CCC.Core.CN05.AR05, CCC.Core.CN05.AR06, CCC.LB.CN09.AR01
•SecNumCloud-3.2: 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
•NIS2: 6.8.2.a
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_endpoint_for_ec2_enabled |
VPC has an Amazon EC2 VPC endpoint |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 |
|
VPC vpc-027f26d26f17ab361 has no EC2 endpoint. |
Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail. |
Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth |
•AWS-Foundational-Security-Best-Practices: EC2.10
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: ra_5, ae_1
•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38
•CCC-v2025.10: CCC.Core.CN05.AR05
•PCI-3.2.1: 1.3, 2.2, 2.2.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_endpoint_for_ec2_enabled |
VPC has an Amazon EC2 VPC endpoint |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c |
•Name=Scrivas_prod_vpc
|
VPC vpc-074cd9d22ca5c317c has no EC2 endpoint. |
Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail. |
Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth |
•AWS-Foundational-Security-Best-Practices: EC2.10
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: ra_5, ae_1
•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38
•CCC-v2025.10: CCC.Core.CN05.AR05
•PCI-3.2.1: 1.3, 2.2, 2.2.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_endpoint_for_ec2_enabled |
VPC has an Amazon EC2 VPC endpoint |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 |
•Name=Scrivas_vpc
|
VPC vpc-03b6368ab9a21d2c7 has no EC2 endpoint. |
Without a private EC2 endpoint, EC2 API traffic exits via IGW/NAT. This expands exposure to network path threats (e.g., DNS hijack, MITM) and weakens egress isolation. It also adds an internet egress dependency for API access, reducing availability if NAT/edge paths fail. |
Use an interface VPC endpoint for the EC2 service in each VPC that requires EC2 API access.
- Enable private DNS to keep calls on the AWS network
- Apply restrictive endpoint policies (least privilege)
- Reduce reliance on public egress and layer controls for defense in depth |
•AWS-Foundational-Security-Best-Practices: EC2.10
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: ra_5, ae_1
•PCI-4.0: 1.2.8.18, 1.2.8.38, 1.3.1.21, 1.3.1.42, 1.3.2.21, 1.3.2.42, 1.4.1.5, 1.4.2.19, 1.4.2.40, 1.4.4.5, 1.5.1.18, 1.5.1.38, A1.1.3.18, A1.1.3.38
•CCC-v2025.10: CCC.Core.CN05.AR05
•PCI-3.2.1: 1.3, 2.2, 2.2.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_endpoint_multi_az_enabled |
Amazon VPC interface endpoint has subnets in multiple Availability Zones |
arn:aws:ec2:us-east-2:716468089330:vpc-endpoint/vpce-06efc11d09168d72d |
•GuardDutyManaged=true
|
VPC Endpoint vpce-06efc11d09168d72d in VPC vpc-074cd9d22ca5c317c has subnets in different AZs. |
A single-subnet endpoint creates a single-AZ dependency. An AZ outage or routing issue can cut access to the service, reducing availability. Workloads may revert to public endpoints, exposing traffic to the Internet and risking confidentiality through interception or tampering. |
Place interface endpoints in multiple subnets across distinct AZs to remove single-AZ reliance. Prefer zone-local routing so clients use the nearest endpoint, and combine with private DNS and restrictive security groups to limit exposure-supporting defense in depth and resilient connectivity. |
•KISA-ISMS-P-2023: 2.9.2
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, pt_5
•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_flow_logs_enabled |
VPC flow logs are enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 |
|
VPC vpc-027f26d26f17ab361 Flow logs are enabled. |
Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability. |
Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth. |
•CISA: your-surroundings-1, your-data-2
•CIS-7.0: 4.7
•SOC2: cc_7_2, cc_7_3
•CIS-1.4: 3.9
•CIS-1.5: 3.9
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: EC2.6
•ISO27001-2013: A.12.4.R
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2
•CIS-2.0: 3.9
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04
•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1
•CIS-5.0: 3.7
•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34
•NIST-800-53-Revision-4: au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8
•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket
•CIS-3.0: 3.7
•ENS-RD2022: op.mon.1.aws.flow.1
•CIS-6.0: 4.7
•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01
•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3
•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1
•ProwlerThreatScore-1.0: 3.1.4
•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: au-2
•CIS-4.0.1: 3.7
•NIS2: 3.2.3.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_flow_logs_enabled |
VPC flow logs are enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c |
•Name=Scrivas_prod_vpc
|
VPC Scrivas_prod_vpc Flow logs are enabled. |
Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability. |
Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth. |
•CISA: your-surroundings-1, your-data-2
•CIS-7.0: 4.7
•SOC2: cc_7_2, cc_7_3
•CIS-1.4: 3.9
•CIS-1.5: 3.9
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: EC2.6
•ISO27001-2013: A.12.4.R
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2
•CIS-2.0: 3.9
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04
•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1
•CIS-5.0: 3.7
•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34
•NIST-800-53-Revision-4: au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8
•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket
•CIS-3.0: 3.7
•ENS-RD2022: op.mon.1.aws.flow.1
•CIS-6.0: 4.7
•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01
•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3
•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1
•ProwlerThreatScore-1.0: 3.1.4
•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: au-2
•CIS-4.0.1: 3.7
•NIS2: 3.2.3.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_flow_logs_enabled |
VPC flow logs are enabled |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 |
•Name=Scrivas_vpc
|
VPC Scrivas_vpc Flow logs are enabled. |
Without flow logs, network activity is opaque, hindering detection and investigation of malicious traffic. Attackers can probe, exfiltrate, or move laterally unnoticed, impacting confidentiality and integrity; outages and misconfigurations are harder to diagnose, reducing availability. |
Enable VPC Flow Logs for all VPCs to provide baseline telemetry.
Prefer capturing at least REJECT and, for sensitive networks, ALL. Send logs to a centralized, access-controlled destination with retention. Apply least privilege to writers/readers and integrate with monitoring for defense in depth. |
•CISA: your-surroundings-1, your-data-2
•CIS-7.0: 4.7
•SOC2: cc_7_2, cc_7_3
•CIS-1.4: 3.9
•CIS-1.5: 3.9
•GDPR: article_25, article_30
•AWS-Foundational-Security-Best-Practices: EC2.6
•ISO27001-2013: A.12.4.R
•KISA-ISMS-P-2023: 2.9.4, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-26.05B, OPS-26.01AS
•HIPAA: 164_308_a_1_ii_d, 164_308_a_3_ii_a, 164_308_a_6_ii, 164_312_b, 164_312_c_2
•CIS-2.0: 3.9
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.2
•GxP-21-CFR-Part-11: 11.10-e
•AWS-Well-Architected-Framework-Security-Pillar: SEC04-BP01, SEC04-BP02, SEC04-BP03, SEC05-BP04, SEC09-BP04
•NIST-CSF-2.0: po_4, pt_1, pt_4, ae_1, cm_1
•CIS-5.0: 3.7
•NIST-800-171-Revision-2: 3_3_1, 3_3_3, 3_6_1, 3_6_2, 3_13_1, 3_14_6, 3_14_7
•PCI-4.0: 10.2.1.1.34, 10.2.1.2.29, 10.2.1.3.29, 10.2.1.4.29, 10.2.1.5.29, 10.2.1.6.29, 10.2.1.7.29, 10.2.1.29, 10.2.2.29, 10.3.1.29, 10.6.3.39, 5.3.4.34, A1.2.1.34
•NIST-800-53-Revision-4: au_2, au_3, au_12
•NIST-800-53-Revision-5: ac_4_26, au_2_b, au_3_a, au_3_b, au_3_c, au_3_d, au_3_e, au_6_3, au_6_4, au_6_6, au_6_9, au_8_b, au_12_a, au_12_c, au_12_1, au_12_2, au_12_3, au_12_4, au_14_a, au_14_b, au_14_3, ca_7_b, cm_5_1_b, cm_6_a, cm_9_b, ia_3_3_b, ma_4_1_a, pm_14_a_1, pm_14_b, pm_31, si_4_17, si_7_8
•AWS-Account-Security-Onboarding: Send VPC Flow Logs (only DENYs) to S3 bucket
•CIS-3.0: 3.7
•ENS-RD2022: op.mon.1.aws.flow.1
•CIS-6.0: 4.7
•NIST-CSF-1.1: ae_1, ae_3, cm_1, cm_7, am_3, ds_5, pt_1
•CCC-v2025.10: CCC.Core.CN04.AR02, CCC.Logging.CN01.AR01, CCC.Logging.CN01.AR02, CCC.VPC.CN04.AR01
•SecNumCloud-3.2: 12.6, 12.14, 13.1, 13.3
•RBI-Cyber-Security-Framework: annex_i_7_4
•FFIEC: d2-ma-ma-b-1, d2-ma-ma-b-2, d3-dc-an-b-3, d3-dc-an-b-4, d3-dc-ev-b-1, d3-dc-ev-b-3, d3-pc-im-b-3
•PCI-3.2.1: 4.1, 4.1.e, 4.1.f, 10.1
•ProwlerThreatScore-1.0: 3.1.4
•ISO27001-2022: A.8.15, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
•FedRamp-Moderate-Revision-4: au-2-a-d, au-3, au-6-1-3, au-12-a-c
•FedRAMP-Low-Revision-4: au-2
•CIS-4.0.1: 3.7
•NIS2: 3.2.3.c
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_subnet_different_az |
VPC has subnets in more than one Availability Zone |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 |
|
VPC vpc-027f26d26f17ab361 has subnets in more than one availability zone. |
Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives. |
Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1
•SecNumCloud-3.2: 17.2
•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_subnet_different_az |
VPC has subnets in more than one Availability Zone |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c |
•Name=Scrivas_prod_vpc
|
VPC Scrivas_prod_vpc has subnets in more than one availability zone. |
Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives. |
Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1
•SecNumCloud-3.2: 17.2
•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22
|
| PASS |
medium |
vpc |
us-east-2 |
vpc_subnet_different_az |
VPC has subnets in more than one Availability Zone |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 |
•Name=Scrivas_vpc
|
VPC Scrivas_vpc has subnets in more than one availability zone. |
Single-AZ subnet layouts create a single point of failure, leading to service downtime during AZ outages, maintenance, or capacity events. Lack of zonal redundancy constrains load balancing and egress design, reduces fault isolation, and undermines availability and recovery objectives. |
Distribute subnets across 2+ Availability Zones and deploy workloads in separate AZs for high availability. Mirror network tiers per AZ, align routing and egress per AZ, and enforce multi-AZ layouts with IaC and policy guardrails. Regularly test failover to validate resilience. |
•KISA-ISMS-P-2023: 2.9.2
•C5-2025: PS-02.01B, PS-02.02AS
•KISA-ISMS-P-2023-korean: 2.9.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.r3.aws.vpc.1, op.cont.2.aws.vpc.1
•SecNumCloud-3.2: 17.2
•ISO27001-2022: A.8.14, A.8.20, A.8.21, A.8.22
|
| FAIL |
high |
vpc |
us-east-2 |
vpc_subnet_no_public_ip_by_default |
VPC subnet does not assign public IP addresses by default |
arn:aws:ec2:us-east-2:716468089330:subnet/subnet-028925e3b66ac3546 |
|
VPC subnet subnet-028925e3b66ac3546 assigns public IP by default. |
Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS. |
Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.15
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
high |
vpc |
us-east-2 |
vpc_subnet_no_public_ip_by_default |
VPC subnet does not assign public IP addresses by default |
arn:aws:ec2:us-east-2:716468089330:subnet/subnet-05e591b90cc4ce834 |
|
VPC subnet subnet-05e591b90cc4ce834 assigns public IP by default. |
Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS. |
Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.15
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| PASS |
high |
vpc |
us-east-2 |
vpc_subnet_no_public_ip_by_default |
VPC subnet does not assign public IP addresses by default |
arn:aws:ec2:us-east-2:716468089330:subnet/subnet-029a31cc702e7daaa |
•Name=prod-public-1b
|
VPC subnet prod-public-1b does NOT assign public IP by default. |
Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS. |
Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.15
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| PASS |
high |
vpc |
us-east-2 |
vpc_subnet_no_public_ip_by_default |
VPC subnet does not assign public IP addresses by default |
arn:aws:ec2:us-east-2:716468089330:subnet/subnet-0cd1dad930562f3cd |
•Name=prod-public-1a
|
VPC subnet prod-public-1a does NOT assign public IP by default. |
Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS. |
Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.15
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| PASS |
high |
vpc |
us-east-2 |
vpc_subnet_no_public_ip_by_default |
VPC subnet does not assign public IP addresses by default |
arn:aws:ec2:us-east-2:716468089330:subnet/subnet-04082d4e496af0c4c |
•Name=Scrivas_subnet1
|
VPC subnet Scrivas_subnet1 does NOT assign public IP by default. |
Internet-exposed instances become reachable by default, enabling port scans, SSH/RDP brute force, and exploit attempts. Successful access can lead to data exfiltration (confidentiality), unauthorized changes (integrity), and outages (availability) through abuse or DDoS. |
Disable subnet auto-assign to enforce least-privilege exposure. Place workloads in private subnets, use controlled egress (NAT or private endpoints), and prefer bastions or SSM for administration.
When public access is necessary, assign IPs explicitly and restrict with tight security groups and routes for defense in depth. |
•SOC2: cc_6_6
•AWS-Foundational-Security-Best-Practices: EC2.15
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 9.7
•RBI-Cyber-Security-Framework: annex_i_1_3
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_subnet_separate_private_public |
VPC has both public and private subnets |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-027f26d26f17ab361 |
|
VPC vpc-027f26d26f17ab361 has only public subnets. |
Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable. |
Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_subnet_separate_private_public |
VPC has both public and private subnets |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-074cd9d22ca5c317c |
•Name=Scrivas_prod_vpc
|
VPC Scrivas_prod_vpc has only public subnets. |
Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable. |
Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
vpc |
us-east-2 |
vpc_subnet_separate_private_public |
VPC has both public and private subnets |
arn:aws:ec2:us-east-2:716468089330:vpc/vpc-03b6368ab9a21d2c7 |
•Name=Scrivas_vpc
|
VPC Scrivas_vpc has only public subnets. |
Missing subnet separation erodes segmentation.
- Only public: workloads face Internet exposure, enabling scanning, brute force, and lateral movement, threatening confidentiality and integrity.
- Only private: no controlled egress can break patching and dependencies, impacting availability.
- No subnets: misconfiguration leaves services unreachable. |
Segment each VPC: put internet-facing endpoints in public subnets and internal workloads in private subnets. Restrict ingress/egress with tight route tables, NACLs, and security groups, minimizing 0.0.0.0/0. Apply least privilege and defense in depth. Provide controlled outbound for private subnets via managed egress and use hardened admin access patterns. |
•SOC2: cc_6_6
•KISA-ISMS-P-2023: 2.6.1, 2.10.2
•C5-2025: PS-03.02B, COS-02.01B, COS-07.04B
•KISA-ISMS-P-2023-korean: 2.6.1, 2.10.2
•NIST-CSF-2.0: be_5, ac_5
•ENS-RD2022: mp.com.4.aws.vpc.1, mp.com.4.r1.aws.vpc.1
•AWS-Foundational-Technical-Review: NETSEC-002
•SecNumCloud-3.2: 13.2
•ISO27001-2022: A.8.20, A.8.21, A.8.22
•AWS-AI-Security-Framework-1.0: AISF-INFRA-08
|
| FAIL |
medium |
wafv2 |
us-east-2 |
wafv2_webacl_logging_enabled |
AWS WAFv2 Web ACL has logging enabled |
arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d |
|
AWS WAFv2 Web ACL acl-alb-ec2-general does not have logging enabled. |
Without WAF logging, visibility into allowed/blocked requests is lost, degrading detection and response. SQLi, credential stuffing, and bot/DDoS probes can go unnoticed, risking data exposure (C), undetected rule misuse (I), and service instability from unseen abuse (A). |
Enable logging on all WAFv2 Web ACLs to a centralized destination. Apply least privilege for log delivery, redact sensitive fields, and filter to retain high-value events. Integrate with monitoring/SIEM for alerting and correlation, and review routinely as part of defense in depth. |
•SOC2: cc_a_1_1, pi_1_2
•AWS-Foundational-Security-Best-Practices: WAF.11
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•PCI-4.0: 10.2.1.1.35, 10.2.1.2.30, 10.2.1.3.30, 10.2.1.4.30, 10.2.1.5.30, 10.2.1.6.30, 10.2.1.7.30, 10.2.1.30, 10.2.2.30, 10.3.1.30, 10.6.3.40, 5.3.4.35, A1.2.1.35
•AWS-Account-Security-Onboarding: Export metrics in centralized collector
•CCC-v2025.10: CCC.LB.CN01.AR02
•SecNumCloud-3.2: 12.6
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-INFRA-03
•NIS2: 3.2.3.c, 11.2.2.f
•FedRAMP-20x-KSI-Low-25.05C: ksi-mla
|
| PASS |
medium |
wafv2 |
us-east-2 |
wafv2_webacl_rule_logging_enabled |
AWS WAFv2 Web ACL has Amazon CloudWatch metrics enabled for all rules and rule groups |
arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d |
|
AWS WAFv2 Web ACL acl-alb-ec2-general does have CloudWatch Metrics enabled in all its rules. |
Absent CloudWatch metrics, WAF telemetry is lost, masking spikes, rule bypasses, and misconfigurations. This delays detection of SQLi/XSS probes and bot floods, risking data confidentiality, request integrity, and application availability. |
Enable CloudWatch metrics for all WAF rules and rule groups (including managed rule groups). Use consistent metric names, centralize dashboards and alerts, and review trends to validate rule efficacy. Integrate with a SIEM for defense in depth and tune rules based on telemetry. |
•SOC2: cc_a_1_1
•KISA-ISMS-P-2023: 2.9.4, 2.10.1, 2.10.2
•C5-2025: AM-01.01AC, OPS-11.02AC, OPS-15.01B, OPS-15.02B, OPS-15.03B, OPS-15.01AC, OPS-26.05B, OPS-26.01AS, SSO-05.01AC, PSS-04.05B
•KISA-ISMS-P-2023-korean: 2.9.4, 2.10.1, 2.10.2
•PCI-4.0: 10.2.1.1.36, 10.4.1.1.7, 10.4.1.6, 10.4.2.7, 10.6.3.41, 10.7.1.8, 10.7.2.8, A3.3.1.11, A3.5.1.11
•ISO27001-2022: A.8.15, A.8.16
•AWS-AI-Security-Framework-1.0: AISF-INFRA-03
•NIS2: 3.2.3.c
|
| PASS |
high |
wafv2 |
us-east-2 |
wafv2_webacl_with_rules |
AWS WAFv2 Web ACL has at least one rule or rule group attached |
arn:aws:wafv2:us-east-2:716468089330:regional/webacl/acl-alb-ec2-general/7a954a9a-3729-48ff-bd99-fdfb1cef7e8d |
|
AWS WAFv2 Web ACL acl-alb-ec2-general does have rules or rule groups attached. |
Without rules, traffic is governed only by the web ACL DefaultAction, often allowing requests without inspection. This increases risks to confidentiality (data exfiltration via injection), integrity (XSS/parameter tampering), and availability (layer-7 DDoS, bot abuse). |
Populate each web ACL with targeted rules or managed rule groups to enforce least-privilege web access: cover common exploits (SQLi/XSS), IP reputation, and rate limits, scoped to your apps. Use a conservative DefaultAction, monitor metrics/logs, and continually tune-supporting defense in depth and zero trust. |
•KISA-ISMS-P-2023: 2.10.1, 2.10.2
•KISA-ISMS-P-2023-korean: 2.10.1, 2.10.2
•PCI-4.0: 6.4.1.8, 6.4.2.8
•CCC-v2025.10: CCC.LB.CN01.AR01
•SecNumCloud-3.2: 13.2
•AWS-AI-Security-Framework-1.0: AISF-INFRA-03
|