Main areas covered
| Section | Area | Description |
|---|---|---|
| 1 | Identity and access management (RAM) | Password length, complexity, reuse and expiration policies; MFA enforcement; and restrictions on excessive RAM permissions |
| 2 | Logging and monitoring (ActionTrail) | Multi-Region trails, log retention, and protection of logs stored in OSS |
| 3 | Networking | Security group restrictions on ports 22/3389 and VPC Flow Log |
| 4 | Virtual machines (ECS) | Disk encryption and limits on public IP exposure |
| 5 | Storage (OSS) | Public-access blocking, server-side encryption, and versioning |
| 6 | Database services (RDS) | SSL connection enforcement, backup retention, and public-access blocking |