Main areas covered
| Section | Area | Description |
|---|---|---|
| 1 | Identity and access management | IAM policies, root-account protection, MFA enforcement, password policies, access-key rotation, and a support role |
| 2 | Storage | S3 public-access blocking, SSL enforcement, and versioning; EBS encryption by default; RDS encryption at rest |
| 3 | Logging | CloudTrail multi-Region trails, log integrity, and KMS encryption; AWS Config; VPC Flow Logs; S3 bucket access logging |
| 4 | Monitoring | CloudWatch metric filters and alarms for root-account use and changes to IAM, CloudTrail, security groups, NACLs, route tables, and VPCs |
| 5 | Networking | Default security-group traffic restrictions and limits on sensitive-port exposure in security groups and NACLs |