CIS Amazon Web Services Three-tier Web Architecture Benchmark

XEIZE supports major IaC checks related to the CIS Amazon Web Services Three-tier Web Architecture Benchmark.

Main areas covered

Layer Components Description
Web tier ALB, CloudFront, WAF Require HTTPS and TLS 1.2 or later, associate a WAF, and primarily allow HTTP/HTTPS traffic
Application tier EC2, Lambda, IAM Use least-privilege IAM roles, limit security groups to internal communication, and use IMDSv2 for instance metadata
Database tier RDS, ElastiCache Block public access, encrypt data at rest, and restrict security groups to the application tier
Networking VPC, subnets Separate public and private subnets, configure route tables and NACLs, and restrict default VPC use
Logging CloudTrail, VPC Flow Logs Use multi-Region trails and enable flow logs
Encryption EBS, S3, RDS Use EBS encryption by default, S3 server-side encryption, and RDS encryption at rest

References