AWS

Security and operational configuration guidance for AWS CloudFormation resources.

Documentation

Article Path
Invalid ACM certificate domain name cloudFormation/aws/wildcard_in_acm_certificate_domain_name
ALB uses an HTTP listener cloudFormation/aws/alb_listening_on_http
ALB is not associated with AWS WAF cloudFormation/aws/alb_is_not_integrated_with_waf
ALB access logging is disabled cloudFormation/aws/elb_v2_alb_access_log_disabled
Review API Gateway authentication configuration cloudFormation/aws/api_gateway_without_configured_authorizer
Review API Gateway detailed CloudWatch metrics cloudFormation/aws/cloudwatch_metrics_disabled
Review access logging for an API Gateway deployment stage cloudFormation/aws/api_gateway_deployment_without_access_log_setting
Usage plan not associated with the deployed API stage cloudFormation/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
Review API Gateway stage logging cloudFormation/aws/api_gateway_access_logging_disabled
API Gateway stage not associated with a usage plan cloudFormation/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API Gateway X-Ray tracing disabled cloudFormation/aws/api_gateway_xray_disabled
Review API Gateway method authentication cloudFormation/aws/api_gateway_with_open_access
Review API Gateway API key usage management cloudFormation/aws/api_gateway_method_does_not_contains_an_api_key
Review the TLS policy for an API Gateway custom domain cloudFormation/aws/api_gateway_without_security_policy
Review the API Gateway compression threshold cloudFormation/aws/api_gateway_with_invalid_compression
Review API Gateway endpoint exposure cloudFormation/aws/api_gateway_endpoint_config_is_not_private
API Gateway cache cluster not configured cloudFormation/aws/api_gateway_cache_cluster_disabled
Review API Gateway backend client certificate settings cloudFormation/aws/api_gateway_without_ssl_certificate
API Gateway invocation scope for Lambda needs review cloudFormation/aws/public_lambda_via_api_gateway
Review AWS WAF protection for API Gateway cloudFormation/aws/api_gateway_without_waf
AWS Config aggregator limited to selected Regions cloudFormation/aws/config_configuration_aggregator_to_all_regions_disabled
AWS Support policy without an attachment target cloudFormation/aws/support_has_no_role_associated
Review the access key age threshold cloudFormation/aws/access_key_not_rotated_within_90_days
Alexa Skill secret storage needs review cloudFormation/aws/alexa_skill_plaintext_client_secret_exposed
Review Amazon MQ broker logging cloudFormation/aws/mq_broker_logging_disabled
Exposed Amplify app access token cloudFormation/aws/amplify_app_access_token_exposed
Exposed Amplify app Basic Auth password cloudFormation/aws/amplify_app_basic_auth_config_password_exposed
Exposed Amplify app OAuth token cloudFormation/aws/amplify_app_oauth_token_exposed
Exposed Amplify branch Basic Auth password cloudFormation/aws/amplify_branch_basic_auth_config_password_exposed
Review load balancer attachment for an Auto Scaling group cloudFormation/aws/auto_scaling_group_with_no_associated_elb
CloudFormation stack notifications not configured cloudFormation/aws/stack_notifications_disabled
Credentials are embedded in a CloudFormation template cloudFormation/aws/cloudformation_specifying_credentials_not_safe
Review CloudFront distribution and origin configuration cloudFormation/aws/cdn_configuration_is_missing
Review CloudFront domain and certificate settings cloudFormation/aws/vulnerable_default_ssl_certificate
CloudFront request logging is not configured cloudFormation/aws/cloudfront_logging_disabled
Review the CloudFront TLS security policy cloudFormation/aws/secure_ciphers_disabled
CloudFront minimum TLS version is too low cloudFormation/aws/cloudfront_without_minimum_protocol_tls_1.2
CloudFront allows HTTP viewer connections cloudFormation/aws/cloudfront_viewer_protocol_policy_allows_http
CloudFront is not associated with AWS WAF cloudFormation/aws/cloudfront_without_waf
Traffic between CloudFront and the origin is not encrypted cloudFormation/aws/connection_between_cloudfront_origin_not_encrypted
CloudTrail not integrated with CloudWatch Logs cloudFormation/aws/cloudtrail_not_integrated_with_cloudwatch
CloudTrail SNS notification topic not configured cloudFormation/aws/cloudtrail_sns_topic_name_undefined
CloudTrail multi-Region logging disabled cloudFormation/aws/cloudtrail_multi_region_disabled
CloudTrail logs without a configured KMS key cloudFormation/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrail log file validation disabled cloudFormation/aws/cloudtrail_log_file_validation_disabled
CloudTrail trail logging is stopped cloudFormation/aws/cloudtrail_logging_disabled
CloudTrail log bucket access logging needs review cloudFormation/aws/s3_bucket_cloudtrail_logging_disabled
CodeBuild artifact encryption key needs review cloudFormation/aws/codebuild_not_encrypted
Cognito user pool without MFA cloudFormation/aws/cognito_userpool_without_mfa
Review DocumentDB audit and profiler logging cloudFormation/aws/docdb_logging_disabled
DynamoDB point-in-time recovery disabled cloudFormation/aws/dynamodb_table_point_in_time_recovery_disabled
Invalid DynamoDB billing mode cloudFormation/aws/dynamodb_with_table_billing_mode_not_recommended
EBS volume without a specified KMS key cloudFormation/aws/ebs_volume_without_kms_key_id
EBS volume not attached to an instance cloudFormation/aws/ebs_volume_not_attached_to_instances
Duplicate network ACL rule number cloudFormation/aws/ec2_network_acl_duplicate_rule
Review EC2 detailed monitoring cloudFormation/aws/ec2_instance_monitoring_disabled
EC2 instance uses the default VPC cloudFormation/aws/ec2_instance_using_default_vpc
Review EC2 EBS optimization cloudFormation/aws/ec2_not_ebs_optimized
Review the IAM role association for the EC2 instance cloudFormation/aws/ec2_instance_has_no_iam_role
Review EC2 metadata service version settings cloudFormation/aws/instance_uses_metadata_service_IMDSv1
EC2 instance uses the default security group cloudFormation/aws/ec2_instance_using_default_security_group
ECR repository without a customer managed KMS key cloudFormation/aws/ecr_repository_not_encrypted_with_CMK
Review ECR image scanning configuration cloudFormation/aws/unscanned_ecr_image
ECR image tags can be overwritten cloudFormation/aws/ecr_image_tag_not_immutable
Review ECS Container Insights settings cloudFormation/aws/ecs_cluster_container_insights_disabled
Review ECS service deployment availability cloudFormation/aws/ecs_service_without_running_tasks
Invalid Fargate task CPU and memory combination cloudFormation/aws/ecs_task_definition_invalid_cpu_or_memory
Review the ECS task network mode cloudFormation/aws/ecs_task_definition_network_mode_not_recommended
ECS container health check not configured cloudFormation/aws/ecs_task_definition_healthcheck_missing
Public IP assignment for ECS tasks cloudFormation/aws/ecs_services_assigned_with_public_ip_address
Review load balancer attachment for an ECS service cloudFormation/aws/ecs_no_load_balancer_attached
ECS service role references a policy cloudFormation/aws/inline_policies_are_attached_to_ecs_service
Review IAM roles for an ECS task cloudFormation/aws/empty_roles_for_ecs_cluster_task_definitions
Review the EFS customer managed KMS key cloudFormation/aws/efs_without_kms
EFS transit encryption settings need review cloudFormation/aws/efs_volume_with_disabled_transit_encryption
EFS tags missing cloudFormation/aws/efs_without_tags
Insufficient restrictions on EKS node group remote access cloudFormation/aws/eks_node_group_remote_access
ELB access logging disabled cloudFormation/aws/elb_access_log_disabled
Review ELB outbound access rules cloudFormation/aws/elb_with_security_group_without_outbound_rules
Review ELB transport encryption cloudFormation/aws/elb_without_secure_protocol
Review ELB inbound access rules cloudFormation/aws/elb_with_security_group_without_inbound_rules
Review ELB protocol security settings cloudFormation/aws/elb_using_insecure_protocols
Review EMR cluster VPC subnet selection cloudFormation/aws/emr_wihout_vpc
EMR cluster has no security configuration attached cloudFormation/aws/emr_cluster_without_security_configuration
Encryption disabled in an EMR security configuration cloudFormation/aws/emr_security_configuration_encryptions_enabled
Review ElastiCache VPC and subnet-group selection cloudFormation/aws/elasticache_without_vpc
Review default ElastiCache port use cloudFormation/aws/elasticache_using_default_port
Memcached nodes placed in one Availability Zone cloudFormation/aws/elasticache_nodes_not_created_across_multi_az
ElastiCache transit encryption is disabled cloudFormation/aws/elasticache_with_disabled_transit_encryption
OpenSearch domain does not require HTTPS cloudFormation/aws/elasticsearch_with_https_disabled
Elasticsearch domain principals need review cloudFormation/aws/elasticsearch_without_iam_authentication
Review Elasticsearch and OpenSearch audit logging cloudFormation/aws/elasticsearch_without_audit_logs
OpenSearch node-to-node encryption needs review cloudFormation/aws/elasticsearch_domain_not_encrypted_node_to_node
OpenSearch and Elasticsearch slow logs not configured cloudFormation/aws/elasticsearch_without_slow_logs
Review Elasticsearch and OpenSearch error logging cloudFormation/aws/elasticsearch_without_es_application_logs
Cross-account role trust needs external-ID or MFA review cloudFormation/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
Review GameLift inbound port ranges cloudFormation/aws/gamelift_fleet_ec2_inbound_permissions_with_port_range
Review the need for CloudFront geographic restrictions cloudFormation/aws/geo_restriction_disabled
GitHub repository visibility needs review cloudFormation/aws/github_repository_set_to_public
GuardDuty is disabled cloudFormation/aws/guardduty_detector_disabled
HTTP port open to all addresses cloudFormation/aws/http_port_open
IAM Access Analyzer not enabled cloudFormation/aws/iam_access_analyzer_not_enabled
IAM user without group membership cloudFormation/aws/iam_user_with_no_group
IAM group uses an inline policy cloudFormation/aws/iam_groups_inline_policies
Neptune cluster has IAM database authentication disabled cloudFormation/aws/neptune_cluster_with_iam_database_authentication_disabled
IAM password below the minimum length cloudFormation/aws/iam_password_without_minimum_length
Review the number of IAM user access keys cloudFormation/aws/iam_user_too_many_access_keys
IAM user console password-reset policy needs review cloudFormation/aws/user_iam_missing_password_reset_required
IAM policy attached directly to users cloudFormation/aws/iam_policies_without_groups
Review EC2 instance VPC association cloudFormation/aws/instance_with_no_vpc
IoT policy allows all resources cloudFormation/aws/iot_policy_allows_wildcard_resource
IoT policy allows all actions cloudFormation/aws/iot_policy_allows_action_as_wildcard
KMS customer managed key automatic rotation disabled cloudFormation/aws/cmk_rotation_disabled
KMS automatic key rotation needs review cloudFormation/aws/kms_enable_key_rotation_disabled
Elasticsearch encryption key configuration needs review cloudFormation/aws/elasticsearch_domain_encryption_with_kms_disabled
Lambda active X-Ray tracing not configured cloudFormation/aws/lambda_functions_without_x-ray_tracing
Lambda function tags missing cloudFormation/aws/lambda_function_without_tags
Retention not configured for failed asynchronous Lambda events cloudFormation/aws/lambda_function_without_dead_letter_queue
Lambda invocation permission misconfigured cloudFormation/aws/lambda_permission_misconfigured
Lambda invocation principal uses a wildcard cloudFormation/aws/lambda_permission_principal_is_wildcard
Possible AWS credential exposure in Lambda environment variables cloudFormation/aws/hardcoded_aws_access_key_in_lambda
MSK broker log export needs review cloudFormation/aws/msk_cluster_logging_disabled
Neptune audit log export needs review cloudFormation/aws/neptune_logging_is_disabled
Network ACL TCP/UDP port ranges need review cloudFormation/aws/tcp_or_udp_protocol_network_acl_entry_allows_all_ports
Security group permits RDP from the entire internet cloudFormation/aws/security_groups_unrestricted_access_to_rdp
RDS IAM database authentication is not enabled cloudFormation/aws/iam_database_auth_not_enabled
RDS Multi-AZ deployment is not enabled cloudFormation/aws/rds_multi_az_deployment_disabled
Review default RDS port use cloudFormation/aws/rds_using_default_port
Insufficient RDS backup retention cloudFormation/aws/low_rds_backup_retention_period
RDS deletion protection disabled cloudFormation/aws/rds_db_instance_with_deletion_protection_disabled
RDS snapshot tag copying disabled cloudFormation/aws/tags_not_copied_to_rds_cluster_snapshot
Review RDS automatic minor upgrade settings cloudFormation/aws/automatic_minor_upgrades_disabled
RDS automated backups are disabled cloudFormation/aws/rds_with_backup_disabled
Database cluster IAM authentication is not enabled cloudFormation/aws/iam_db_cluster_auth_not_enabled
Review default Redshift port use cloudFormation/aws/redshift_using_default_port
Review the Redshift cluster encryption key cloudFormation/aws/redshift_cluster_without_kms_cmk
Review Redshift VPC and subnet-group selection cloudFormation/aws/redshift_cluster_without_vpc
Redshift audit log export needs review cloudFormation/aws/redshift_cluster_logging_disabled
Review VPC default-route purpose cloudFormation/aws/routertable_with_default_routing
Review Route 53 public DNS logging to CloudWatch cloudFormation/aws/cloudwatch_logging_disabled
Review S3 public ACL handling cloudFormation/aws/s3_bucket_without_ignore_public_acl
Review S3 public ACL blocking cloudFormation/aws/s3_bucket_allows_public_acl
Review access restrictions for S3 public policies cloudFormation/aws/s3_bucket_without_restriction_of_public_bucket
S3 bucket versioning is not enabled cloudFormation/aws/s3_bucket_without_versioning
Review TLS enforcement for S3 writes cloudFormation/aws/s3_bucket_without_ssl_in_write_actions
Review S3 CORS scope cloudFormation/aws/s3_bucket_with_unsecured_cors_rule
S3 bucket access logging needs review cloudFormation/aws/s3_bucket_logging_disabled
S3 bucket policy not associated with its target cloudFormation/aws/s3_bucket_should_have_bucket_policy
NotAction in an SNS allow policy cloudFormation/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
SNS topic KMS encryption not configured cloudFormation/aws/sns_topic_without_kms_master_key_id
Review SQS message encryption settings cloudFormation/aws/sqs_with_sse_disabled
Public access in an SQS queue policy cloudFormation/aws/sqs_policy_with_public_access
Review the SageMaker endpoint volume encryption key cloudFormation/aws/sagemaker_endpoint_config_should_specify_kms_key_id_attribute
SageMaker notebook has no VPC subnet specified cloudFormation/aws/sagemaker_notebook_not_placed_in_vpc
Direct internet access for a SageMaker notebook cloudFormation/aws/sagemaker_enabling_internet_access
Secrets Manager KMS key not specified cloudFormation/aws/secrets_manager_should_specify_kms_key_id
Review the Secrets Manager encryption key cloudFormation/aws/secretsmanager_secret_without_kms
Review security-group VPC selection cloudFormation/aws/security_groups_without_vpc_attached
Security-group or rule description missing cloudFormation/aws/security_group_rule_without_description
Review single-IP security-group access cloudFormation/aws/security_group_ingress_has_cidr_not_recommended
Review the need for Shield Advanced cloudFormation/aws/shield_advanced_not_in_use
Review SimpleDB domain use cloudFormation/aws/sdb_domain_declared_as_a_resource
Review StackSet retention on account removal cloudFormation/aws/stack_retention_disabled
Encoded private key in user data cloudFormation/aws/user_data_contains_encoded_private_key
VPC Flow Logs coverage needs review cloudFormation/aws/vpc_flowlogs_disabled
Review the Network Firewall inspection path for a VPC cloudFormation/aws/vpc_without_network_firewall
VPC gateway attachment limit exceeded cloudFormation/aws/vpc_attached_with_too_many_gateways
Review the purpose of a VPC without subnets cloudFormation/aws/vpc_without_attached_subnet
AWS Batch job definition with privileged mode enabled cloudFormation/aws/batch_job_definition_with_privileged_container_properties
Overlapping port ranges in network ACL rules cloudFormation/aws/ec2_network_acl_overlapping_ports
DynamoDB uses an AWS owned key cloudFormation/aws/dynamodb_with_aws_owned_cmk
Review S3 public-policy blocking cloudFormation/aws/s3_bucket_with_public_policy
RDS-associated security group has an unrestricted ingress range cloudFormation/aws/db_security_group_with_public_scope
RDS-linked subnet uses a /0 CIDR cloudFormation/aws/rds_associated_with_public_subnet
S3 bucket ACL is PublicReadWrite cloudFormation/aws/s3_bucket_acl_allows_read_or_write_to_all_users
ECR repository policy uses a wildcard principal cloudFormation/aws/ecr_repository_is_publicly_accessible
SNS topic policy has a wildcard or missing principal cloudFormation/aws/sns_topic_is_publicly_accessible
AWS DMS replication instance has public accessibility enabled or unset cloudFormation/aws/amazon_dms_replication_instance_is_publicly_accessible
RDS instance enables public access cloudFormation/aws/rds_db_instance_publicly_accessible
Review protocols allowed by a network ACL cloudFormation/aws/ec2_permissive_network_acl_protocols
Security group exposes administrative ports cloudFormation/aws/security_groups_with_exhibited_admin_ports
ECS service role permissions need review cloudFormation/aws/ecs_service_admin_role_is_present
Default database KMS key usage cloudFormation/aws/default_kms_key_usage
Review a web ACL default-allow policy cloudFormation/aws/webacl_allow_defaultaction
Security group permits a broad source range cloudFormation/aws/db_security_group_open_to_large_scope
IAM policy grants excessive data read access cloudFormation/aws/iam_policy_allows_for_data_exfiltration
Review service records in a Route 53 hosted zone cloudFormation/aws/route53_record_undefined
AWS access key ownership and permissions need review cloudFormation/aws/root_account_has_active_access_keys
Security group allows all ports from all addresses cloudFormation/aws/fully_open_ingress
S3 bucket policy uses a wildcard principal for delete actions cloudFormation/aws/s3_bucket_allows_delete_actions_from_all_principals
S3 Get permissions for a wildcard principal cloudFormation/aws/s3_bucket_allows_get_actions_from_all_principals
S3 bucket policy uses a wildcard principal for put actions cloudFormation/aws/s3_bucket_allows_put_actions_from_all_principals
S3 object restoration permissions for a wildcard principal cloudFormation/aws/s3_bucket_allows_restore_actions_from_all_principals
S3 listing permissions for a wildcard principal cloudFormation/aws/s3_bucket_allows_list_actions_from_all_principals
S3 bucket policy has a wildcard or missing principal cloudFormation/aws/s3_bucket_access_to_any_principal
S3 bucket policy uses wildcards for Action and Principal cloudFormation/aws/s3_bucket_with_all_permissions
S3 bucket ACL permits listing by all users cloudFormation/aws/s3_bucket_acl_allows_read_to_all_users
AssumeRole permission targets all roles cloudFormation/aws/iam_policy_grants_assumerole_permission_across_all_services
Review account-wide trust in an IAM role cloudFormation/aws/iam_role_allows_all_principals_to_assume
Review principals allowed by a KMS key policy cloudFormation/aws/kms_allows_wildcard_principal
Security group allows all ports from the internet cloudFormation/aws/security_groups_with_meta_ip
EC2 security group exposes a sensitive port to all addresses cloudFormation/aws/ec2_sensitive_port_is_publicly_exposed
ELB security group exposes a sensitive port to all addresses cloudFormation/aws/elb_sensitive_port_is_exposed_to_entire_network
Security group allows SSH from all addresses cloudFormation/aws/security_groups_with_unrestricted_access_to_ssh
Security group egress allows all destination addresses cloudFormation/aws/security_group_egress_cidr_open_to_world
Security group egress allows all protocols cloudFormation/aws/security_group_egress_with_all_protocols
Review security group egress port ranges cloudFormation/aws/security_group_egress_with_port_range
Security group ingress allows all protocols cloudFormation/aws/security_group_ingress_with_all_protocols
Review security group ingress port ranges cloudFormation/aws/security_group_ingress_with_port_range
Security group allows unrestricted outbound traffic cloudFormation/aws/security_groups_allows_unrestricted_outbound_traffic
KMS key availability needs review cloudFormation/aws/cmk_is_unusable
IAM group has no users cloudFormation/aws/iam_group_without_users
IAM policies are attached directly to a user cloudFormation/aws/iam_policies_attached_to_user
IAM policy resource is attached directly to users cloudFormation/aws/iam_policy_on_user
Managed IAM policy is attached directly to a user cloudFormation/aws/iam_managed_policy_applied_to_a_user
Kinesis stream without server-side encryption cloudFormation/aws/kinesis_sse_not_configured
DynamoDB encryption key settings need review cloudFormation/aws/dynamodb_table_not_encrypted
Review S3 bucket default encryption policy cloudFormation/aws/s3_bucket_without_server_side_encryption
Automatic public IP assignment enabled for a subnet cloudFormation/aws/ec2_instance_subnet_has_public_ip_mapping_on_launch
Public EC2 instance exposure through its subnet cloudFormation/aws/ec2_public_instance_exposed_through_subnet
Externally allowed port range needs review cloudFormation/aws/unknown_port_exposed_to_internet
EBS encryption monitoring needs review cloudFormation/aws/config_rule_for_encryption_volumes_disabled
Amazon MQ encryption key settings need review cloudFormation/aws/amazon_mq_broker_encryption_disabled
EKS encryption key configuration needs review cloudFormation/aws/eks_cluster_encryption_disabled
SageMaker notebook encryption key settings need review cloudFormation/aws/sagemaker_data_encryption_disabled
API Gateway cache encryption is disabled cloudFormation/aws/api_gateway_cache_encrypted_disabled
EBS volume encryption needs review cloudFormation/aws/ebs_volume_encryption_disabled
EFS file system with encryption disabled cloudFormation/aws/efs_not_encrypted
WorkSpaces without configured encryption cloudFormation/aws/workspace_without_encryption
DAX cluster encryption at rest is disabled cloudFormation/aws/dax_cluster_not_encrypted
EBS block-device encryption needs review cloudFormation/aws/block_device_is_not_encrypted
Database storage encryption needs review cloudFormation/aws/cmk_unencrypted_storage
ELB TLS security policy needs review cloudFormation/aws/elb_using_weak_ciphers
Lambda functions share an execution role cloudFormation/aws/lambda_functions_without_unique_iam_roles
Amazon MQ broker has public access enabled cloudFormation/aws/mq_broker_is_publicly_accessible
Amazon MSK brokers have public access enabled cloudFormation/aws/msk_broker_is_publicly_accessible
Redshift public-access settings need review cloudFormation/aws/redshift_publicly_accessible
S3 bucket ACL permits listing by any AWS account cloudFormation/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
RDP port is open to the internet cloudFormation/aws/remote_desktop_port_open_to_internet
Neptune database cluster with storage encryption disabled cloudFormation/aws/neptune_database_cluster_encryption_disabled
RDS instance storage encryption settings need review cloudFormation/aws/rds_storage_not_encrypted
RDS cluster storage encryption settings need review cloudFormation/aws/rds_storage_encryption_disabled
Redshift storage encryption settings need review cloudFormation/aws/redshift_not_encrypted
MSK cluster encryption settings need review cloudFormation/aws/msk_cluster_encryption_disabled
ECS EFS transport encryption needs review cloudFormation/aws/ecs_cluster_not_encrypted_at_rest
ElastiCache Redis replication group with encryption at rest disabled cloudFormation/aws/elasticache_with_disabled_at_rest_encryption
Elasticsearch domain with encryption at rest disabled cloudFormation/aws/elasticsearch_not_encrypted_at_rest
Lambda execution role may have excessive permissions cloudFormation/aws/lambda_functions_with_full_privileges
IAM policy allows all actions and resources cloudFormation/aws/iam_policy_grants_full_permissions
IAM policy allows full privileges cloudFormation/aws/iam_policies_with_full_privileges
KMS key policy permissions need review cloudFormation/aws/kms_key_with_full_permissions
Security group ingress allows all source addresses cloudFormation/aws/unrestricted_security_group_ingress
S3 bucket has static website hosting configured cloudFormation/aws/s3_static_website_host_enabled
Default security group retains traffic rules cloudFormation/aws/default_security_groups_with_unrestricted_traffic
Plaintext master password in a DocumentDB cluster cloudFormation/aws/docdb_cluster_master_password_in_plaintext
Plaintext password in DMS MongoDB endpoint settings cloudFormation/aws/dms_endpoint_mongo_db_settings_password_exposed
Plaintext password in a DMS endpoint cloudFormation/aws/dms_endpoint_password_exposed
Plaintext password in Directory Service Microsoft AD cloudFormation/aws/directory_service_microsoft_ad_password_set_to_plaintext_or_default_ref
Plaintext password in Directory Service Simple AD cloudFormation/aws/directory_service_simple_ad_password_exposed
IAM login password may be exposed in the template cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext
Plaintext Alexa ASK skill refresh token cloudFormation/aws/refresh_token_is_exposed
Review the scope of network ACL deny rules cloudFormation/aws/ec2_network_acl_ineffective_denied_traffic

Related pages262

Invalid ACM certificate domain name

Specify a valid domain and the required certificate scope.

ALB uses an HTTP listener

Use HTTPS between clients and the ALB.

ALB is not associated with AWS WAF

Configure required AWS WAF request filtering for public ALBs.

ALB access logging is disabled

Store ALB access logs in S3 to support request investigations.

Review API Gateway authentication configuration

Attach appropriate authentication to protected API routes and verify actual permission checks.

Review API Gateway detailed CloudWatch metrics

Enable detailed metrics for APIs that need method-level analysis.

Review access logging for an API Gateway deployment stage

Retain request records for the operating stage and verify actual log delivery.

Usage plan not associated with the deployed API stage

Associate the deployment’s stage with a usage plan when per-key usage management is needed.

Review API Gateway stage logging

Configure stage logs so API requests and errors can be investigated.

API Gateway stage not associated with a usage plan

Associate stages with a usage plan when per-key limits are required.

API Gateway X-Ray tracing disabled

Configure X-Ray to meet the REST API’s distributed-tracing needs.

Review API Gateway method authentication

Apply caller authentication and operation-specific permissions to methods that need protection.

Review API Gateway API key usage management

Apply API keys where usage plans are needed and configure caller authentication separately.

Review the TLS policy for an API Gateway custom domain

Restrict old protocols with a supported TLS policy and verify client compatibility.

Review the API Gateway compression threshold

Use a valid byte threshold when compression is needed.

Review API Gateway endpoint exposure

Restrict the network path and invocation permissions of internal APIs to the required scope.

API Gateway cache cluster not configured

Configure response caching for REST APIs that can use it safely.

Review API Gateway backend client certificate settings

Configure a client certificate when an HTTPS backend must verify calls from API Gateway.

API Gateway invocation scope for Lambda needs review

Restrict API Gateway’s Lambda permission to required API routes and check caller authentication separately.

Review AWS WAF protection for API Gateway

Apply required web request filtering to REST API stages and check its effect on legitimate requests.

AWS Config aggregator limited to selected Regions

Check that aggregation covers the Regions required for central assessment.

AWS Support policy without an attachment target

Attach support permissions to the identities that need them.

Review the access key age threshold

Manage both the access key age threshold and the actual rotation process.

Alexa Skill secret storage needs review

Keep Alexa authentication secrets out of template text and manage them in an access-controlled secret store.

Review Amazon MQ broker logging

Collect operational and audit logs appropriate for the broker engine.

Exposed Amplify app access token

Putting an Amplify app access token in a template leaves credentials in deployment code and history.

Exposed Amplify app Basic Auth password

A plaintext Amplify app Basic Auth password can expose credentials through the template.

Exposed Amplify app OAuth token

Putting an Amplify app OAuth token in a template leaves repository credentials in code and history.

Exposed Amplify branch Basic Auth password

Putting an Amplify branch Basic Auth password in a template leaves branch credentials in code.

Review load balancer attachment for an Auto Scaling group

Attach a load balancer when an Auto Scaling group needs request distribution.

CloudFormation stack notifications not configured

Configure an SNS topic for stack events.

Credentials are embedded in a CloudFormation template

Remove template secrets and use role-based access or a supported secret-management method.

Review CloudFront distribution and origin configuration

Review the CloudFront distribution and origins needed by the service, and manage origin access, HTTPS and application security separately.

Review CloudFront domain and certificate settings

Check the domain names, Region and TLS policy associated with the certificate.

CloudFront request logging is not configured

Collect CloudFront request logs and verify delivery.

Review the CloudFront TLS security policy

Review the minimum TLS version and ciphers used for CloudFront viewer connections.

CloudFront minimum TLS version is too low

Apply a suitable TLS security policy to CloudFront connections using a custom domain.

CloudFront allows HTTP viewer connections

Require HTTPS for viewer connections to CloudFront.

CloudFront is not associated with AWS WAF

Apply AWS WAF rules suited to the service through CloudFront.

Traffic between CloudFront and the origin is not encrypted

Use HTTPS between CloudFront and custom origin servers as well.

CloudTrail not integrated with CloudWatch Logs

Configure log delivery when CloudWatch is used to analyze audit events.

CloudTrail SNS notification topic not configured

Connect an SNS topic when log-file delivery notifications are needed.

CloudTrail multi-Region logging disabled

Configure the trail to record activity across the required Regions.

CloudTrail logs without a configured KMS key

Configure KMS encryption to meet log key-management requirements.

CloudTrail log file validation disabled

Use signed digests to verify CloudTrail log integrity.

CloudTrail trail logging is stopped

Enable event recording and log delivery for CloudTrail trails needed for auditing.

CloudTrail log bucket access logging needs review

Check request-log coverage and retention for the bucket storing CloudTrail logs.

CodeBuild artifact encryption key needs review

Check whether the encryption key for CodeBuild output artifacts meets your key-management requirements.

Cognito user pool without MFA

Configure the additional authentication required for password sign-in.

Review DocumentDB audit and profiler logging

Configure required log generation together with CloudWatch export.