Documentation
| Article | Path |
|---|---|
| CloudFront distribution without a WAF web ACL | crossplane/aws/cloudfront_without_waf |
| Review CloudFront access logging | crossplane/aws/cloudfront_logging_disabled |
| Review the minimum TLS version for CloudFront viewers | crossplane/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| Review CloudWatch log retention | crossplane/aws/cloudwatch_without_retention_period_specified |
| Review DocumentDB audit and profiler logging | crossplane/aws/docdb_logging_disabled |
| Review ECS Container Insights settings | crossplane/aws/ecs_cluster_with_container_insights_disabled |
| Review the EFS customer managed KMS key | crossplane/aws/efs_without_kms |
| Review SQS KMS encryption settings | crossplane/aws/sqs_with_sse_disabled |
| RDS instance may receive a public IP address | crossplane/aws/rds_db_instance_publicly_accessible |
| Security group rule allows all IPv4 addresses | crossplane/aws/db_security_group_has_public_interface |
| EFS file system without configured encryption | crossplane/aws/efs_not_encrypted |
| Review the ELB listener TLS security policy | crossplane/aws/elb_using_weak_ciphers |
| Neptune DB cluster without configured storage encryption | crossplane/aws/neptune_database_cluster_encryption_disabled |
| RDS instance without configured storage encryption | crossplane/aws/db_instance_storage_not_encrypted |