AWS

Security and configuration guidance for AWS resources managed with Crossplane.

Documentation

Article Path
CloudFront distribution without a WAF web ACL crossplane/aws/cloudfront_without_waf
Review CloudFront access logging crossplane/aws/cloudfront_logging_disabled
Review the minimum TLS version for CloudFront viewers crossplane/aws/cloudfront_without_minimum_protocol_tls_1.2
Review CloudWatch log retention crossplane/aws/cloudwatch_without_retention_period_specified
Review DocumentDB audit and profiler logging crossplane/aws/docdb_logging_disabled
Review ECS Container Insights settings crossplane/aws/ecs_cluster_with_container_insights_disabled
Review the EFS customer managed KMS key crossplane/aws/efs_without_kms
Review SQS KMS encryption settings crossplane/aws/sqs_with_sse_disabled
RDS instance may receive a public IP address crossplane/aws/rds_db_instance_publicly_accessible
Security group rule allows all IPv4 addresses crossplane/aws/db_security_group_has_public_interface
EFS file system without configured encryption crossplane/aws/efs_not_encrypted
Review the ELB listener TLS security policy crossplane/aws/elb_using_weak_ciphers
Neptune DB cluster without configured storage encryption crossplane/aws/neptune_database_cluster_encryption_disabled
RDS instance without configured storage encryption crossplane/aws/db_instance_storage_not_encrypted

Related pages14

CloudFront distribution without a WAF web ACL

Associating an AWS WAF web ACL with CloudFront lets configured rules inspect and control web requests.

Review CloudFront access logging

Collect CloudFront access logs and verify delivery to retain request history for security analysis and troubleshooting.

Review the minimum TLS version for CloudFront viewers

Restrict obsolete TLS protocols on CloudFront viewer connections and apply a security policy appropriate for the certificate type.

Review CloudWatch log retention

Choose CloudWatch log retention to meet investigation, audit and data-retention needs.

Review DocumentDB audit and profiler logging

Configure both DocumentDB audit or profiler log generation and CloudWatch export to retain the records needed for investigation.

Review ECS Container Insights settings

Check the effective ECS Container Insights setting and CloudWatch metric collection.

Review the EFS customer managed KMS key

Review EFS encryption separately from requirements for a customer managed KMS key.

Review SQS KMS encryption settings

Check the actual SQS server-side encryption mode and key-management requirements, and configure a KMS key and permissions when needed.

RDS instance may receive a public IP address

Disable public access for internal RDS instances and configure private connectivity and security groups to reduce unnecessary external access.

Security group rule allows all IPv4 addresses

A security group rule allowing every IPv4 address can permit unwanted connection attempts to reachable resources.

EFS file system without configured encryption

Encrypt data at rest in EFS file systems created through Crossplane.

Review the ELB listener TLS security policy

Use a supported security policy for an ELB HTTPS listener and restrict obsolete TLS protocols and weak cipher suites.

Neptune DB cluster without configured storage encryption

Protect Neptune graph data and backups with encryption at rest.

RDS instance without configured storage encryption

Encrypt RDS storage created through Crossplane and migrate existing data through supported procedures.