AWS

AWS CloudFormationリソースのセキュリティと運用設定についての文書です。

文書一覧

文書 パス
ACM証明書のドメイン名が不正 cloudFormation/aws/wildcard_in_acm_certificate_domain_name
ALB が HTTP リスナーを使用 cloudFormation/aws/alb_listening_on_http
ALB に AWS WAF が未関連付け cloudFormation/aws/alb_is_not_integrated_with_waf
ALB のアクセスログが無効 cloudFormation/aws/elb_v2_alb_access_log_disabled
API Gateway の認証構成の確認 cloudFormation/aws/api_gateway_without_configured_authorizer
API Gateway の詳細 CloudWatch メトリクス設定の確認 cloudFormation/aws/cloudwatch_metrics_disabled
API Gateway デプロイメントのステージのアクセスログ設定の確認 cloudFormation/aws/api_gateway_deployment_without_access_log_setting
デプロイ先のAPIステージに使用量プランが未関連付け cloudFormation/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
API Gateway ステージのログ設定の確認 cloudFormation/aws/api_gateway_access_logging_disabled
API Gatewayステージに使用量プランが未関連付け cloudFormation/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API GatewayのX-Rayトレースが無効 cloudFormation/aws/api_gateway_xray_disabled
API Gateway メソッドの認証設定の確認 cloudFormation/aws/api_gateway_with_open_access
API Gateway の API キーによる使用量管理設定の確認 cloudFormation/aws/api_gateway_method_does_not_contains_an_api_key
API Gateway カスタムドメインの TLS ポリシーの確認 cloudFormation/aws/api_gateway_without_security_policy
API Gatewayの圧縮しきい値の確認 cloudFormation/aws/api_gateway_with_invalid_compression
API Gateway エンドポイントの公開範囲の確認 cloudFormation/aws/api_gateway_endpoint_config_is_not_private
API Gatewayのキャッシュクラスターが未設定 cloudFormation/aws/api_gateway_cache_cluster_disabled
API Gateway のバックエンド用クライアント証明書設定の確認 cloudFormation/aws/api_gateway_without_ssl_certificate
API GatewayからのLambda呼び出し範囲の確認 cloudFormation/aws/public_lambda_via_api_gateway
API Gateway の AWS WAF 保護設定の確認 cloudFormation/aws/api_gateway_without_waf
AWS Configアグリゲーターのリージョン範囲が限定されている cloudFormation/aws/config_configuration_aggregator_to_all_regions_disabled
AWS Supportポリシーの接続先が未指定 cloudFormation/aws/support_has_no_role_associated
アクセスキーの経過日数の基準を確認 cloudFormation/aws/access_key_not_rotated_within_90_days
Alexa Skillのシークレット保存方法の確認 cloudFormation/aws/alexa_skill_plaintext_client_secret_exposed
Amazon MQ ブローカーのログ設定の確認 cloudFormation/aws/mq_broker_logging_disabled
Amplify アプリのアクセストークンの露出 cloudFormation/aws/amplify_app_access_token_exposed
Amplify アプリの Basic Auth パスワードの露出 cloudFormation/aws/amplify_app_basic_auth_config_password_exposed
Amplify アプリの OAuth トークンの露出 cloudFormation/aws/amplify_app_oauth_token_exposed
Amplify ブランチの Basic Auth パスワードの露出 cloudFormation/aws/amplify_branch_basic_auth_config_password_exposed
Auto Scaling グループのロードバランサー接続を確認 cloudFormation/aws/auto_scaling_group_with_no_associated_elb
CloudFormationスタック通知が未設定 cloudFormation/aws/stack_notifications_disabled
CloudFormationテンプレートに認証情報を直接記載 cloudFormation/aws/cloudformation_specifying_credentials_not_safe
CloudFront のディストリビューションとオリジン設定の確認 cloudFormation/aws/cdn_configuration_is_missing
CloudFront のドメインと証明書設定の確認 cloudFormation/aws/vulnerable_default_ssl_certificate
CloudFront のリクエストログが未構成 cloudFormation/aws/cloudfront_logging_disabled
CloudFront の TLS セキュリティポリシーの確認 cloudFormation/aws/secure_ciphers_disabled
CloudFront の最小 TLS バージョンが不十分 cloudFormation/aws/cloudfront_without_minimum_protocol_tls_1.2
CloudFront が HTTP 接続を許可 cloudFormation/aws/cloudfront_viewer_protocol_policy_allows_http
CloudFront に WAF が未関連付け cloudFormation/aws/cloudfront_without_waf
CloudFront とオリジン間の通信が未暗号化 cloudFormation/aws/connection_between_cloudfront_origin_not_encrypted
CloudTrailとCloudWatch Logsが未連携 cloudFormation/aws/cloudtrail_not_integrated_with_cloudwatch
CloudTrailのSNS通知トピックが未設定 cloudFormation/aws/cloudtrail_sns_topic_name_undefined
CloudTrailのマルチリージョン記録が無効 cloudFormation/aws/cloudtrail_multi_region_disabled
CloudTrailログのKMSキーが未設定 cloudFormation/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrailログファイルの検証が無効 cloudFormation/aws/cloudtrail_log_file_validation_disabled
ログ配信が停止している CloudTrail 証跡 cloudFormation/aws/cloudtrail_logging_disabled
CloudTrailログ保存バケットのアクセスログ設定の確認 cloudFormation/aws/s3_bucket_cloudtrail_logging_disabled
CodeBuildアーティファクトの暗号化キーの確認 cloudFormation/aws/codebuild_not_encrypted
CognitoユーザープールのMFAが未設定 cloudFormation/aws/cognito_userpool_without_mfa
DocumentDB の監査・プロファイラーログ設定の確認 cloudFormation/aws/docdb_logging_disabled
DynamoDBのポイントインタイムリカバリが無効 cloudFormation/aws/dynamodb_table_point_in_time_recovery_disabled
DynamoDBの課金モードが不正 cloudFormation/aws/dynamodb_with_table_billing_mode_not_recommended
EBSボリュームのKMSキーが未指定 cloudFormation/aws/ebs_volume_without_kms_key_id
インスタンスに接続されていないEBSボリューム cloudFormation/aws/ebs_volume_not_attached_to_instances
ネットワークACLのルール番号が重複 cloudFormation/aws/ec2_network_acl_duplicate_rule
EC2 の詳細モニタリング設定の確認 cloudFormation/aws/ec2_instance_monitoring_disabled
デフォルト VPC を使用する EC2 インスタンス cloudFormation/aws/ec2_instance_using_default_vpc
EC2のEBS最適化設定を確認 cloudFormation/aws/ec2_not_ebs_optimized
EC2 インスタンスの IAM ロール関連付けを確認 cloudFormation/aws/ec2_instance_has_no_iam_role
EC2メタデータサービスのバージョン設定の確認 cloudFormation/aws/instance_uses_metadata_service_IMDSv1
EC2 がデフォルトセキュリティグループを使用 cloudFormation/aws/ec2_instance_using_default_security_group
ECRリポジトリでカスタマーマネージドKMSキーが未使用 cloudFormation/aws/ecr_repository_not_encrypted_with_CMK
ECRイメージのスキャン設定を確認 cloudFormation/aws/unscanned_ecr_image
ECRイメージタグを上書き可能 cloudFormation/aws/ecr_image_tag_not_immutable
ECS Container Insights 設定の確認 cloudFormation/aws/ecs_cluster_container_insights_disabled
ECSサービスのデプロイ時の可用性設定を確認 cloudFormation/aws/ecs_service_without_running_tasks
FargateタスクのCPUとメモリの組み合わせが不正 cloudFormation/aws/ecs_task_definition_invalid_cpu_or_memory
ECS タスクのネットワークモードを確認 cloudFormation/aws/ecs_task_definition_network_mode_not_recommended
ECSコンテナーのヘルスチェックが未設定 cloudFormation/aws/ecs_task_definition_healthcheck_missing
ECS タスクへのパブリック IP 割り当て cloudFormation/aws/ecs_services_assigned_with_public_ip_address
ECS サービスのロードバランサー接続を確認 cloudFormation/aws/ecs_no_load_balancer_attached
ECSサービスのロールがポリシーを参照している cloudFormation/aws/inline_policies_are_attached_to_ecs_service
ECS タスクの IAM ロールを確認 cloudFormation/aws/empty_roles_for_ecs_cluster_task_definitions
EFS のカスタマー管理 KMS キーの確認 cloudFormation/aws/efs_without_kms
EFSの転送時暗号化設定の確認 cloudFormation/aws/efs_volume_with_disabled_transit_encryption
EFSのタグが未設定 cloudFormation/aws/efs_without_tags
EKS ノードグループのリモートアクセス制限が不十分 cloudFormation/aws/eks_node_group_remote_access
ELB のアクセスログが無効 cloudFormation/aws/elb_access_log_disabled
ELB のアウトバウンド許可ルールの確認 cloudFormation/aws/elb_with_security_group_without_outbound_rules
ELB の転送時の暗号化設定の確認 cloudFormation/aws/elb_without_secure_protocol
ELB のインバウンド許可ルールの確認 cloudFormation/aws/elb_with_security_group_without_inbound_rules
ELB のプロトコルセキュリティ設定の確認 cloudFormation/aws/elb_using_insecure_protocols
EMR クラスターの VPC サブネット選択の確認 cloudFormation/aws/emr_wihout_vpc
EMR クラスターにセキュリティ設定が未接続 cloudFormation/aws/emr_cluster_without_security_configuration
EMR セキュリティ設定の暗号化が無効 cloudFormation/aws/emr_security_configuration_encryptions_enabled
ElastiCache の VPC とサブネットグループの確認 cloudFormation/aws/elasticache_without_vpc
ElastiCache のデフォルトポートの確認 cloudFormation/aws/elasticache_using_default_port
Memcached ノードが単一のアベイラビリティーゾーンに配置 cloudFormation/aws/elasticache_nodes_not_created_across_multi_az
ElastiCacheの転送時暗号化が無効 cloudFormation/aws/elasticache_with_disabled_transit_encryption
OpenSearchドメインでHTTPSが必須ではない cloudFormation/aws/elasticsearch_with_https_disabled
Elasticsearchドメインのアクセス主体の確認 cloudFormation/aws/elasticsearch_without_iam_authentication
Elasticsearch・OpenSearch の監査ログ設定の確認 cloudFormation/aws/elasticsearch_without_audit_logs
OpenSearchのノード間暗号化設定の確認 cloudFormation/aws/elasticsearch_domain_not_encrypted_node_to_node
OpenSearchとElasticsearchのスローログが未設定 cloudFormation/aws/elasticsearch_without_slow_logs
Elasticsearch・OpenSearch のエラーログ設定の確認 cloudFormation/aws/elasticsearch_without_es_application_logs
外部IDやMFAによる保護の確認が必要なクロスアカウントロールの信頼設定 cloudFormation/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
GameLift の受信ポート範囲を確認 cloudFormation/aws/gamelift_fleet_ec2_inbound_permissions_with_port_range
CloudFront の地理的制限の必要性を確認 cloudFormation/aws/geo_restriction_disabled
GitHubリポジトリの公開範囲の確認 cloudFormation/aws/github_repository_set_to_public
GuardDutyが無効 cloudFormation/aws/guardduty_detector_disabled
HTTP ポートが全アドレスに公開 cloudFormation/aws/http_port_open
IAM Access Analyzerが無効 cloudFormation/aws/iam_access_analyzer_not_enabled
グループに所属していないIAMユーザー cloudFormation/aws/iam_user_with_no_group
IAM グループでインラインポリシーを使用 cloudFormation/aws/iam_groups_inline_policies
IAMデータベース認証が無効なNeptuneクラスター cloudFormation/aws/neptune_cluster_with_iam_database_authentication_disabled
IAMパスワードの最小文字数が不足 cloudFormation/aws/iam_password_without_minimum_length
IAM ユーザーのアクセスキー数を確認 cloudFormation/aws/iam_user_too_many_access_keys
IAMユーザーのコンソールパスワード変更方針の確認 cloudFormation/aws/user_iam_missing_password_reset_required
IAMポリシーがユーザーに直接接続されている cloudFormation/aws/iam_policies_without_groups
EC2 インスタンスの VPC 関連付けの確認 cloudFormation/aws/instance_with_no_vpc
IoT ポリシーがすべてのリソースを許可 cloudFormation/aws/iot_policy_allows_wildcard_resource
IoT ポリシーがすべての操作を許可 cloudFormation/aws/iot_policy_allows_action_as_wildcard
KMSカスタマーマネージドキーの自動ローテーションが無効 cloudFormation/aws/cmk_rotation_disabled
KMSキーの自動ローテーション設定の確認 cloudFormation/aws/kms_enable_key_rotation_disabled
Elasticsearch の暗号化キー設定の確認 cloudFormation/aws/elasticsearch_domain_encryption_with_kms_disabled
LambdaのX-Rayアクティブトレースが未設定 cloudFormation/aws/lambda_functions_without_x-ray_tracing
Lambda関数のタグが未設定 cloudFormation/aws/lambda_function_without_tags
Lambdaの非同期失敗イベントの保存が未設定 cloudFormation/aws/lambda_function_without_dead_letter_queue
Lambdaの呼び出し権限が不適切 cloudFormation/aws/lambda_permission_misconfigured
Lambda の呼び出し主体にワイルドカードを使用 cloudFormation/aws/lambda_permission_principal_is_wildcard
Lambda環境変数からのAWS認証情報漏えいの可能性 cloudFormation/aws/hardcoded_aws_access_key_in_lambda
MSKブローカーログのエクスポート設定の確認 cloudFormation/aws/msk_cluster_logging_disabled
Neptune監査ログのエクスポート設定の確認 cloudFormation/aws/neptune_logging_is_disabled
Network ACL の TCP・UDP ポート範囲の確認 cloudFormation/aws/tcp_or_udp_protocol_network_acl_entry_allows_all_ports
全インターネットから RDP を許可するセキュリティグループ cloudFormation/aws/security_groups_unrestricted_access_to_rdp
RDS の IAM データベース認証が未使用 cloudFormation/aws/iam_database_auth_not_enabled
RDS の Multi-AZ 配置が未使用 cloudFormation/aws/rds_multi_az_deployment_disabled
RDS のデフォルトポートの確認 cloudFormation/aws/rds_using_default_port
RDSのバックアップ保持期間が不足 cloudFormation/aws/low_rds_backup_retention_period
RDSの削除保護が無効 cloudFormation/aws/rds_db_instance_with_deletion_protection_disabled
RDSスナップショットへのタグコピーが無効 cloudFormation/aws/tags_not_copied_to_rds_cluster_snapshot
RDSの自動マイナーバージョンアップグレード設定の確認 cloudFormation/aws/automatic_minor_upgrades_disabled
RDS の自動バックアップが無効 cloudFormation/aws/rds_with_backup_disabled
データベースクラスターの IAM 認証が未使用 cloudFormation/aws/iam_db_cluster_auth_not_enabled
Redshift のデフォルトポートの確認 cloudFormation/aws/redshift_using_default_port
Redshift クラスターの暗号化キーを確認 cloudFormation/aws/redshift_cluster_without_kms_cmk
Redshift の VPC とサブネットグループの確認 cloudFormation/aws/redshift_cluster_without_vpc
Redshift監査ログのエクスポート設定の確認 cloudFormation/aws/redshift_cluster_logging_disabled
VPCのデフォルトルートの用途を確認 cloudFormation/aws/routertable_with_default_routing
Route 53 の公開 DNS の CloudWatch ログ設定の確認 cloudFormation/aws/cloudwatch_logging_disabled
S3 の公開 ACL 無視設定の確認 cloudFormation/aws/s3_bucket_without_ignore_public_acl
S3 の公開 ACL ブロック設定の確認 cloudFormation/aws/s3_bucket_allows_public_acl
S3 公開ポリシーバケットのアクセス制限の確認 cloudFormation/aws/s3_bucket_without_restriction_of_public_bucket
S3 バケットのバージョニングが無効 cloudFormation/aws/s3_bucket_without_versioning
S3 書き込みの TLS 強制設定の確認 cloudFormation/aws/s3_bucket_without_ssl_in_write_actions
S3 CORS の許可範囲の確認 cloudFormation/aws/s3_bucket_with_unsecured_cors_rule
S3バケットのアクセスログ設定の確認 cloudFormation/aws/s3_bucket_logging_disabled
S3バケットポリシーが対象に関連付けられていない cloudFormation/aws/s3_bucket_should_have_bucket_policy
SNS の許可ポリシーで NotAction を使用 cloudFormation/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
SNSトピックのKMS暗号化が未設定 cloudFormation/aws/sns_topic_without_kms_master_key_id
SQS メッセージの保存時暗号化設定を確認 cloudFormation/aws/sqs_with_sse_disabled
SQS キューポリシーの公開アクセス cloudFormation/aws/sqs_policy_with_public_access
SageMaker エンドポイントのボリューム暗号化キーを確認 cloudFormation/aws/sagemaker_endpoint_config_should_specify_kms_key_id_attribute
SageMaker ノートブックの VPC サブネットが未指定 cloudFormation/aws/sagemaker_notebook_not_placed_in_vpc
SageMaker ノートブックの直接インターネットアクセス cloudFormation/aws/sagemaker_enabling_internet_access
Secrets ManagerのKMSキーが未指定 cloudFormation/aws/secrets_manager_should_specify_kms_key_id
Secrets Manager の暗号化キーを確認 cloudFormation/aws/secretsmanager_secret_without_kms
セキュリティグループのVPC選択を確認 cloudFormation/aws/security_groups_without_vpc_attached
セキュリティグループまたはルールの説明が未設定 cloudFormation/aws/security_group_rule_without_description
セキュリティグループの単一IP許可範囲を確認 cloudFormation/aws/security_group_ingress_has_cidr_not_recommended
Shield Advancedの必要性を確認 cloudFormation/aws/shield_advanced_not_in_use
SimpleDBドメインの利用を確認 cloudFormation/aws/sdb_domain_declared_as_a_resource
StackSet のアカウント除外時のスタック保持の確認 cloudFormation/aws/stack_retention_disabled
ユーザーデータ内のエンコードされた秘密鍵 cloudFormation/aws/user_data_contains_encoded_private_key
VPC Flow Logsの収集範囲の確認 cloudFormation/aws/vpc_flowlogs_disabled
VPC の Network Firewall 検査経路を確認 cloudFormation/aws/vpc_without_network_firewall
VPCのゲートウェイ接続上限を超過 cloudFormation/aws/vpc_attached_with_too_many_gateways
サブネットのないVPCの用途を確認 cloudFormation/aws/vpc_without_attached_subnet
特権モードが有効な AWS Batch ジョブ定義 cloudFormation/aws/batch_job_definition_with_privileged_container_properties
Network ACL ルールのポート範囲が重複 cloudFormation/aws/ec2_network_acl_overlapping_ports
AWS 所有キーを使用する DynamoDB cloudFormation/aws/dynamodb_with_aws_owned_cmk
S3 の公開ポリシーのブロック設定の確認 cloudFormation/aws/s3_bucket_with_public_policy
全アドレス範囲を許可するRDS関連の受信ルール cloudFormation/aws/db_security_group_with_public_scope
サブネットの CIDR に /0 を指定した RDS 構成 cloudFormation/aws/rds_associated_with_public_subnet
PublicReadWrite ACLが指定されたS3バケット cloudFormation/aws/s3_bucket_acl_allows_read_or_write_to_all_users
ワイルドカードのプリンシパルを使用する ECR ポリシー cloudFormation/aws/ecr_repository_is_publicly_accessible
Principal がワイルドカードまたは未指定の SNS ポリシー cloudFormation/aws/sns_topic_is_publicly_accessible
公開アクセス設定が有効または未指定のAWS DMSレプリケーションインスタンス cloudFormation/aws/amazon_dms_replication_instance_is_publicly_accessible
公開アクセスを有効にした RDS インスタンス cloudFormation/aws/rds_db_instance_publicly_accessible
Network ACL のプロトコル許可範囲を確認 cloudFormation/aws/ec2_permissive_network_acl_protocols
管理用ポートを外部に公開するセキュリティグループ cloudFormation/aws/security_groups_with_exhibited_admin_ports
ECSサービスロールの権限の見直し cloudFormation/aws/ecs_service_admin_role_is_present
データベースのデフォルトKMSキーの使用 cloudFormation/aws/default_kms_key_usage
ウェブ ACL の既定の許可ポリシーの確認 cloudFormation/aws/webacl_allow_defaultaction
広い送信元範囲を許可するセキュリティグループ cloudFormation/aws/db_security_group_open_to_large_scope
IAM ポリシーのデータ読み取り権限が過大 cloudFormation/aws/iam_policy_allows_for_data_exfiltration
Route 53 ホストゾーンのサービス用レコードの確認 cloudFormation/aws/route53_record_undefined
AWSアクセスキーの所有者と権限の確認が必要 cloudFormation/aws/root_account_has_active_access_keys
全アドレスから全ポートを許可するセキュリティグループ cloudFormation/aws/fully_open_ingress
削除操作にワイルドカードのプリンシパルを使う S3 ポリシー cloudFormation/aws/s3_bucket_allows_delete_actions_from_all_principals
ワイルドカードのプリンシパルに対する S3 の Get 権限 cloudFormation/aws/s3_bucket_allows_get_actions_from_all_principals
Put 操作にワイルドカードのプリンシパルを使う S3 ポリシー cloudFormation/aws/s3_bucket_allows_put_actions_from_all_principals
ワイルドカードのプリンシパルに対する S3 オブジェクトの復元権限 cloudFormation/aws/s3_bucket_allows_restore_actions_from_all_principals
ワイルドカードのプリンシパルに対する S3 の一覧取得権限 cloudFormation/aws/s3_bucket_allows_list_actions_from_all_principals
プリンシパルがワイルドカードまたは未指定のS3バケットポリシー cloudFormation/aws/s3_bucket_access_to_any_principal
ActionとPrincipalにワイルドカードを指定したS3バケットポリシー cloudFormation/aws/s3_bucket_with_all_permissions
すべてのユーザーに一覧取得を許可するS3バケットACL cloudFormation/aws/s3_bucket_acl_allows_read_to_all_users
AssumeRole 権限の対象がすべてのロール cloudFormation/aws/iam_policy_grants_assumerole_permission_across_all_services
IAM ロールのアカウント単位の信頼範囲を確認 cloudFormation/aws/iam_role_allows_all_principals_to_assume
KMS キーポリシーのプリンシパル制限を確認 cloudFormation/aws/kms_allows_wildcard_principal
全インターネットから全ポートを許可するセキュリティグループ cloudFormation/aws/security_groups_with_meta_ip
管理用・内部サービス用ポートを全アドレスに許可するEC2セキュリティグループ cloudFormation/aws/ec2_sensitive_port_is_publicly_exposed
管理用・内部サービス用ポートを全アドレスに許可するELBセキュリティグループ cloudFormation/aws/elb_sensitive_port_is_exposed_to_entire_network
セキュリティグループで全アドレスからの SSH を許可 cloudFormation/aws/security_groups_with_unrestricted_access_to_ssh
セキュリティグループの送信先が全アドレス cloudFormation/aws/security_group_egress_cidr_open_to_world
セキュリティグループの送信で全プロトコルを許可 cloudFormation/aws/security_group_egress_with_all_protocols
セキュリティグループの送信ポート範囲を確認 cloudFormation/aws/security_group_egress_with_port_range
セキュリティグループの受信で全プロトコルを許可 cloudFormation/aws/security_group_ingress_with_all_protocols
セキュリティグループの受信ポート範囲を確認 cloudFormation/aws/security_group_ingress_with_port_range
セキュリティグループで送信を無制限に許可 cloudFormation/aws/security_groups_allows_unrestricted_outbound_traffic
KMSキーの使用可能な状態の確認 cloudFormation/aws/cmk_is_unusable
ユーザーがいない IAM グループ cloudFormation/aws/iam_group_without_users
IAM ポリシーをユーザーに直接関連付け cloudFormation/aws/iam_policies_attached_to_user
IAM ポリシーリソースをユーザーに直接関連付け cloudFormation/aws/iam_policy_on_user
管理 IAM ポリシーをユーザーに直接関連付け cloudFormation/aws/iam_managed_policy_applied_to_a_user
サーバー側の暗号化が設定されていない Kinesis ストリーム cloudFormation/aws/kinesis_sse_not_configured
DynamoDB の暗号化キー設定の確認 cloudFormation/aws/dynamodb_table_not_encrypted
S3 バケットの既定の暗号化ポリシーの確認 cloudFormation/aws/s3_bucket_without_server_side_encryption
サブネットでパブリック IP の自動割り当てが有効 cloudFormation/aws/ec2_instance_subnet_has_public_ip_mapping_on_launch
サブネット経由での EC2 パブリックインスタンスの公開 cloudFormation/aws/ec2_public_instance_exposed_through_subnet
外部に許可されたポート範囲の確認 cloudFormation/aws/unknown_port_exposed_to_internet
EBS 暗号化の監視設定の確認 cloudFormation/aws/config_rule_for_encryption_volumes_disabled
Amazon MQ の暗号化キー設定の確認 cloudFormation/aws/amazon_mq_broker_encryption_disabled
EKS の暗号化キー設定の確認 cloudFormation/aws/eks_cluster_encryption_disabled
SageMaker ノートブックインスタンスの暗号化キー設定の確認 cloudFormation/aws/sagemaker_data_encryption_disabled
API Gateway キャッシュの暗号化が無効 cloudFormation/aws/api_gateway_cache_encrypted_disabled
EBS ボリュームの暗号化の確認 cloudFormation/aws/ebs_volume_encryption_disabled
暗号化が無効な EFS ファイルシステム cloudFormation/aws/efs_not_encrypted
暗号化が設定されていない WorkSpaces cloudFormation/aws/workspace_without_encryption
保存時暗号化が無効な DAX クラスター cloudFormation/aws/dax_cluster_not_encrypted
EBS ブロックデバイスの暗号化の確認 cloudFormation/aws/block_device_is_not_encrypted
データベースの保存時暗号化の確認 cloudFormation/aws/cmk_unencrypted_storage
ELB の TLS セキュリティポリシーの確認 cloudFormation/aws/elb_using_weak_ciphers
実行ロールを共有するLambda関数 cloudFormation/aws/lambda_functions_without_unique_iam_roles
公開アクセスが有効な Amazon MQ ブローカー cloudFormation/aws/mq_broker_is_publicly_accessible
公開アクセスが有効な Amazon MSK ブローカー cloudFormation/aws/msk_broker_is_publicly_accessible
Redshift の公開アクセス設定の確認 cloudFormation/aws/redshift_publicly_accessible
任意のAWSアカウントに一覧取得を許可するS3バケットACL cloudFormation/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
インターネットに公開された RDP ポート cloudFormation/aws/remote_desktop_port_open_to_internet
保存データの暗号化が無効な Neptune データベースクラスター cloudFormation/aws/neptune_database_cluster_encryption_disabled
RDS インスタンスの保存時の暗号化設定の確認 cloudFormation/aws/rds_storage_not_encrypted
RDS クラスターの保存時の暗号化設定の確認 cloudFormation/aws/rds_storage_encryption_disabled
Redshift の保存時の暗号化設定の確認 cloudFormation/aws/redshift_not_encrypted
MSK クラスターの暗号化設定の確認 cloudFormation/aws/msk_cluster_encryption_disabled
ECS と EFS 間の転送時暗号化の確認 cloudFormation/aws/ecs_cluster_not_encrypted_at_rest
保存時の暗号化が無効な ElastiCache Redis レプリケーショングループ cloudFormation/aws/elasticache_with_disabled_at_rest_encryption
保存時の暗号化が無効な Elasticsearch ドメイン cloudFormation/aws/elasticsearch_not_encrypted_at_rest
過剰な権限を持つ可能性があるLambda実行ロール cloudFormation/aws/lambda_functions_with_full_privileges
すべての操作とリソースを許可するIAMポリシー cloudFormation/aws/iam_policy_grants_full_permissions
IAM ポリシーが全権限を許可 cloudFormation/aws/iam_policies_with_full_privileges
KMSキーポリシーの権限の見直し cloudFormation/aws/kms_key_with_full_permissions
すべての送信元を許可するセキュリティグループのインバウンド規則 cloudFormation/aws/unrestricted_security_group_ingress
静的ウェブサイトホスティングが設定された S3 バケット cloudFormation/aws/s3_static_website_host_enabled
通信ルールが残っているデフォルトセキュリティグループ cloudFormation/aws/default_security_groups_with_unrestricted_traffic
DocumentDB クラスターの平文マスターパスワード cloudFormation/aws/docdb_cluster_master_password_in_plaintext
DMS MongoDB エンドポイント設定の平文パスワード cloudFormation/aws/dms_endpoint_mongo_db_settings_password_exposed
DMS エンドポイントの平文パスワード cloudFormation/aws/dms_endpoint_password_exposed
Directory Service Microsoft AD の平文パスワード cloudFormation/aws/directory_service_microsoft_ad_password_set_to_plaintext_or_default_ref
Directory Service Simple AD の平文パスワード cloudFormation/aws/directory_service_simple_ad_password_exposed
テンプレートからのIAMログインパスワード漏えいの可能性 cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext
Alexa ASK スキルの平文リフレッシュトークン cloudFormation/aws/refresh_token_is_exposed
Network ACL の拒否範囲を確認 cloudFormation/aws/ec2_network_acl_ineffective_denied_traffic

関連ページ262

ACM証明書のドメイン名が不正

証明書に有効なドメインと必要な範囲を指定してください。

ALB が HTTP リスナーを使用

クライアントと ALB の間の通信に HTTPS を使用します。

ALB に AWS WAF が未関連付け

公開 ALB に必要な AWS WAF のリクエストフィルタリングを構成します。

ALB のアクセスログが無効

ALB のアクセスログを S3 に保存し、リクエストを調査できるようにします。

API Gateway の認証構成の確認

保護する API ルートに適切な認証を関連付け、実際の権限確認を検証してください。

API Gateway の詳細 CloudWatch メトリクス設定の確認

メソッド別の分析が必要な API で詳細メトリクスを有効にしてください。

API Gateway デプロイメントのステージのアクセスログ設定の確認

運用ステージの要求記録を残し、実際のログ配信を確認してください。

デプロイ先のAPIステージに使用量プランが未関連付け

APIキーごとの使用量管理が必要なら、デプロイ先のステージを使用量プランに関連付けてください。

API Gateway ステージのログ設定の確認

API の要求やエラーを調査できるよう、ステージのログ収集を構成してください。

API Gatewayステージに使用量プランが未関連付け

キーごとの制限が必要なステージを使用量プランに関連付けてください。

API GatewayのX-Rayトレースが無効

REST APIの分散トレース要件に合わせてX-Rayを設定してください。

API Gateway メソッドの認証設定の確認

保護が必要なメソッドに呼び出し元の認証と操作別のアクセス権限を適用してください。

API Gateway の API キーによる使用量管理設定の確認

使用量プランが必要なメソッドに API キーを適用し、呼び出し元の認証は別途構成してください。

API Gateway カスタムドメインの TLS ポリシーの確認

対応する TLS ポリシーで古いプロトコルを制限し、クライアントの互換性を確認してください。

API Gatewayの圧縮しきい値の確認

圧縮が必要なら、有効なバイト単位のしきい値を指定してください。

API Gateway エンドポイントの公開範囲の確認

内部専用 API のネットワーク経路と呼び出し権限を必要な範囲に制限してください。

API Gatewayのキャッシュクラスターが未設定

キャッシュが適したREST APIにレスポンスキャッシュを設定してください。

API Gateway のバックエンド用クライアント証明書設定の確認

HTTPS バックエンドで API Gateway の呼び出しを確認する必要がある場合は、クライアント証明書を構成してください。

API GatewayからのLambda呼び出し範囲の確認

API GatewayのLambda権限を必要なAPI経路に制限し、利用者の認証も別途確認してください。

API Gateway の AWS WAF 保護設定の確認

REST API ステージに必要なウェブ要求のフィルタリングを適用し、正常な要求への影響を確認してください。

AWS Configアグリゲーターのリージョン範囲が限定されている

中央評価に必要なリージョンが集約範囲に含まれるか確認してください。

AWS Supportポリシーの接続先が未指定

サポート業務に必要な権限を、実際の担当者に接続してください。

アクセスキーの経過日数の基準を確認

アクセスキーの経過日数の基準と、実際の更新手順を合わせて管理します。

Alexa Skillのシークレット保存方法の確認

Alexaの認証用シークレットをテンプレートに直接書かず、アクセスを制限した保管先で管理してください。

Amazon MQ ブローカーのログ設定の確認

ブローカーのエンジンに合う運用・監査ログを収集してください。

Amplify アプリのアクセストークンの露出

Amplify アプリのアクセストークンをテンプレートに直接記述すると、認証情報がデプロイ用コードや履歴に残ります。

Amplify アプリの Basic Auth パスワードの露出

Amplify アプリの Basic Auth パスワードを平文で保存すると、テンプレートを通じて認証情報が露出するおそれがあります。

Amplify アプリの OAuth トークンの露出

Amplify アプリの OAuth トークンをテンプレートに直接記述すると、リポジトリ連携の認証情報がコードや履歴に残ります。

Amplify ブランチの Basic Auth パスワードの露出

Amplify ブランチの Basic Auth パスワードをテンプレートに直接記述すると、ブランチを保護する認証情報がコードに残ります。

Auto Scaling グループのロードバランサー接続を確認

リクエストの分散が必要な Auto Scaling グループにロードバランサーを接続します。

CloudFormationスタック通知が未設定

スタックイベントを受け取るSNSトピックを設定してください。

CloudFormationテンプレートに認証情報を直接記載

テンプレートからシークレットを除き、用途に合うロールやシークレット管理方法を使ってください。

CloudFront のディストリビューションとオリジン設定の確認

サービスに必要な CloudFront ディストリビューションとオリジンを確認し、オリジンへのアクセス、HTTPS、アプリケーションの保護を別途管理してください。

CloudFront のドメインと証明書設定の確認

証明書の対象ドメイン、リージョン、TLS ポリシーを確認してください。

CloudFront のリクエストログが未構成

CloudFront のリクエストログを収集し、配信結果を確認します。

CloudFront の TLS セキュリティポリシーの確認

CloudFront の閲覧者接続に使う最小 TLS バージョンと暗号スイートを確認してください。

CloudFront の最小 TLS バージョンが不十分

カスタムドメインの CloudFront 接続に適切な TLS セキュリティポリシーを適用します。

CloudFront が HTTP 接続を許可

CloudFront のビューワー接続に HTTPS を適用します。

CloudFront に WAF が未関連付け

CloudFront にサービスに合った AWS WAF ルールを適用します。

CloudFront とオリジン間の通信が未暗号化

CloudFront とカスタムオリジンサーバーの間にも HTTPS を使用します。

CloudTrailとCloudWatch Logsが未連携

CloudWatchで監査イベントを分析する場合は、ログ配信を設定してください。

CloudTrailのSNS通知トピックが未設定

ログファイルの配信通知が必要な場合は、SNSトピックを接続してください。

CloudTrailのマルチリージョン記録が無効

必要なリージョン全体のアクティビティを記録するように証跡を設定してください。

CloudTrailログのKMSキーが未設定

ログのキー管理要件に合わせてKMS暗号化を設定してください。

CloudTrailログファイルの検証が無効

署名付きダイジェストでCloudTrailログの完全性を確認してください。

ログ配信が停止している CloudTrail 証跡

監査に必要な CloudTrail 証跡のイベント記録とログ配信を有効にしてください。

CloudTrailログ保存バケットのアクセスログ設定の確認

CloudTrailログ保存バケットに対する要求の記録範囲と保存状態を確認してください。

CodeBuildアーティファクトの暗号化キーの確認

CodeBuildの出力アーティファクトに使用する暗号化キーが、組織のキー管理要件を満たすか確認してください。

CognitoユーザープールのMFAが未設定

パスワードでのサインインに必要な追加認証を設定してください。

DocumentDB の監査・プロファイラーログ設定の確認

必要なログの生成と CloudWatch へのエクスポートを合わせて構成してください。