文書一覧
| 文書 | パス |
|---|---|
| ACM証明書のドメイン名が不正 | cloudFormation/aws/wildcard_in_acm_certificate_domain_name |
| ALB が HTTP リスナーを使用 | cloudFormation/aws/alb_listening_on_http |
| ALB に AWS WAF が未関連付け | cloudFormation/aws/alb_is_not_integrated_with_waf |
| ALB のアクセスログが無効 | cloudFormation/aws/elb_v2_alb_access_log_disabled |
| API Gateway の認証構成の確認 | cloudFormation/aws/api_gateway_without_configured_authorizer |
| API Gateway の詳細 CloudWatch メトリクス設定の確認 | cloudFormation/aws/cloudwatch_metrics_disabled |
| API Gateway デプロイメントのステージのアクセスログ設定の確認 | cloudFormation/aws/api_gateway_deployment_without_access_log_setting |
| デプロイ先のAPIステージに使用量プランが未関連付け | cloudFormation/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated |
| API Gateway ステージのログ設定の確認 | cloudFormation/aws/api_gateway_access_logging_disabled |
| API Gatewayステージに使用量プランが未関連付け | cloudFormation/aws/api_gateway_stage_without_api_gateway_usage_plan_associated |
| API GatewayのX-Rayトレースが無効 | cloudFormation/aws/api_gateway_xray_disabled |
| API Gateway メソッドの認証設定の確認 | cloudFormation/aws/api_gateway_with_open_access |
| API Gateway の API キーによる使用量管理設定の確認 | cloudFormation/aws/api_gateway_method_does_not_contains_an_api_key |
| API Gateway カスタムドメインの TLS ポリシーの確認 | cloudFormation/aws/api_gateway_without_security_policy |
| API Gatewayの圧縮しきい値の確認 | cloudFormation/aws/api_gateway_with_invalid_compression |
| API Gateway エンドポイントの公開範囲の確認 | cloudFormation/aws/api_gateway_endpoint_config_is_not_private |
| API Gatewayのキャッシュクラスターが未設定 | cloudFormation/aws/api_gateway_cache_cluster_disabled |
| API Gateway のバックエンド用クライアント証明書設定の確認 | cloudFormation/aws/api_gateway_without_ssl_certificate |
| API GatewayからのLambda呼び出し範囲の確認 | cloudFormation/aws/public_lambda_via_api_gateway |
| API Gateway の AWS WAF 保護設定の確認 | cloudFormation/aws/api_gateway_without_waf |
| AWS Configアグリゲーターのリージョン範囲が限定されている | cloudFormation/aws/config_configuration_aggregator_to_all_regions_disabled |
| AWS Supportポリシーの接続先が未指定 | cloudFormation/aws/support_has_no_role_associated |
| アクセスキーの経過日数の基準を確認 | cloudFormation/aws/access_key_not_rotated_within_90_days |
| Alexa Skillのシークレット保存方法の確認 | cloudFormation/aws/alexa_skill_plaintext_client_secret_exposed |
| Amazon MQ ブローカーのログ設定の確認 | cloudFormation/aws/mq_broker_logging_disabled |
| Amplify アプリのアクセストークンの露出 | cloudFormation/aws/amplify_app_access_token_exposed |
| Amplify アプリの Basic Auth パスワードの露出 | cloudFormation/aws/amplify_app_basic_auth_config_password_exposed |
| Amplify アプリの OAuth トークンの露出 | cloudFormation/aws/amplify_app_oauth_token_exposed |
| Amplify ブランチの Basic Auth パスワードの露出 | cloudFormation/aws/amplify_branch_basic_auth_config_password_exposed |
| Auto Scaling グループのロードバランサー接続を確認 | cloudFormation/aws/auto_scaling_group_with_no_associated_elb |
| CloudFormationスタック通知が未設定 | cloudFormation/aws/stack_notifications_disabled |
| CloudFormationテンプレートに認証情報を直接記載 | cloudFormation/aws/cloudformation_specifying_credentials_not_safe |
| CloudFront のディストリビューションとオリジン設定の確認 | cloudFormation/aws/cdn_configuration_is_missing |
| CloudFront のドメインと証明書設定の確認 | cloudFormation/aws/vulnerable_default_ssl_certificate |
| CloudFront のリクエストログが未構成 | cloudFormation/aws/cloudfront_logging_disabled |
| CloudFront の TLS セキュリティポリシーの確認 | cloudFormation/aws/secure_ciphers_disabled |
| CloudFront の最小 TLS バージョンが不十分 | cloudFormation/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| CloudFront が HTTP 接続を許可 | cloudFormation/aws/cloudfront_viewer_protocol_policy_allows_http |
| CloudFront に WAF が未関連付け | cloudFormation/aws/cloudfront_without_waf |
| CloudFront とオリジン間の通信が未暗号化 | cloudFormation/aws/connection_between_cloudfront_origin_not_encrypted |
| CloudTrailとCloudWatch Logsが未連携 | cloudFormation/aws/cloudtrail_not_integrated_with_cloudwatch |
| CloudTrailのSNS通知トピックが未設定 | cloudFormation/aws/cloudtrail_sns_topic_name_undefined |
| CloudTrailのマルチリージョン記録が無効 | cloudFormation/aws/cloudtrail_multi_region_disabled |
| CloudTrailログのKMSキーが未設定 | cloudFormation/aws/cloudtrail_log_files_not_encrypted_with_kms |
| CloudTrailログファイルの検証が無効 | cloudFormation/aws/cloudtrail_log_file_validation_disabled |
| ログ配信が停止している CloudTrail 証跡 | cloudFormation/aws/cloudtrail_logging_disabled |
| CloudTrailログ保存バケットのアクセスログ設定の確認 | cloudFormation/aws/s3_bucket_cloudtrail_logging_disabled |
| CodeBuildアーティファクトの暗号化キーの確認 | cloudFormation/aws/codebuild_not_encrypted |
| CognitoユーザープールのMFAが未設定 | cloudFormation/aws/cognito_userpool_without_mfa |
| DocumentDB の監査・プロファイラーログ設定の確認 | cloudFormation/aws/docdb_logging_disabled |
| DynamoDBのポイントインタイムリカバリが無効 | cloudFormation/aws/dynamodb_table_point_in_time_recovery_disabled |
| DynamoDBの課金モードが不正 | cloudFormation/aws/dynamodb_with_table_billing_mode_not_recommended |
| EBSボリュームのKMSキーが未指定 | cloudFormation/aws/ebs_volume_without_kms_key_id |
| インスタンスに接続されていないEBSボリューム | cloudFormation/aws/ebs_volume_not_attached_to_instances |
| ネットワークACLのルール番号が重複 | cloudFormation/aws/ec2_network_acl_duplicate_rule |
| EC2 の詳細モニタリング設定の確認 | cloudFormation/aws/ec2_instance_monitoring_disabled |
| デフォルト VPC を使用する EC2 インスタンス | cloudFormation/aws/ec2_instance_using_default_vpc |
| EC2のEBS最適化設定を確認 | cloudFormation/aws/ec2_not_ebs_optimized |
| EC2 インスタンスの IAM ロール関連付けを確認 | cloudFormation/aws/ec2_instance_has_no_iam_role |
| EC2メタデータサービスのバージョン設定の確認 | cloudFormation/aws/instance_uses_metadata_service_IMDSv1 |
| EC2 がデフォルトセキュリティグループを使用 | cloudFormation/aws/ec2_instance_using_default_security_group |
| ECRリポジトリでカスタマーマネージドKMSキーが未使用 | cloudFormation/aws/ecr_repository_not_encrypted_with_CMK |
| ECRイメージのスキャン設定を確認 | cloudFormation/aws/unscanned_ecr_image |
| ECRイメージタグを上書き可能 | cloudFormation/aws/ecr_image_tag_not_immutable |
| ECS Container Insights 設定の確認 | cloudFormation/aws/ecs_cluster_container_insights_disabled |
| ECSサービスのデプロイ時の可用性設定を確認 | cloudFormation/aws/ecs_service_without_running_tasks |
| FargateタスクのCPUとメモリの組み合わせが不正 | cloudFormation/aws/ecs_task_definition_invalid_cpu_or_memory |
| ECS タスクのネットワークモードを確認 | cloudFormation/aws/ecs_task_definition_network_mode_not_recommended |
| ECSコンテナーのヘルスチェックが未設定 | cloudFormation/aws/ecs_task_definition_healthcheck_missing |
| ECS タスクへのパブリック IP 割り当て | cloudFormation/aws/ecs_services_assigned_with_public_ip_address |
| ECS サービスのロードバランサー接続を確認 | cloudFormation/aws/ecs_no_load_balancer_attached |
| ECSサービスのロールがポリシーを参照している | cloudFormation/aws/inline_policies_are_attached_to_ecs_service |
| ECS タスクの IAM ロールを確認 | cloudFormation/aws/empty_roles_for_ecs_cluster_task_definitions |
| EFS のカスタマー管理 KMS キーの確認 | cloudFormation/aws/efs_without_kms |
| EFSの転送時暗号化設定の確認 | cloudFormation/aws/efs_volume_with_disabled_transit_encryption |
| EFSのタグが未設定 | cloudFormation/aws/efs_without_tags |
| EKS ノードグループのリモートアクセス制限が不十分 | cloudFormation/aws/eks_node_group_remote_access |
| ELB のアクセスログが無効 | cloudFormation/aws/elb_access_log_disabled |
| ELB のアウトバウンド許可ルールの確認 | cloudFormation/aws/elb_with_security_group_without_outbound_rules |
| ELB の転送時の暗号化設定の確認 | cloudFormation/aws/elb_without_secure_protocol |
| ELB のインバウンド許可ルールの確認 | cloudFormation/aws/elb_with_security_group_without_inbound_rules |
| ELB のプロトコルセキュリティ設定の確認 | cloudFormation/aws/elb_using_insecure_protocols |
| EMR クラスターの VPC サブネット選択の確認 | cloudFormation/aws/emr_wihout_vpc |
| EMR クラスターにセキュリティ設定が未接続 | cloudFormation/aws/emr_cluster_without_security_configuration |
| EMR セキュリティ設定の暗号化が無効 | cloudFormation/aws/emr_security_configuration_encryptions_enabled |
| ElastiCache の VPC とサブネットグループの確認 | cloudFormation/aws/elasticache_without_vpc |
| ElastiCache のデフォルトポートの確認 | cloudFormation/aws/elasticache_using_default_port |
| Memcached ノードが単一のアベイラビリティーゾーンに配置 | cloudFormation/aws/elasticache_nodes_not_created_across_multi_az |
| ElastiCacheの転送時暗号化が無効 | cloudFormation/aws/elasticache_with_disabled_transit_encryption |
| OpenSearchドメインでHTTPSが必須ではない | cloudFormation/aws/elasticsearch_with_https_disabled |
| Elasticsearchドメインのアクセス主体の確認 | cloudFormation/aws/elasticsearch_without_iam_authentication |
| Elasticsearch・OpenSearch の監査ログ設定の確認 | cloudFormation/aws/elasticsearch_without_audit_logs |
| OpenSearchのノード間暗号化設定の確認 | cloudFormation/aws/elasticsearch_domain_not_encrypted_node_to_node |
| OpenSearchとElasticsearchのスローログが未設定 | cloudFormation/aws/elasticsearch_without_slow_logs |
| Elasticsearch・OpenSearch のエラーログ設定の確認 | cloudFormation/aws/elasticsearch_without_es_application_logs |
| 外部IDやMFAによる保護の確認が必要なクロスアカウントロールの信頼設定 | cloudFormation/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa |
| GameLift の受信ポート範囲を確認 | cloudFormation/aws/gamelift_fleet_ec2_inbound_permissions_with_port_range |
| CloudFront の地理的制限の必要性を確認 | cloudFormation/aws/geo_restriction_disabled |
| GitHubリポジトリの公開範囲の確認 | cloudFormation/aws/github_repository_set_to_public |
| GuardDutyが無効 | cloudFormation/aws/guardduty_detector_disabled |
| HTTP ポートが全アドレスに公開 | cloudFormation/aws/http_port_open |
| IAM Access Analyzerが無効 | cloudFormation/aws/iam_access_analyzer_not_enabled |
| グループに所属していないIAMユーザー | cloudFormation/aws/iam_user_with_no_group |
| IAM グループでインラインポリシーを使用 | cloudFormation/aws/iam_groups_inline_policies |
| IAMデータベース認証が無効なNeptuneクラスター | cloudFormation/aws/neptune_cluster_with_iam_database_authentication_disabled |
| IAMパスワードの最小文字数が不足 | cloudFormation/aws/iam_password_without_minimum_length |
| IAM ユーザーのアクセスキー数を確認 | cloudFormation/aws/iam_user_too_many_access_keys |
| IAMユーザーのコンソールパスワード変更方針の確認 | cloudFormation/aws/user_iam_missing_password_reset_required |
| IAMポリシーがユーザーに直接接続されている | cloudFormation/aws/iam_policies_without_groups |
| EC2 インスタンスの VPC 関連付けの確認 | cloudFormation/aws/instance_with_no_vpc |
| IoT ポリシーがすべてのリソースを許可 | cloudFormation/aws/iot_policy_allows_wildcard_resource |
| IoT ポリシーがすべての操作を許可 | cloudFormation/aws/iot_policy_allows_action_as_wildcard |
| KMSカスタマーマネージドキーの自動ローテーションが無効 | cloudFormation/aws/cmk_rotation_disabled |
| KMSキーの自動ローテーション設定の確認 | cloudFormation/aws/kms_enable_key_rotation_disabled |
| Elasticsearch の暗号化キー設定の確認 | cloudFormation/aws/elasticsearch_domain_encryption_with_kms_disabled |
| LambdaのX-Rayアクティブトレースが未設定 | cloudFormation/aws/lambda_functions_without_x-ray_tracing |
| Lambda関数のタグが未設定 | cloudFormation/aws/lambda_function_without_tags |
| Lambdaの非同期失敗イベントの保存が未設定 | cloudFormation/aws/lambda_function_without_dead_letter_queue |
| Lambdaの呼び出し権限が不適切 | cloudFormation/aws/lambda_permission_misconfigured |
| Lambda の呼び出し主体にワイルドカードを使用 | cloudFormation/aws/lambda_permission_principal_is_wildcard |
| Lambda環境変数からのAWS認証情報漏えいの可能性 | cloudFormation/aws/hardcoded_aws_access_key_in_lambda |
| MSKブローカーログのエクスポート設定の確認 | cloudFormation/aws/msk_cluster_logging_disabled |
| Neptune監査ログのエクスポート設定の確認 | cloudFormation/aws/neptune_logging_is_disabled |
| Network ACL の TCP・UDP ポート範囲の確認 | cloudFormation/aws/tcp_or_udp_protocol_network_acl_entry_allows_all_ports |
| 全インターネットから RDP を許可するセキュリティグループ | cloudFormation/aws/security_groups_unrestricted_access_to_rdp |
| RDS の IAM データベース認証が未使用 | cloudFormation/aws/iam_database_auth_not_enabled |
| RDS の Multi-AZ 配置が未使用 | cloudFormation/aws/rds_multi_az_deployment_disabled |
| RDS のデフォルトポートの確認 | cloudFormation/aws/rds_using_default_port |
| RDSのバックアップ保持期間が不足 | cloudFormation/aws/low_rds_backup_retention_period |
| RDSの削除保護が無効 | cloudFormation/aws/rds_db_instance_with_deletion_protection_disabled |
| RDSスナップショットへのタグコピーが無効 | cloudFormation/aws/tags_not_copied_to_rds_cluster_snapshot |
| RDSの自動マイナーバージョンアップグレード設定の確認 | cloudFormation/aws/automatic_minor_upgrades_disabled |
| RDS の自動バックアップが無効 | cloudFormation/aws/rds_with_backup_disabled |
| データベースクラスターの IAM 認証が未使用 | cloudFormation/aws/iam_db_cluster_auth_not_enabled |
| Redshift のデフォルトポートの確認 | cloudFormation/aws/redshift_using_default_port |
| Redshift クラスターの暗号化キーを確認 | cloudFormation/aws/redshift_cluster_without_kms_cmk |
| Redshift の VPC とサブネットグループの確認 | cloudFormation/aws/redshift_cluster_without_vpc |
| Redshift監査ログのエクスポート設定の確認 | cloudFormation/aws/redshift_cluster_logging_disabled |
| VPCのデフォルトルートの用途を確認 | cloudFormation/aws/routertable_with_default_routing |
| Route 53 の公開 DNS の CloudWatch ログ設定の確認 | cloudFormation/aws/cloudwatch_logging_disabled |
| S3 の公開 ACL 無視設定の確認 | cloudFormation/aws/s3_bucket_without_ignore_public_acl |
| S3 の公開 ACL ブロック設定の確認 | cloudFormation/aws/s3_bucket_allows_public_acl |
| S3 公開ポリシーバケットのアクセス制限の確認 | cloudFormation/aws/s3_bucket_without_restriction_of_public_bucket |
| S3 バケットのバージョニングが無効 | cloudFormation/aws/s3_bucket_without_versioning |
| S3 書き込みの TLS 強制設定の確認 | cloudFormation/aws/s3_bucket_without_ssl_in_write_actions |
| S3 CORS の許可範囲の確認 | cloudFormation/aws/s3_bucket_with_unsecured_cors_rule |
| S3バケットのアクセスログ設定の確認 | cloudFormation/aws/s3_bucket_logging_disabled |
| S3バケットポリシーが対象に関連付けられていない | cloudFormation/aws/s3_bucket_should_have_bucket_policy |
| SNS の許可ポリシーで NotAction を使用 | cloudFormation/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously |
| SNSトピックのKMS暗号化が未設定 | cloudFormation/aws/sns_topic_without_kms_master_key_id |
| SQS メッセージの保存時暗号化設定を確認 | cloudFormation/aws/sqs_with_sse_disabled |
| SQS キューポリシーの公開アクセス | cloudFormation/aws/sqs_policy_with_public_access |
| SageMaker エンドポイントのボリューム暗号化キーを確認 | cloudFormation/aws/sagemaker_endpoint_config_should_specify_kms_key_id_attribute |
| SageMaker ノートブックの VPC サブネットが未指定 | cloudFormation/aws/sagemaker_notebook_not_placed_in_vpc |
| SageMaker ノートブックの直接インターネットアクセス | cloudFormation/aws/sagemaker_enabling_internet_access |
| Secrets ManagerのKMSキーが未指定 | cloudFormation/aws/secrets_manager_should_specify_kms_key_id |
| Secrets Manager の暗号化キーを確認 | cloudFormation/aws/secretsmanager_secret_without_kms |
| セキュリティグループのVPC選択を確認 | cloudFormation/aws/security_groups_without_vpc_attached |
| セキュリティグループまたはルールの説明が未設定 | cloudFormation/aws/security_group_rule_without_description |
| セキュリティグループの単一IP許可範囲を確認 | cloudFormation/aws/security_group_ingress_has_cidr_not_recommended |
| Shield Advancedの必要性を確認 | cloudFormation/aws/shield_advanced_not_in_use |
| SimpleDBドメインの利用を確認 | cloudFormation/aws/sdb_domain_declared_as_a_resource |
| StackSet のアカウント除外時のスタック保持の確認 | cloudFormation/aws/stack_retention_disabled |
| ユーザーデータ内のエンコードされた秘密鍵 | cloudFormation/aws/user_data_contains_encoded_private_key |
| VPC Flow Logsの収集範囲の確認 | cloudFormation/aws/vpc_flowlogs_disabled |
| VPC の Network Firewall 検査経路を確認 | cloudFormation/aws/vpc_without_network_firewall |
| VPCのゲートウェイ接続上限を超過 | cloudFormation/aws/vpc_attached_with_too_many_gateways |
| サブネットのないVPCの用途を確認 | cloudFormation/aws/vpc_without_attached_subnet |
| 特権モードが有効な AWS Batch ジョブ定義 | cloudFormation/aws/batch_job_definition_with_privileged_container_properties |
| Network ACL ルールのポート範囲が重複 | cloudFormation/aws/ec2_network_acl_overlapping_ports |
| AWS 所有キーを使用する DynamoDB | cloudFormation/aws/dynamodb_with_aws_owned_cmk |
| S3 の公開ポリシーのブロック設定の確認 | cloudFormation/aws/s3_bucket_with_public_policy |
| 全アドレス範囲を許可するRDS関連の受信ルール | cloudFormation/aws/db_security_group_with_public_scope |
| サブネットの CIDR に /0 を指定した RDS 構成 | cloudFormation/aws/rds_associated_with_public_subnet |
| PublicReadWrite ACLが指定されたS3バケット | cloudFormation/aws/s3_bucket_acl_allows_read_or_write_to_all_users |
| ワイルドカードのプリンシパルを使用する ECR ポリシー | cloudFormation/aws/ecr_repository_is_publicly_accessible |
| Principal がワイルドカードまたは未指定の SNS ポリシー | cloudFormation/aws/sns_topic_is_publicly_accessible |
| 公開アクセス設定が有効または未指定のAWS DMSレプリケーションインスタンス | cloudFormation/aws/amazon_dms_replication_instance_is_publicly_accessible |
| 公開アクセスを有効にした RDS インスタンス | cloudFormation/aws/rds_db_instance_publicly_accessible |
| Network ACL のプロトコル許可範囲を確認 | cloudFormation/aws/ec2_permissive_network_acl_protocols |
| 管理用ポートを外部に公開するセキュリティグループ | cloudFormation/aws/security_groups_with_exhibited_admin_ports |
| ECSサービスロールの権限の見直し | cloudFormation/aws/ecs_service_admin_role_is_present |
| データベースのデフォルトKMSキーの使用 | cloudFormation/aws/default_kms_key_usage |
| ウェブ ACL の既定の許可ポリシーの確認 | cloudFormation/aws/webacl_allow_defaultaction |
| 広い送信元範囲を許可するセキュリティグループ | cloudFormation/aws/db_security_group_open_to_large_scope |
| IAM ポリシーのデータ読み取り権限が過大 | cloudFormation/aws/iam_policy_allows_for_data_exfiltration |
| Route 53 ホストゾーンのサービス用レコードの確認 | cloudFormation/aws/route53_record_undefined |
| AWSアクセスキーの所有者と権限の確認が必要 | cloudFormation/aws/root_account_has_active_access_keys |
| 全アドレスから全ポートを許可するセキュリティグループ | cloudFormation/aws/fully_open_ingress |
| 削除操作にワイルドカードのプリンシパルを使う S3 ポリシー | cloudFormation/aws/s3_bucket_allows_delete_actions_from_all_principals |
| ワイルドカードのプリンシパルに対する S3 の Get 権限 | cloudFormation/aws/s3_bucket_allows_get_actions_from_all_principals |
| Put 操作にワイルドカードのプリンシパルを使う S3 ポリシー | cloudFormation/aws/s3_bucket_allows_put_actions_from_all_principals |
| ワイルドカードのプリンシパルに対する S3 オブジェクトの復元権限 | cloudFormation/aws/s3_bucket_allows_restore_actions_from_all_principals |
| ワイルドカードのプリンシパルに対する S3 の一覧取得権限 | cloudFormation/aws/s3_bucket_allows_list_actions_from_all_principals |
| プリンシパルがワイルドカードまたは未指定のS3バケットポリシー | cloudFormation/aws/s3_bucket_access_to_any_principal |
| ActionとPrincipalにワイルドカードを指定したS3バケットポリシー | cloudFormation/aws/s3_bucket_with_all_permissions |
| すべてのユーザーに一覧取得を許可するS3バケットACL | cloudFormation/aws/s3_bucket_acl_allows_read_to_all_users |
| AssumeRole 権限の対象がすべてのロール | cloudFormation/aws/iam_policy_grants_assumerole_permission_across_all_services |
| IAM ロールのアカウント単位の信頼範囲を確認 | cloudFormation/aws/iam_role_allows_all_principals_to_assume |
| KMS キーポリシーのプリンシパル制限を確認 | cloudFormation/aws/kms_allows_wildcard_principal |
| 全インターネットから全ポートを許可するセキュリティグループ | cloudFormation/aws/security_groups_with_meta_ip |
| 管理用・内部サービス用ポートを全アドレスに許可するEC2セキュリティグループ | cloudFormation/aws/ec2_sensitive_port_is_publicly_exposed |
| 管理用・内部サービス用ポートを全アドレスに許可するELBセキュリティグループ | cloudFormation/aws/elb_sensitive_port_is_exposed_to_entire_network |
| セキュリティグループで全アドレスからの SSH を許可 | cloudFormation/aws/security_groups_with_unrestricted_access_to_ssh |
| セキュリティグループの送信先が全アドレス | cloudFormation/aws/security_group_egress_cidr_open_to_world |
| セキュリティグループの送信で全プロトコルを許可 | cloudFormation/aws/security_group_egress_with_all_protocols |
| セキュリティグループの送信ポート範囲を確認 | cloudFormation/aws/security_group_egress_with_port_range |
| セキュリティグループの受信で全プロトコルを許可 | cloudFormation/aws/security_group_ingress_with_all_protocols |
| セキュリティグループの受信ポート範囲を確認 | cloudFormation/aws/security_group_ingress_with_port_range |
| セキュリティグループで送信を無制限に許可 | cloudFormation/aws/security_groups_allows_unrestricted_outbound_traffic |
| KMSキーの使用可能な状態の確認 | cloudFormation/aws/cmk_is_unusable |
| ユーザーがいない IAM グループ | cloudFormation/aws/iam_group_without_users |
| IAM ポリシーをユーザーに直接関連付け | cloudFormation/aws/iam_policies_attached_to_user |
| IAM ポリシーリソースをユーザーに直接関連付け | cloudFormation/aws/iam_policy_on_user |
| 管理 IAM ポリシーをユーザーに直接関連付け | cloudFormation/aws/iam_managed_policy_applied_to_a_user |
| サーバー側の暗号化が設定されていない Kinesis ストリーム | cloudFormation/aws/kinesis_sse_not_configured |
| DynamoDB の暗号化キー設定の確認 | cloudFormation/aws/dynamodb_table_not_encrypted |
| S3 バケットの既定の暗号化ポリシーの確認 | cloudFormation/aws/s3_bucket_without_server_side_encryption |
| サブネットでパブリック IP の自動割り当てが有効 | cloudFormation/aws/ec2_instance_subnet_has_public_ip_mapping_on_launch |
| サブネット経由での EC2 パブリックインスタンスの公開 | cloudFormation/aws/ec2_public_instance_exposed_through_subnet |
| 外部に許可されたポート範囲の確認 | cloudFormation/aws/unknown_port_exposed_to_internet |
| EBS 暗号化の監視設定の確認 | cloudFormation/aws/config_rule_for_encryption_volumes_disabled |
| Amazon MQ の暗号化キー設定の確認 | cloudFormation/aws/amazon_mq_broker_encryption_disabled |
| EKS の暗号化キー設定の確認 | cloudFormation/aws/eks_cluster_encryption_disabled |
| SageMaker ノートブックインスタンスの暗号化キー設定の確認 | cloudFormation/aws/sagemaker_data_encryption_disabled |
| API Gateway キャッシュの暗号化が無効 | cloudFormation/aws/api_gateway_cache_encrypted_disabled |
| EBS ボリュームの暗号化の確認 | cloudFormation/aws/ebs_volume_encryption_disabled |
| 暗号化が無効な EFS ファイルシステム | cloudFormation/aws/efs_not_encrypted |
| 暗号化が設定されていない WorkSpaces | cloudFormation/aws/workspace_without_encryption |
| 保存時暗号化が無効な DAX クラスター | cloudFormation/aws/dax_cluster_not_encrypted |
| EBS ブロックデバイスの暗号化の確認 | cloudFormation/aws/block_device_is_not_encrypted |
| データベースの保存時暗号化の確認 | cloudFormation/aws/cmk_unencrypted_storage |
| ELB の TLS セキュリティポリシーの確認 | cloudFormation/aws/elb_using_weak_ciphers |
| 実行ロールを共有するLambda関数 | cloudFormation/aws/lambda_functions_without_unique_iam_roles |
| 公開アクセスが有効な Amazon MQ ブローカー | cloudFormation/aws/mq_broker_is_publicly_accessible |
| 公開アクセスが有効な Amazon MSK ブローカー | cloudFormation/aws/msk_broker_is_publicly_accessible |
| Redshift の公開アクセス設定の確認 | cloudFormation/aws/redshift_publicly_accessible |
| 任意のAWSアカウントに一覧取得を許可するS3バケットACL | cloudFormation/aws/s3_bucket_acl_allows_read_to_any_authenticated_user |
| インターネットに公開された RDP ポート | cloudFormation/aws/remote_desktop_port_open_to_internet |
| 保存データの暗号化が無効な Neptune データベースクラスター | cloudFormation/aws/neptune_database_cluster_encryption_disabled |
| RDS インスタンスの保存時の暗号化設定の確認 | cloudFormation/aws/rds_storage_not_encrypted |
| RDS クラスターの保存時の暗号化設定の確認 | cloudFormation/aws/rds_storage_encryption_disabled |
| Redshift の保存時の暗号化設定の確認 | cloudFormation/aws/redshift_not_encrypted |
| MSK クラスターの暗号化設定の確認 | cloudFormation/aws/msk_cluster_encryption_disabled |
| ECS と EFS 間の転送時暗号化の確認 | cloudFormation/aws/ecs_cluster_not_encrypted_at_rest |
| 保存時の暗号化が無効な ElastiCache Redis レプリケーショングループ | cloudFormation/aws/elasticache_with_disabled_at_rest_encryption |
| 保存時の暗号化が無効な Elasticsearch ドメイン | cloudFormation/aws/elasticsearch_not_encrypted_at_rest |
| 過剰な権限を持つ可能性があるLambda実行ロール | cloudFormation/aws/lambda_functions_with_full_privileges |
| すべての操作とリソースを許可するIAMポリシー | cloudFormation/aws/iam_policy_grants_full_permissions |
| IAM ポリシーが全権限を許可 | cloudFormation/aws/iam_policies_with_full_privileges |
| KMSキーポリシーの権限の見直し | cloudFormation/aws/kms_key_with_full_permissions |
| すべての送信元を許可するセキュリティグループのインバウンド規則 | cloudFormation/aws/unrestricted_security_group_ingress |
| 静的ウェブサイトホスティングが設定された S3 バケット | cloudFormation/aws/s3_static_website_host_enabled |
| 通信ルールが残っているデフォルトセキュリティグループ | cloudFormation/aws/default_security_groups_with_unrestricted_traffic |
| DocumentDB クラスターの平文マスターパスワード | cloudFormation/aws/docdb_cluster_master_password_in_plaintext |
| DMS MongoDB エンドポイント設定の平文パスワード | cloudFormation/aws/dms_endpoint_mongo_db_settings_password_exposed |
| DMS エンドポイントの平文パスワード | cloudFormation/aws/dms_endpoint_password_exposed |
| Directory Service Microsoft AD の平文パスワード | cloudFormation/aws/directory_service_microsoft_ad_password_set_to_plaintext_or_default_ref |
| Directory Service Simple AD の平文パスワード | cloudFormation/aws/directory_service_simple_ad_password_exposed |
| テンプレートからのIAMログインパスワード漏えいの可能性 | cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext |
| Alexa ASK スキルの平文リフレッシュトークン | cloudFormation/aws/refresh_token_is_exposed |
| Network ACL の拒否範囲を確認 | cloudFormation/aws/ec2_network_acl_ineffective_denied_traffic |