AWS

Terraformで管理するAWSリソースのセキュリティと構成についての文書です。

文書一覧

文書 パス
API Gatewayのデプロイ先ステージと使用量プランの関連付けの確認 terraform/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
API Gatewayステージと使用量プランの関連付けの確認 terraform/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API Gateway の X-Ray トレースが無効 terraform/aws/api_gateway_xray_disabled
API Gateway のレスポンス圧縮設定の確認 terraform/aws/api_gateway_with_invalid_compression
API Gateway による Lambda 呼び出し範囲の確認 terraform/aws/public_lambda_via_api_gateway
API GatewayのAPIキーによる利用量管理の確認 terraform/aws/api_gateway_method_does_not_contains_an_api_key
AWS Configの集約対象リージョンの確認 terraform/aws/config_configuration_aggregator_to_all_regions_disabled
AWS Configの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_aws_config_configuration_changes_alarm_missing
コンソールサインインの失敗を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_management_console_auth_failed_alarm_missing
AWS Organizations の変更を監視するアラームの未設定 terraform/aws/cloudwatch_aws_organizations_changes_missing_alarm
AWS Shield Advancedの適用要否の確認 terraform/aws/shield_advanced_not_in_use
AWS マネージドキーで暗号化された SNS トピック terraform/aws/sns_topic_encrypted_with_aws_managed_key
AWS マネージドキーで暗号化された Secrets Manager シークレット terraform/aws/secretsmanager_secret_encrypted_with_aws_managed_key
API Gateway REST APIの認証構成の確認 terraform/aws/api_gateway_without_configured_authorizer
Auto Scalingグループのタグが未設定 terraform/aws/autoscaling_groups_supply_tags
起動設定のユーザーデータ内にある Base64 形式の秘密鍵の確認 terraform/aws/user_data_contains_encoded_private_key
CloudFrontのコンテンツ配信設定の確認 terraform/aws/cdn_configuration_is_missing
CloudFormation スタックの通知設定の確認 terraform/aws/stack_notifications_disabled
CloudFormationスタックポリシーが未設定 terraform/aws/no_stack_policy
CloudFormationスタックのテンプレートが未設定 terraform/aws/stack_without_template
CloudFrontのTLSセキュリティポリシーの確認 terraform/aws/secure_ciphers_disabled
CloudTrailのログファイル配信通知が未設定 terraform/aws/cloudtrail_sns_topic_name_undefined
CloudTrail ログの KMS キー設定の確認 terraform/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrailログの整合性確認用ダイジェストが無効になっている terraform/aws/cloudtrail_log_file_validation_disabled
CloudTrailのリージョンとグローバルイベントの対象範囲の確認 terraform/aws/cloudtrail_multi_region_disabled
CloudTrailの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_cloudtrail_configuration_changes_alarm_missing
CloudTrailとCloudWatch Logsが未連携 terraform/aws/cloudtrail_not_integrated_with_cloudwatch
CloudWatch Logsの送信先ポリシーが過剰なアクセスを許可している terraform/aws/cloudwatch_logs_destination_with_vulnerable_policy
API Gatewayのメソッド詳細メトリクスが無効になっている terraform/aws/cloudwatch_metrics_disabled
Route 53のパブリックDNSクエリログが未設定 terraform/aws/cloudwatch_logging_disabled
CloudWatch ログの保存期間の確認 terraform/aws/cloudwatch_without_retention_period_specified
API GatewayのCloudWatchログ配信設定の確認 terraform/aws/api_gateway_with_cloudwatch_logging_disabled
AWS マネージドキーを使用する CodeBuild プロジェクト terraform/aws/codebuild_project_encrypted_with_aws_managed_key
Cognito User Pool の MFA 適用範囲の確認 terraform/aws/cognito_userpool_without_mfa
DocumentDBの暗号化キー管理の確認 terraform/aws/docdb_cluster_encrypted_with_aws_managed_key
DynamoDBゲートウェイエンドポイントの経路関連付けの確認 terraform/aws/dynamodb_vpc_endpoint_without_route_table_association
DynamoDB のポイントインタイムリカバリが無効 terraform/aws/dynamodb_table_point_in_time_recovery_disabled
EC2 の EBS 最適化設定の確認 terraform/aws/ec2_not_ebs_optimized
EC2 ユーザーデータ内の AWS 認証情報の確認 terraform/aws/hardcoded_aws_access_key
EC2 メタデータの IMDSv1 許可の確認 terraform/aws/instance_uses_metadata_service_IMDSv1
EC2のサブネットとセキュリティグループ選択の確認 terraform/aws/instance_with_no_vpc
EC2インスタンスのデフォルトVPC利用の確認 terraform/aws/ec2_instance_using_default_vpc
EC2 インスタンスに直接配布する AWS アクセスキー terraform/aws/ec2_instance_using_api_keys
ECRリポジトリの暗号化キー管理の確認 terraform/aws/ecr_repository_not_encrypted
ECRリポジトリのアクセスポリシーの確認 terraform/aws/ecr_repository_without_policy
ECRイメージの脆弱性スキャン設定の確認 terraform/aws/unscanned_ecr_image
ECS Container Insights 設定の確認 terraform/aws/ecs_cluster_container_insights_disabled
ECS サービスに必要なタスク数の確認 terraform/aws/ecs_service_without_running_tasks
EFS のカスタマー管理 KMS キーの確認 terraform/aws/efs_without_kms
EKSコントロールプレーンのログ種別が不足 terraform/aws/missing_cluster_log_types
EMRクラスターのサブネット選択の確認 terraform/aws/emr_without_vpc
ENCRYPTED_VOLUMES の AWS Config ルールがない構成 terraform/aws/config_rule_for_encrypted_volumes_is_disabled
ElastiCache のエンジン選択の確認 terraform/aws/redis_disabled
ElastiCacheのサブネットグループ選択の確認 terraform/aws/elasticache_without_vpc
ElastiCache の既定ポートとアクセス制御の確認 terraform/aws/elasticache_using_default_port
Elasticsearch のスローログ設定の確認 terraform/aws/elasticsearch_without_slow_logs
クロスアカウント IAM ロールの信頼条件の確認 terraform/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
GuardDutyの検出器が無効になっている terraform/aws/guardduty_detector_disabled
S3バケットのHTTPS強制ポリシーの確認 terraform/aws/s3_bucket_policy_accepts_http_requests
HTTPポート80がインターネットに公開されている terraform/aws/http_port_open
ElasticsearchドメインでHTTPSが必須になっていない terraform/aws/elasticsearch_with_https_disabled
HTTPを使用するAWS ALBリスナー terraform/aws/alb_listening_on_http
CloudFrontのビューワーポリシーがHTTPを許可している terraform/aws/cloudfront_viewer_protocol_policy_allows_http
IAM Access Analyzer の構成の確認 terraform/aws/iam_access_analyzer_not_enabled
IAM データベース認証が無効な Neptune クラスター terraform/aws/neptune_cluster_with_iam_database_authentication_disabled
IAM パスワード有効期限ポリシーの確認 terraform/aws/misconfigured_password_policy_expiration
IAM パスワード再利用防止の確認 terraform/aws/password_without_reuse_prevention
IAM パスワードの最小文字数の確認 terraform/aws/iam_password_without_minimum_length
IAM ユーザーポリシーの MFA 要件の確認 terraform/aws/iam_user_policy_without_mfa
Elasticsearch ドメインの IAM アクセス制御の確認 terraform/aws/elasticsearch_without_iam_authentication
IAM ポリシー変更を監視するアラームの未設定 terraform/aws/cloudwatch_iam_policy_changes_alarm_missing
KMS カスタマーマネージドキーのローテーション設定の確認 terraform/aws/cmk_rotation_disabled
KMS 暗号化のない AWS Kinesis ストリーム terraform/aws/kinesis_not_encrypted_with_kms
CloudWatch ロググループの暗号化キーの確認 terraform/aws/cloudwatch_log_group_not_encrypted
KMS キー削除待機期間の確認 terraform/aws/kms_key_with_no_deletion_window
DocumentDB の暗号化キー設定の確認 terraform/aws/docdb_cluster_without_kms
Elasticsearch の暗号化キー設定の確認 terraform/aws/elasticsearch_encryption_with_kms_is_disabled
SageMaker ノートブックの暗号化キーを確認 terraform/aws/sagemaker_notebook_instance_without_kms
Secrets Manager シークレットの暗号化キー設定の確認 terraform/aws/secretsmanager_secret_without_kms
Lambda 非同期処理の失敗イベント保管設定の確認 terraform/aws/lambda_function_without_dead_letter_queue
Lambda InvokeFunction の IAM リソース範囲の確認 terraform/aws/lambda_iam_invokefunction_misconfigured
Lambda 権限の action 設定の確認 terraform/aws/lambda_permission_misconfigured
Lambda の X-Ray トレース設定の確認 terraform/aws/lambda_functions_without_x-ray_tracing
Lambda 環境変数内の AWS 認証情報の確認 terraform/aws/hardcoded_aws_access_key_in_lambda
IAM ユーザーアクセスの MFA 要件の確認 terraform/aws/authentication_without_mfa
MFA なしのコンソールログインを監視するアラームの未設定 terraform/aws/cloudwatch_management_console_sign_in_without_mfa_alarm_missing
MQブローカーのログ設定の確認 terraform/aws/mq_broker_logging_disabled
MSKブローカーログ設定の確認 terraform/aws/msk_cluster_logging_disabled
ネットワークACLの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_changes_to_nacl_alarm_missing
Neptune監査ログのエクスポート設定の確認 terraform/aws/neptune_logging_disabled
VPCでのNetwork Firewall利用の確認 terraform/aws/vpc_without_network_firewall
API Gatewayエンドポイントの公開範囲の確認 terraform/aws/api_gateway_endpoint_config_is_not_private
RDS for PostgreSQL のクエリログ設定の確認 terraform/aws/postgres_rds_logging_disabled
リソースベースポリシーにPrincipalがない terraform/aws/policy_without_principal
全アドレスから RDP を許可する AWS Network ACL terraform/aws/network_acl_with_unrestricted_access_to_rdp
すべてのアドレスから RDP を許可する AWS セキュリティグループ terraform/aws/remote_desktop_port_open_to_internet
RDS の既定ポートとアクセス制御の確認 terraform/aws/rds_using_default_port
RDSのCloudWatchログエクスポート設定の確認 terraform/aws/rds_without_logging
RDS インスタンスの自動バックアップが無効 terraform/aws/rds_with_backup_disabled
RDS インスタンスの IAM データベース認証が未使用 terraform/aws/iam_database_auth_not_enabled
RDS の自動マイナーアップグレードが無効 terraform/aws/automatic_minor_upgrades_disabled
RDS クラスターのバックアップ保持期間の確認 terraform/aws/rds_cluster_with_backup_disabled
RDS スナップショットのタグコピー設定の確認 terraform/aws/tags_not_copied_to_rds_cluster_snapshot
RDS クラスターの IAM データベース認証が未使用 terraform/aws/iam_db_cluster_auth_not_enabled
TLS証明書のRSA鍵が短すぎる terraform/aws/certificate_rsa_key_bytes_lower_than_256
Redshift の既定ポートとアクセス制御の確認 terraform/aws/redshift_using_default_port
Redshiftクラスターのネットワーク選択の確認 terraform/aws/redshift_cluster_without_vpc
Redshift監査ログ設定の確認 terraform/aws/redshift_cluster_logging_disabled
S3オブジェクトのCloudTrailデータイベント収集範囲の確認 terraform/aws/s3_bucket_object_level_cloudtrail_logging_disabled
S3 バケットの MFA Delete 利用の確認 terraform/aws/s3_bucket_without_enabled_mfa_delete
S3サーバーアクセスログ設定の確認 terraform/aws/s3_bucket_logging_disabled
S3 バケットのイベント通知設定の確認 terraform/aws/s3_bucket_notifications_disabled
S3バケットポリシーの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_s3_policy_change_alarm_missing
SQL Analysis Servicesのポート2383が接続元を制限していない terraform/aws/sql_analysis_services_port_2383_is_publicly_accessible
SQS VPCエンドポイントのDNS設定の確認 terraform/aws/sqs_vpc_endpoint_without_dns_resolution
SQSキューのサーバー側暗号化設定の確認 terraform/aws/sqs_with_sse_disabled
ネットワークACLが広い範囲からのSSHを許可している terraform/aws/network_acl_with_unrestricted_access_to_ssh
セキュリティグループがインターネット全体からのSSHを許可している terraform/aws/security_group_with_unrestricted_access_to_ssh
API Gateway のバックエンド用クライアント証明書設定の確認 terraform/aws/api_gateway_without_ssl_certificate
SSM セッションの追加 KMS 暗号化設定の確認 terraform/aws/ssm_session_transit_encryption_disabled
IAM Identity Center の許可セットのセッション期間の確認 terraform/aws/sso_permission_with_inadequate_user_session_duration
セキュリティグループルールの説明が未記入 terraform/aws/security_group_rules_without_description
セキュリティグループの説明の確認 terraform/aws/security_group_without_description
Service Control Policy を使用できない AWS Organizations 設定 terraform/aws/service_control_policies_disabled
StackSetのスタック保持設定の確認 terraform/aws/stack_retention_disabled
Terraform で直接作成される AWS Identity Center ユーザー terraform/aws/sso_policy_with_full_priveleges_copy
VPC Flow Logsの収集範囲の確認 terraform/aws/vpc_flowlogs_disabled
VPCの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_vpc_changes_alarm_missing
API GatewayのAWS WAF保護設定の確認 terraform/aws/api_gateway_without_waf
CloudFrontのWAF関連付け設定の確認 terraform/aws/cloudfront_without_waf
AWS ALBにWAFが関連付けられていない terraform/aws/alb_is_not_integrated_with_waf
WRITE_ACP 権限を指定した S3 バケット ACL terraform/aws/s3_bucket_acl_grants_write_acp_permission
Effect: Allow と NotAction を併用する SNS トピックポリシー terraform/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
IAMグループに過剰なCloudFormationとPassRole権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
IAMユーザーに過剰なCloudFormation作成とPassRole権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
cloudformation:CreateStack と iam:PassRole による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
IAMグループに過剰なEC2起動とPassRole権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
IAMユーザーに過剰なEC2起動とPassRole権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
ec2:RunInstances と iam:PassRole による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
IAMグループに過剰なGlue作成とPassRole権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
IAMユーザーに過剰なGlue作成とPassRole権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
glue:CreateDevEndpoint と iam:PassRole による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
IAMグループに過剰なglue:UpdateDevEndpoint権限がある terraform/aws/group_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAMユーザーに過剰なglue:UpdateDevEndpoint権限がある terraform/aws/user_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
glue:UpdateDevEndpoint による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAM グループの iam:AddUserToGroup 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM ユーザーの iam:AddUserToGroup 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM ロールの iam:AddUserToGroup 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM グループの iam:AttachGroupPolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM ユーザーの iam:AttachGroupPolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM ロールの iam:AttachGroupPolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM グループの iam:AttachRolePolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM ユーザーの iam:AttachRolePolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM ロールの iam:AttachRolePolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM グループの iam:AttachUserPolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM ユーザーの iam:AttachUserPolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM ロールの iam:AttachUserPolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAMグループに過剰なiam:CreateAccessKey権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateAccessKey
IAMユーザーに過剰なiam:CreateAccessKey権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateAccessKey
iam:CreateAccessKey による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateAccessKey
IAMグループに過剰なiam:CreateLoginProfile権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAMユーザーに過剰なiam:CreateLoginProfile権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateLoginProfile
iam:CreateLoginProfile による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAM グループの iam:CreatePolicyVersion 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM ユーザーの iam:CreatePolicyVersion 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM ロールの iam:CreatePolicyVersion 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM グループの iam:PutGroupPolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM ユーザーの iam:PutGroupPolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM ロールの iam:PutGroupPolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM グループの iam:PutRolePolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM ユーザーの iam:PutRolePolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM ロールの iam:PutRolePolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM グループの iam:PutUserPolicy 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM ユーザーの iam:PutUserPolicy 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM ロールの iam:PutUserPolicy 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM グループの iam:SetDefaultPolicyVersion 権限の確認 terraform/aws/group_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM ユーザーの iam:SetDefaultPolicyVersion 権限の確認 terraform/aws/user_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM ロールの iam:SetDefaultPolicyVersion 権限の確認 terraform/aws/role_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAMグループに過剰な信頼ポリシー変更とロール引き受け権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
IAMユーザーに過剰な信頼ポリシー変更とロール引き受け権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
iam:UpdateAssumeRolePolicy と sts:AssumeRole による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
IAMグループに過剰なiam:UpdateLoginProfile権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
IAMユーザーに過剰なiam:UpdateLoginProfile権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
iam:UpdateLoginProfile による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
IAMグループに過剰なLambda作成・呼び出しとPassRole権限がある terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
IAMユーザーに過剰なLambda作成・呼び出しとPassRole権限がある terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
lambda:CreateFunction、lambda:InvokeFunction、iam:PassRole による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_lambda_InvokeFunction
IAMグループに過剰なlambda:UpdateFunctionCode権限がある terraform/aws/group_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
IAMユーザーに過剰なlambda:UpdateFunctionCode権限がある terraform/aws/user_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
lambda:UpdateFunctionCode による権限昇格のおそれがある IAM ロール terraform/aws/role_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
privileged コンテナーを有効にした AWS Batch ジョブ定義 terraform/aws/batch_job_definition_with_privileged_container_properties
EKS の暗号化キー設定の確認 terraform/aws/eks_cluster_encryption_disabled
IAMポリシーがユーザーに直接関連付けられている terraform/aws/iam_policies_attached_to_user
KMSキーの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_disabling_or_scheduled_deletion_of_customer_created_cmk_alarm_missing
S3の公開ACLを無視する設定の確認 terraform/aws/s3_bucket_without_ignore_public_acl
公開 ACL とパブリックアクセスのブロックを併用する S3 バケット terraform/aws/s3_bucket_public_acl_overridden_by_public_access_block
S3の公開ACLブロック設定の確認 terraform/aws/s3_bucket_allows_public_acl
S3の公開バケットポリシーブロック設定の確認 terraform/aws/s3_bucket_with_public_policy
サブネット CIDR に /0 を指定した RDS 構成 terraform/aws/rds_associated_with_public_subnet
すべての接続元アドレスを許可する従来の DB セキュリティグループ terraform/aws/db_security_group_has_public_interface
公開アクセスが有効な DMS レプリケーションインスタンス terraform/aws/amazon_dms_replication_instance_is_publicly_accessible
SQS キューポリシーの公開主体への許可の確認 terraform/aws/sqs_policy_with_public_access
公開アクセスが可能な AWS MQ ブローカー terraform/aws/mq_broker_is_publicly_accessible
公開アクセスが可能な AWS MSK ブローカー terraform/aws/msk_broker_is_publicly_accessible
公開アクセスが可能な AWS Neptune クラスターインスタンス terraform/aws/neptune_cluster_instance_is_publicly_accessible
ワイルドカードのプリンシパルを使用するECRポリシー terraform/aws/ecr_repository_is_publicly_accessible
アクセス主体にワイルドカードを指定したSNSトピックポリシー terraform/aws/sns_topic_is_publicly_accessible
CloudTrail ログバケットの公開アクセスの確認 terraform/aws/cloudtrail_log_files_s3_bucket_is_publicly_accessible
公開アクセス設定の確認が必要な RDS 構成 terraform/aws/rds_db_instance_publicly_accessible
EC2インスタンスのパブリックIP割り当ての確認 terraform/aws/ec2_instance_has_public_ip
パブリックIPが割り当てられたECSサービス terraform/aws/ecs_services_assigned_with_public_ip_address
パブリック IP を自動割り当てする VPC サブネット terraform/aws/vpc_subnet_assigns_public_ip
接続元の範囲を確認する必要がある従来の DB セキュリティグループ terraform/aws/db_security_group_open_to_large_scope
IAM ロールの信頼ポリシーの確認 terraform/aws/iam_role_with_full_privileges
KMS キーのアクセスポリシーの確認 terraform/aws/kms_key_with_full_permissions
Secrets Manager のシークレットアクセスポリシーの確認 terraform/aws/secrets_manager_with_vulnerable_policy
AWS ECS サービスロールの権限確認 terraform/aws/ecs_service_admin_role_is_present
ECSタスクのネットワークモードの確認 terraform/aws/ecs_task_definition_network_mode_not_recommended
過剰な権限を持つ実行ロールを使用する AWS Lambda 関数 terraform/aws/lambda_function_with_privileged_role
アカウント・リージョンで EBS の既定の暗号化が無効 terraform/aws/ebs_default_encryption_disabled
AWS デフォルト VPC の設定の確認 terraform/aws/default_vpc_exists
EC2インスタンスのデフォルトセキュリティグループ使用の確認 terraform/aws/ec2_instance_using_default_security_group
ネットワークゲートウェイ変更を監視するアラームの未設定 terraform/aws/cloudwatch_network_gateways_changes_alarm_missing
ノード間暗号化がない Elasticsearch ドメイン terraform/aws/elasticsearch_domain_not_encrypted_node_to_node
ElastiCacheノードが複数のアベイラビリティーゾーンに分散されていない terraform/aws/elasticache_nodes_not_created_across_multi_az
データ流出に悪用されるおそれがある IAM ポリシー terraform/aws/iam_policy_allows_for_data_exfiltration
ルートテーブル変更を監視するアラームの未設定 terraform/aws/cloudwatch_route_table_changes_alarm_missing
AWS Route 53レコードの値が空 terraform/aws/route53_record_undefined
CloudFrontリクエストログ設定の確認 terraform/aws/cloudfront_logging_disabled
AWS CloudTrailのログ記録が無効 terraform/aws/cloudtrail_logging_disabled
DocumentDBログエクスポート設定の確認 terraform/aws/docdb_logging_disabled
CloudTrailログバケットのアクセスログ設定の確認 terraform/aws/cloudtrail_log_files_s3_bucket_with_logging_disabled
EKSクラスターのログ記録が無効 terraform/aws/eks_cluster_log_disabled
Elasticsearchログ発行設定の確認 terraform/aws/elasticsearch_logs_disabled
ルートユーザーの使用を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_root_account_use_alarm_missing
root という名前の IAM ユーザーのアクセスキーの確認 terraform/aws/iam_access_key_is_exposed
TLS証明書の有効期限が切れている terraform/aws/certificate_has_expired
IAM サービスロールの信頼する主体の確認 terraform/aws/iam_policy_grants_assumerole_permission_across_all_services
操作とプリンシパルにワイルドカードを使う S3 バケットポリシー terraform/aws/s3_bucket_with_all_permissions
iam:PassRoleの対象がすべてのロールに広がっている terraform/aws/iam_role_policy_passrole_allows_all
認証されたすべての AWS アカウントに読み取りを許可する S3 バケット ACL terraform/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
SQS キューポリシーの広すぎる操作許可の確認 terraform/aws/sqs_policy_allows_all_actions
IAM ロールのアカウント単位の信頼を確認 terraform/aws/iam_role_allows_all_principals_to_assume
削除操作のプリンシパルにワイルドカードを指定した S3 バケットポリシー terraform/aws/s3_bucket_allows_delete_action_from_all_principals
Put 操作のプリンシパルにワイルドカードを指定した S3 バケットポリシー terraform/aws/s3_bucket_allows_put_action_from_all_principals
ワイルドカードのプリンシパルを使用する S3 バケットポリシー terraform/aws/s3_bucket_access_to_any_principal
すべての主体に Get 権限を許可する S3 バケットポリシー terraform/aws/s3_bucket_allows_get_action_from_all_principals
すべての主体に一覧取得を許可する S3 バケットポリシー terraform/aws/s3_bucket_allows_list_action_from_all_principals
デフォルトセキュリティグループの通信許可の確認 terraform/aws/vpc_default_security_group_accepts_all_traffic
全アドレスとの通信を許可する AWS のデフォルトセキュリティグループ terraform/aws/default_security_groups_with_unrestricted_traffic
未使用のセキュリティグループの確認 terraform/aws/security_groups_not_used
機密性の高いサービスポートへのプライベートネットワークからのアクセスの確認 terraform/aws/sensitive_port_is_exposed_to_wide_private_network
全アドレスから管理用・内部サービス用ポートを許可する AWS セキュリティグループ terraform/aws/sensitive_port_is_exposed_to_entire_network
ElastiCache Redisの自動バックアップが無効 terraform/aws/elasticache_redis_cluster_without_backup
S3バージョニング設定の確認 terraform/aws/s3_bucket_without_versioning
セキュリティグループの変更を通知するCloudWatchアラームが未設定 terraform/aws/cloudwatch_security_group_changes_alarm_missing
AWS ElastiCache Redis OSSのエンジンバージョンの確認 terraform/aws/redis_not_compliant
API GatewayカスタムドメインのTLSポリシーの確認 terraform/aws/api_gateway_without_security_policy
ボリューム暗号化のない WorkSpace terraform/aws/workspaces_workspace_volume_not_encrypted
IAMユーザーの初期パスワード設定の確認 terraform/aws/no_password_policy_enabled
非暗号化 EBS ボリュームから作成された AWS スナップショット terraform/aws/ebs_volume_snapshot_not_encrypted
RDS クラスタースナップショットの暗号化の確認 terraform/aws/rds_database_cluster_not_encrypted
権限エラーを監視するCloudWatch設定の見直し terraform/aws/cloudwatch_unauthorized_access_defined_alarm_missing
ユーザーが所属していないIAMグループ terraform/aws/iam_group_without_users
IAM ユーザーのパスワード変更権限の確認 terraform/aws/aws_password_policy_with_unchangeable_passwords
無効な KMS カスタマーマネージドキーの利用確認 terraform/aws/cmk_is_unusable
AWS ALBの削除保護が無効 terraform/aws/alb_deletion_protection_disabled
EC2の詳細モニタリングが無効 terraform/aws/ec2_instance_monitoring_disabled
DynamoDB テーブルの暗号化キー設定の確認 terraform/aws/dynamodb_table_not_encrypted
S3 オブジェクトのサーバー側暗号化設定の確認 terraform/aws/s3_bucket_object_not_encrypted
Amazon Data Firehose のサーバー側暗号化設定の確認 terraform/aws/kinesis_sse_not_configured
S3 CORSの許可範囲の確認 terraform/aws/s3_bucket_with_unsecured_cors_rule
ELBポリシーのSSL/TLSプロトコルの確認 terraform/aws/elb_using_insecure_protocols
ポートの公開範囲を確認すべき AWS セキュリティグループ terraform/aws/unknown_port_exposed_to_internet
MSK クラスターの暗号化設定の確認 terraform/aws/msk_cluster_encryption_disabled
Athena データベース作成クエリの結果暗号化設定の確認 terraform/aws/athena_database_not_encrypted
SageMaker エンドポイントの保存時暗号化キーを確認 terraform/aws/sagemaker_endpoint_configuration_encryption_disabled
Amazon MQ ブローカーの暗号化キー設定の確認 terraform/aws/amazon_mq_broker_encryption_disabled
Glue Data Catalog と接続パスワードの暗号化の確認 terraform/aws/glue_data_catalog_encryption_disabled
Glue Security Configuration の暗号化設定の確認 terraform/aws/glue_security_configuration_encryption_disabled
メッセージ暗号化のない SNS トピック terraform/aws/sns_topic_not_encrypted
暗号化されていない API Gateway キャッシュ terraform/aws/api_gateway_method_settings_cache_not_encrypted
暗号化されていない AWS AMI terraform/aws/ami_not_encrypted
暗号化されていない AWS EBS ボリューム terraform/aws/ebs_volume_encryption_disabled
暗号化されていない AWS EFS ファイルシステム terraform/aws/efs_not_encrypted
暗号化されていない AWS ブロックデバイスマッピング terraform/aws/block_device_is_not_encrypted
AWS Classic ELB の暗号スイートポリシーの確認 terraform/aws/elb_using_weak_ciphers
AWS AMI のアカウント間共有の確認 terraform/aws/ami_shared_with_multiple_accounts
Elastic IP の用途と関連付けの確認 terraform/aws/aws_eip_not_attached_to_any_instance
Auto Scalingグループのロードバランサー関連付けの確認 terraform/aws/auto_scaling_group_with_no_associated_elb
RDSインスタンスが古いCA証明書を使用している terraform/aws/ca_certificate_identifier_is_outdated
Lambda 関数ポリシーの広すぎる操作許可の確認 terraform/aws/lambda_with_vulnerable_policy
ワイルドカード principal を使用する Lambda 呼び出し権限 terraform/aws/lambda_permission_principal_is_wildcard
アクセス範囲が過剰な API Gateway REST API ポリシー terraform/aws/rest_api_with_vulnerable_policy
公開アクセス設定の確認が必要な AWS Redshift クラスター terraform/aws/redshift_publicly_accessible
AWS SQS キューポリシーのアクセス範囲の確認 terraform/aws/sqs_queue_exposed
運用タグが未設定 terraform/aws/resource_not_using_tags
API Gatewayメソッドの認証設定の確認 terraform/aws/api_gateway_with_open_access
機密性の高いサービスポートへのアクセス元の確認 terraform/aws/sensitive_port_is_exposed_to_small_public_network
AWS ALBが無効なヘッダーを削除しない terraform/aws/alb_not_dropping_invalid_headers
Redshift の保存時暗号化の確認 terraform/aws/redshift_not_encrypted
Amazon Aurora の保存時の暗号化設定の確認 terraform/aws/aurora_with_disabled_at_rest_encryption
保存時の暗号化がない AWS DAX クラスター terraform/aws/dax_cluster_not_encrypted
ストレージ暗号化がない Amazon DocumentDB クラスター terraform/aws/docdb_cluster_not_encrypted
保存時暗号化のない AWS ElastiCache レプリケーショングループ terraform/aws/elasticache_replication_group_not_encrypted_at_rest
保存時暗号化のない AWS Elasticsearch ドメイン terraform/aws/elasticsearch_not_encrypted_at_rest
保存時暗号化のない AWS Neptune クラスター terraform/aws/neptune_database_cluster_encryption_disabled
ストレージ暗号化がない AWS DB インスタンス terraform/aws/db_instance_storage_not_encrypted
RDS クラスターの保存時暗号化の確認 terraform/aws/rds_storage_not_encrypted
転送時暗号化が無効な EFS ボリューム terraform/aws/efs_volume_with_disabled_transit_encryption
転送時暗号化が無効な ElastiCache レプリケーショングループ terraform/aws/elasticache_replication_group_not_encrypted_at_transit
VPC ピアリング経路の宛先範囲の確認 terraform/aws/vpc_peering_route_table_with_unrestricted_cidr
IAM ポリシーの広すぎる管理権限の確認 terraform/aws/iam_policies_with_full_privileges
Identity Center のアクセス許可セットの過剰な権限を確認 terraform/aws/sso_policy_with_full_priveleges
過剰な権限を許可する AWS IAM ポリシー terraform/aws/iam_policy_grants_full_permissions
公開 ACL を指定した S3 バケット設定 terraform/aws/s3_bucket_acl_allows_read_or_write_to_all_users
すべての IPv4 アドレスを許可する EC2-Classic DB セキュリティグループ terraform/aws/db_security_group_with_public_scope
インターネット全体を許可する EKS の公開アクセス CIDR terraform/aws/eks_cluster_has_public_access_cidrs
全接続元アドレスからの受信を許可する AWS セキュリティグループ terraform/aws/unrestricted_security_group_ingress
SES アイデンティティポリシーのアクセス権限の確認 terraform/aws/ses_policy_with_allowed_iam_actions
API Gatewayデプロイステージのアクセスログ設定の確認 terraform/aws/api_gateway_deployment_without_access_log_setting
API Gatewayステージのログ設定の確認 terraform/aws/api_gateway_access_logging_disabled
Classic ELBのアクセスログが無効 terraform/aws/elb_access_logging_disabled
ELBv2ロードバランサーのアクセスログ設定の確認 terraform/aws/elb_v2_lb_access_log_disabled
接続元セキュリティグループがない EKS ノードのリモートアクセス terraform/aws/eks_node_group_remote_access_disabled
AWS S3静的ウェブサイトの公開範囲の確認 terraform/aws/s3_static_website_host_enabled
CloudFrontのセキュリティポリシーが古いTLSを許可している terraform/aws/cloudfront_without_minimum_protocol_tls_1.2
CloudFrontのカスタムドメイン用証明書の確認 terraform/aws/vulnerable_default_ssl_certificate
EFS ファイルシステムポリシーのアクセス権限の確認 terraform/aws/efs_with_vulnerable_policy
AWS Glue Data Catalog ポリシーの権限の確認 terraform/aws/glue_with_vulnerable_policy
Elasticsearch ドメインポリシーのアクセス権限の確認 terraform/aws/elasticsearch_domain_with_vulnerable_policy
IAMユーザーにコンソールアクセスがある terraform/aws/iam_user_with_access_to_console
Athena ワークグループの結果暗号化設定の確認 terraform/aws/athena_workgroup_not_encrypted
イメージタグを変更できる AWS ECR リポジトリ terraform/aws/ecr_image_tag_not_immutable
パブリック EC2 とプライベート EC2 の IAM ロール共有 terraform/aws/public_and_private_ec2_share_role
S3の公開バケットに対するアクセス制限の確認 terraform/aws/s3_bucket_without_restriction_of_public_bucket
パブリックアクセスが有効な EKS クラスター terraform/aws/eks_cluster_has_public_access
IAMユーザーのアクセスキー数の確認 terraform/aws/iam_user_too_many_access_keys
IAM ユーザーの有効なアクセスキーの確認 terraform/aws/root_account_has_active_access_keys
AWS Global Acceleratorのフローログが無効 terraform/aws/global_accelerator_flow_logs_disabled

関連ページ340

API Gatewayのデプロイ先ステージと使用量プランの関連付けの確認

キーごとの使用量管理が必要な場合は、デプロイ先のステージを使用量プランに関連付けてください。

API Gatewayステージと使用量プランの関連付けの確認

キーごとの使用量制御が必要なステージを、適切なプランに関連付けてください。

API Gateway の X-Ray トレースが無効

REST API の X-Ray トレースが無効だと、リクエスト経路や遅延原因の分析が難しくなる可能性があります。

API Gateway のレスポンス圧縮設定の確認

API のレスポンス特性に合わせて、圧縮の有無と最小サイズを選んでください。

API Gateway による Lambda 呼び出し範囲の確認

API Gateway による Lambda の呼び出しを、必要なステージ、メソッド、パスに限定してください。

API GatewayのAPIキーによる利用量管理の確認

キーごとの利用量管理が必要な場合にAPIキーを要求し、認証は別途設定してください。

AWS Configの集約対象リージョンの確認

中央で確認する必要があるリージョンをAWS Configの集約対象に含めてください。

AWS Configの変更を通知するCloudWatchアラームが未設定

AWS Configの変更をCloudWatchアラームで監視してください。

コンソールサインインの失敗を通知するCloudWatchアラームが未設定

AWSコンソールへのサインイン失敗を通知するよう設定してください。

AWS Organizations の変更を監視するアラームの未設定

AWS Organizations の変更を監視する CloudWatch フィルターとアラームがないと、組織内の権限変更に気付くのが遅れる場合があります。

AWS Shield Advancedの適用要否の確認

サービスのDDoS対応要件に合わせて追加の保護を検討してください。

AWS マネージドキーで暗号化された SNS トピック

SNS の AWS マネージド暗号化キーが組織のキー管理要件に適しているか確認してください。

AWS マネージドキーで暗号化された Secrets Manager シークレット

Secrets Manager の AWS マネージドキーが組織のキー管理要件に適しているか確認してください。

API Gateway REST APIの認証構成の確認

保護対象のREST APIメソッドに適切な認証を関連付け、実際の権限確認を検証してください。

Auto Scalingグループのタグが未設定

グループと新しいインスタンスに必要な運用タグを指定してください。

起動設定のユーザーデータ内にある Base64 形式の秘密鍵の確認

Base64 エンコードでは秘密鍵を保護できません。EC2 のユーザーデータから実際の秘密鍵を取り除いてください。

CloudFrontのコンテンツ配信設定の確認

サービスに必要なCloudFrontディストリビューションとオリジンを設定してください。

CloudFormation スタックの通知設定の確認

CloudFormation スタックのイベントを運用に必要な通知経路へ配信し、失敗・ロールバック通知の受信を確認してください。

CloudFormationスタックポリシーが未設定

スタック更新から保護するリソースをスタックポリシーで指定してください。

CloudFormationスタックのテンプレートが未設定

作成するスタックのテンプレート本文またはURLを指定してください。

CloudFrontのTLSセキュリティポリシーの確認

CloudFrontのクライアント接続に適切な最小TLSバージョンを設定してください。

CloudTrailのログファイル配信通知が未設定

ログファイルの到着通知が必要な場合はSNSトピックを関連付けてください。

CloudTrail ログの KMS キー設定の確認

CloudTrail の既定の保存時暗号化と、個別の KMS キーによる管理を区別して設定してください。

CloudTrailログの整合性確認用ダイジェストが無効になっている

CloudTrailログの変更を検証するためのダイジェストファイルを生成してください。

CloudTrailのリージョンとグローバルイベントの対象範囲の確認

監査に必要なリージョンとグローバルサービスイベントを証跡に含めてください。

CloudTrailの変更を通知するCloudWatchアラームが未設定

CloudTrailの構成変更とログ記録の停止を監視してください。

CloudTrailとCloudWatch Logsが未連携

CloudWatchで監査ログを分析する場合は、CloudTrailからの配信を設定してください。

CloudWatch Logsの送信先ポリシーが過剰なアクセスを許可している

ログサブスクリプションに必要な送信元と操作だけを許可してください。

API Gatewayのメソッド詳細メトリクスが無効になっている

必要なAPIメソッドで詳細なCloudWatchメトリクスを有効にしてください。

Route 53のパブリックDNSクエリログが未設定

詳細ログが必要なパブリックホストゾーンのDNSクエリを記録してください。

CloudWatch ログの保存期間の確認

CloudWatch ログの保存期間を運用・規制要件に合わせ、必要な記録の喪失と過剰な保存を防いでください。

API GatewayのCloudWatchログ配信設定の確認

API Gatewayで使うログの種類に合わせて、CloudWatchへの配信と保持期間を確認してください。

AWS マネージドキーを使用する CodeBuild プロジェクト

CodeBuild のビルド成果物に必要なキーポリシーに応じて、AWS マネージドキーまたはカスタマー管理キーを選択してください。

Cognito User Pool の MFA 適用範囲の確認

必要なパスワード認証に MFA を適用し、任意設定で保護される利用者の範囲を確認してください。

DocumentDBの暗号化キー管理の確認

キー管理の要件に合うKMSキーを選んでください。

DynamoDBゲートウェイエンドポイントの経路関連付けの確認

アプリケーション用サブネットのルートテーブルをエンドポイントに関連付けてください。

DynamoDB のポイントインタイムリカバリが無効

重要なテーブルの復旧目標に合わせ、時点復旧と実際の復元手順を用意してください。

EC2 の EBS 最適化設定の確認

インスタンスタイプの既定動作と、ワークロードの EBS 性能要件を確認してください。

EC2 ユーザーデータ内の AWS 認証情報の確認

EC2 のユーザーデータから長期 AWS 認証情報を取り除き、インスタンスロールの一時的な認証情報を使用してください。

EC2 メタデータの IMDSv1 許可の確認

必要なメタデータアクセスには IMDSv2 を要求し、実際の設定を確認してください。

EC2のサブネットとセキュリティグループ選択の確認

EC2のネットワーク配置を明示的に設定してください。

EC2インスタンスのデフォルトVPC利用の確認

デフォルトVPCの利用がワークロードのネットワーク設計に合うか確認してください。

EC2 インスタンスに直接配布する AWS アクセスキー

EC2 に長期キーを置かず、IAM ロールの一時的な認証情報を使用してください。

ECRリポジトリの暗号化キー管理の確認

必要なキー管理の水準に合わせてECRの暗号化を設定してください。

ECRリポジトリのアクセスポリシーの確認

必要な主体とイメージ操作にアクセス権限を限定してください。

ECRイメージの脆弱性スキャン設定の確認

保存したイメージをスキャンし、検出結果に対応してください。

ECS Container Insights 設定の確認

ECS Container Insights で必要な運用情報を収集してください。

ECS サービスに必要なタスク数の確認

運用目的に合わせ、希望するタスク数と実際の実行状態を確認してください。

EFS のカスタマー管理 KMS キーの確認

組織のキー管理要件に合わせて EFS の暗号化キーを選択してください。

EKSコントロールプレーンのログ種別が不足

EKSコントロールプレーンのログ種別をすべて設定してください。