AWS

AWS CloudFormation 리소스의 보안과 운영 설정 관련 문서입니다.

문서 목록

문서 경로
ACM 인증서 도메인 이름 오류 cloudFormation/aws/wildcard_in_acm_certificate_domain_name
ALB HTTP 리스너 사용 cloudFormation/aws/alb_listening_on_http
ALB WAF 미연동 cloudFormation/aws/alb_is_not_integrated_with_waf
ALB 액세스 로그 비활성화 cloudFormation/aws/elb_v2_alb_access_log_disabled
API Gateway 인증 구성 점검 cloudFormation/aws/api_gateway_without_configured_authorizer
API Gateway 상세 CloudWatch 지표 설정 점검 cloudFormation/aws/cloudwatch_metrics_disabled
API Gateway 배포 스테이지의 액세스 로그 설정 점검 cloudFormation/aws/api_gateway_deployment_without_access_log_setting
API Gateway 배포 스테이지의 사용량 계획 미연결 cloudFormation/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
API Gateway 스테이지 로그 설정 점검 cloudFormation/aws/api_gateway_access_logging_disabled
API Gateway 스테이지의 사용량 계획 미연결 cloudFormation/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API Gateway X-Ray 추적 비활성화 cloudFormation/aws/api_gateway_xray_disabled
API Gateway 메서드 인증 설정 점검 cloudFormation/aws/api_gateway_with_open_access
API Gateway API 키 사용량 관리 설정 점검 cloudFormation/aws/api_gateway_method_does_not_contains_an_api_key
API Gateway 사용자 지정 도메인 TLS 정책 점검 cloudFormation/aws/api_gateway_without_security_policy
API Gateway 압축 임계값 점검 cloudFormation/aws/api_gateway_with_invalid_compression
API Gateway 엔드포인트 공개 범위 점검 cloudFormation/aws/api_gateway_endpoint_config_is_not_private
API Gateway 캐시 클러스터 미설정 cloudFormation/aws/api_gateway_cache_cluster_disabled
API Gateway 백엔드 클라이언트 인증서 설정 점검 cloudFormation/aws/api_gateway_without_ssl_certificate
API Gateway의 Lambda 호출 범위 점검 cloudFormation/aws/public_lambda_via_api_gateway
API Gateway의 WAF 보호 설정 점검 cloudFormation/aws/api_gateway_without_waf
AWS Config Aggregator의 리전 범위 제한 cloudFormation/aws/config_configuration_aggregator_to_all_regions_disabled
AWS Support 정책 연결 대상 누락 cloudFormation/aws/support_has_no_role_associated
액세스 키 수명 평가 기준 점검 cloudFormation/aws/access_key_not_rotated_within_90_days
Alexa Skill 비밀정보 저장 방식 점검 cloudFormation/aws/alexa_skill_plaintext_client_secret_exposed
Amazon MQ 브로커 로그 설정 점검 cloudFormation/aws/mq_broker_logging_disabled
Amplify App Access Token 노출 cloudFormation/aws/amplify_app_access_token_exposed
Amplify App Basic Auth 비밀번호 노출 cloudFormation/aws/amplify_app_basic_auth_config_password_exposed
Amplify App OAuth Token 노출 cloudFormation/aws/amplify_app_oauth_token_exposed
Amplify Branch Basic Auth 비밀번호 노출 cloudFormation/aws/amplify_branch_basic_auth_config_password_exposed
Auto Scaling 그룹의 로드 밸런서 연결 점검 cloudFormation/aws/auto_scaling_group_with_no_associated_elb
CloudFormation 스택 알림 미설정 cloudFormation/aws/stack_notifications_disabled
CloudFormation 템플릿에 자격 증명 직접 포함 cloudFormation/aws/cloudformation_specifying_credentials_not_safe
CloudFront 배포와 오리진 구성 점검 cloudFormation/aws/cdn_configuration_is_missing
CloudFront 도메인과 인증서 설정 점검 cloudFormation/aws/vulnerable_default_ssl_certificate
CloudFront 요청 로그 미구성 cloudFormation/aws/cloudfront_logging_disabled
CloudFront TLS 보안 정책 점검 cloudFormation/aws/secure_ciphers_disabled
CloudFront 최소 TLS 버전 미흡 cloudFormation/aws/cloudfront_without_minimum_protocol_tls_1.2
CloudFront가 HTTP 연결 허용 cloudFormation/aws/cloudfront_viewer_protocol_policy_allows_http
CloudFront에 WAF 미연동 cloudFormation/aws/cloudfront_without_waf
CloudFront와 원본 서버 간 암호화 미적용 cloudFormation/aws/connection_between_cloudfront_origin_not_encrypted
CloudTrail CloudWatch Logs 연동 미설정 cloudFormation/aws/cloudtrail_not_integrated_with_cloudwatch
CloudTrail SNS 알림 토픽 미설정 cloudFormation/aws/cloudtrail_sns_topic_name_undefined
CloudTrail 다중 리전 추적 비활성화 cloudFormation/aws/cloudtrail_multi_region_disabled
CloudTrail 로그 KMS 키 미설정 cloudFormation/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrail 로그 파일 무결성 검증 비활성화 cloudFormation/aws/cloudtrail_log_file_validation_disabled
로그 전달이 중지된 CloudTrail 추적 cloudFormation/aws/cloudtrail_logging_disabled
CloudTrail 로그 저장 버킷의 액세스 로깅 점검 cloudFormation/aws/s3_bucket_cloudtrail_logging_disabled
CodeBuild 산출물 암호화 키 점검 cloudFormation/aws/codebuild_not_encrypted
Cognito 사용자 풀 MFA 미설정 cloudFormation/aws/cognito_userpool_without_mfa
DocumentDB 감사·프로파일러 로그 설정 점검 cloudFormation/aws/docdb_logging_disabled
DynamoDB 시점 복구 비활성화 cloudFormation/aws/dynamodb_table_point_in_time_recovery_disabled
DynamoDB 과금 모드 설정 오류 cloudFormation/aws/dynamodb_with_table_billing_mode_not_recommended
EBS 볼륨 KMS 키 미지정 cloudFormation/aws/ebs_volume_without_kms_key_id
인스턴스에 연결되지 않은 EBS 볼륨 cloudFormation/aws/ebs_volume_not_attached_to_instances
네트워크 ACL 규칙 번호 중복 cloudFormation/aws/ec2_network_acl_duplicate_rule
EC2 상세 모니터링 설정 점검 cloudFormation/aws/ec2_instance_monitoring_disabled
기본 VPC를 사용하는 EC2 인스턴스 cloudFormation/aws/ec2_instance_using_default_vpc
EC2 EBS 최적화 설정 점검 cloudFormation/aws/ec2_not_ebs_optimized
EC2 인스턴스의 IAM 역할 연결 점검 cloudFormation/aws/ec2_instance_has_no_iam_role
EC2 메타데이터 서비스 버전 설정 점검 cloudFormation/aws/instance_uses_metadata_service_IMDSv1
EC2가 기본 보안 그룹 사용 cloudFormation/aws/ec2_instance_using_default_security_group
ECR 리포지토리 고객 관리형 KMS 키 미사용 cloudFormation/aws/ecr_repository_not_encrypted_with_CMK
ECR 이미지 스캔 설정 검토 cloudFormation/aws/unscanned_ecr_image
ECR 이미지 태그 변경 가능 cloudFormation/aws/ecr_image_tag_not_immutable
ECS Container Insights 설정 점검 cloudFormation/aws/ecs_cluster_container_insights_disabled
ECS 서비스 배포 가용성 설정 검토 cloudFormation/aws/ecs_service_without_running_tasks
Fargate 태스크 CPU·메모리 조합 오류 cloudFormation/aws/ecs_task_definition_invalid_cpu_or_memory
ECS 태스크의 네트워크 모드 점검 cloudFormation/aws/ecs_task_definition_network_mode_not_recommended
ECS 컨테이너 헬스 체크 미설정 cloudFormation/aws/ecs_task_definition_healthcheck_missing
ECS 태스크의 퍼블릭 IP 할당 cloudFormation/aws/ecs_services_assigned_with_public_ip_address
ECS 서비스의 로드 밸런서 연결 점검 cloudFormation/aws/ecs_no_load_balancer_attached
ECS 서비스 역할의 정책 참조 오류 cloudFormation/aws/inline_policies_are_attached_to_ecs_service
ECS 태스크의 IAM 역할 점검 cloudFormation/aws/empty_roles_for_ecs_cluster_task_definitions
EFS 고객 관리형 KMS 키 점검 cloudFormation/aws/efs_without_kms
EFS 전송 중 암호화 설정 점검 cloudFormation/aws/efs_volume_with_disabled_transit_encryption
EFS 태그 누락 cloudFormation/aws/efs_without_tags
EKS 노드 그룹 원격 접근 제한 미흡 cloudFormation/aws/eks_node_group_remote_access
ELB 액세스 로그 비활성화 cloudFormation/aws/elb_access_log_disabled
ELB 아웃바운드 허용 규칙 점검 cloudFormation/aws/elb_with_security_group_without_outbound_rules
ELB 전송 암호화 설정 점검 cloudFormation/aws/elb_without_secure_protocol
ELB 인바운드 허용 규칙 점검 cloudFormation/aws/elb_with_security_group_without_inbound_rules
ELB 프로토콜 보안 설정 점검 cloudFormation/aws/elb_using_insecure_protocols
EMR 클러스터 VPC 서브넷 선택 점검 cloudFormation/aws/emr_wihout_vpc
EMR 클러스터의 보안 구성 미연결 cloudFormation/aws/emr_cluster_without_security_configuration
EMR 보안 구성의 암호화 비활성화 cloudFormation/aws/emr_security_configuration_encryptions_enabled
ElastiCache VPC와 서브넷 그룹 점검 cloudFormation/aws/elasticache_without_vpc
ElastiCache 기본 포트 사용 점검 cloudFormation/aws/elasticache_using_default_port
Memcached 노드의 단일 가용 영역 배치 cloudFormation/aws/elasticache_nodes_not_created_across_multi_az
ElastiCache 전송 중 암호화 비활성화 cloudFormation/aws/elasticache_with_disabled_transit_encryption
OpenSearch 도메인 HTTPS 미강제 cloudFormation/aws/elasticsearch_with_https_disabled
Elasticsearch 도메인 접근 주체 점검 cloudFormation/aws/elasticsearch_without_iam_authentication
Elasticsearch·OpenSearch 감사 로그 설정 점검 cloudFormation/aws/elasticsearch_without_audit_logs
OpenSearch 노드 간 암호화 설정 점검 cloudFormation/aws/elasticsearch_domain_not_encrypted_node_to_node
OpenSearch 및 Elasticsearch 슬로우 로그 미설정 cloudFormation/aws/elasticsearch_without_slow_logs
Elasticsearch·OpenSearch 오류 로그 설정 점검 cloudFormation/aws/elasticsearch_without_es_application_logs
외부 ID 또는 MFA 보호를 점검해야 하는 교차 계정 역할 신뢰 cloudFormation/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
GameLift 인바운드 포트 범위 점검 cloudFormation/aws/gamelift_fleet_ec2_inbound_permissions_with_port_range
CloudFront 지리적 제한 필요성 점검 cloudFormation/aws/geo_restriction_disabled
GitHub 저장소 공개 범위 점검 cloudFormation/aws/github_repository_set_to_public
GuardDuty 비활성화 cloudFormation/aws/guardduty_detector_disabled
HTTP 포트 전체 공개 cloudFormation/aws/http_port_open
IAM Access Analyzer 미활성화 cloudFormation/aws/iam_access_analyzer_not_enabled
그룹에 속하지 않은 IAM 사용자 cloudFormation/aws/iam_user_with_no_group
IAM 그룹 인라인 정책 사용 cloudFormation/aws/iam_groups_inline_policies
IAM 데이터베이스 인증이 비활성화된 Neptune 클러스터 cloudFormation/aws/neptune_cluster_with_iam_database_authentication_disabled
IAM 비밀번호 최소 길이 부족 cloudFormation/aws/iam_password_without_minimum_length
IAM 사용자 액세스 키 개수 점검 cloudFormation/aws/iam_user_too_many_access_keys
IAM 사용자 콘솔 비밀번호 변경 정책 점검 cloudFormation/aws/user_iam_missing_password_reset_required
IAM 정책의 사용자 직접 연결 cloudFormation/aws/iam_policies_without_groups
EC2 인스턴스 VPC 연결 점검 cloudFormation/aws/instance_with_no_vpc
IoT 정책의 리소스 전체 허용 cloudFormation/aws/iot_policy_allows_wildcard_resource
IoT 정책의 작업 전체 허용 cloudFormation/aws/iot_policy_allows_action_as_wildcard
KMS 고객 관리형 키 자동 회전 비활성화 cloudFormation/aws/cmk_rotation_disabled
KMS 키 자동 회전 설정 점검 cloudFormation/aws/kms_enable_key_rotation_disabled
Elasticsearch 암호화 키 설정 점검 cloudFormation/aws/elasticsearch_domain_encryption_with_kms_disabled
Lambda 함수의 X-Ray 능동 추적 미설정 cloudFormation/aws/lambda_functions_without_x-ray_tracing
Lambda 함수 태그 누락 cloudFormation/aws/lambda_function_without_tags
Lambda 비동기 실행 실패 이벤트의 보관 미설정 cloudFormation/aws/lambda_function_without_dead_letter_queue
Lambda 호출 권한 설정 오류 cloudFormation/aws/lambda_permission_misconfigured
Lambda 호출 주체 와일드카드 사용 cloudFormation/aws/lambda_permission_principal_is_wildcard
Lambda 환경 변수의 AWS 자격 증명 노출 가능성 cloudFormation/aws/hardcoded_aws_access_key_in_lambda
MSK 브로커 로그 내보내기 점검 cloudFormation/aws/msk_cluster_logging_disabled
Neptune 감사 로그 내보내기 점검 cloudFormation/aws/neptune_logging_is_disabled
Network ACL TCP/UDP 포트 범위 점검 cloudFormation/aws/tcp_or_udp_protocol_network_acl_entry_allows_all_ports
RDP 포트가 전체 인터넷에 공개된 보안 그룹 cloudFormation/aws/security_groups_unrestricted_access_to_rdp
RDS IAM 데이터베이스 인증 미사용 cloudFormation/aws/iam_database_auth_not_enabled
RDS Multi-AZ 배포 미사용 cloudFormation/aws/rds_multi_az_deployment_disabled
RDS 기본 포트 사용 점검 cloudFormation/aws/rds_using_default_port
RDS 백업 보존 기간 부족 cloudFormation/aws/low_rds_backup_retention_period
RDS 삭제 방지 비활성화 cloudFormation/aws/rds_db_instance_with_deletion_protection_disabled
RDS 스냅샷 태그 복사 비활성화 cloudFormation/aws/tags_not_copied_to_rds_cluster_snapshot
RDS 자동 마이너 업그레이드 설정 검토 cloudFormation/aws/automatic_minor_upgrades_disabled
RDS 자동 백업 비활성화 cloudFormation/aws/rds_with_backup_disabled
데이터베이스 클러스터 IAM 인증 미사용 cloudFormation/aws/iam_db_cluster_auth_not_enabled
Redshift 기본 포트 사용 점검 cloudFormation/aws/redshift_using_default_port
Redshift 클러스터 암호화 키 점검 cloudFormation/aws/redshift_cluster_without_kms_cmk
Redshift VPC와 서브넷 그룹 점검 cloudFormation/aws/redshift_cluster_without_vpc
Redshift 감사 로그 내보내기 점검 cloudFormation/aws/redshift_cluster_logging_disabled
VPC 기본 경로 용도 점검 cloudFormation/aws/routertable_with_default_routing
Route 53 공개 DNS의 CloudWatch 로그 설정 점검 cloudFormation/aws/cloudwatch_logging_disabled
S3 공개 ACL 무시 설정 점검 cloudFormation/aws/s3_bucket_without_ignore_public_acl
S3 공개 ACL 차단 설정 점검 cloudFormation/aws/s3_bucket_allows_public_acl
S3 공개 정책 버킷의 접근 제한 점검 cloudFormation/aws/s3_bucket_without_restriction_of_public_bucket
S3 버킷 버전 관리 비활성화 cloudFormation/aws/s3_bucket_without_versioning
S3 쓰기 요청의 TLS 강제 설정 점검 cloudFormation/aws/s3_bucket_without_ssl_in_write_actions
S3 CORS 허용 범위 점검 cloudFormation/aws/s3_bucket_with_unsecured_cors_rule
S3 버킷 액세스 로깅 점검 cloudFormation/aws/s3_bucket_logging_disabled
S3 버킷 정책 연결 누락 cloudFormation/aws/s3_bucket_should_have_bucket_policy
SNS 허용 정책의 NotAction 사용 cloudFormation/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
SNS 토픽 KMS 암호화 미설정 cloudFormation/aws/sns_topic_without_kms_master_key_id
SQS 메시지 저장 암호화 설정 점검 cloudFormation/aws/sqs_with_sse_disabled
SQS 큐 정책의 공개 접근 cloudFormation/aws/sqs_policy_with_public_access
SageMaker 엔드포인트 볼륨 암호화 키 점검 cloudFormation/aws/sagemaker_endpoint_config_should_specify_kms_key_id_attribute
SageMaker 노트북의 VPC 서브넷 미지정 cloudFormation/aws/sagemaker_notebook_not_placed_in_vpc
SageMaker 노트북의 직접 인터넷 접근 cloudFormation/aws/sagemaker_enabling_internet_access
Secrets Manager KMS 키 미지정 cloudFormation/aws/secrets_manager_should_specify_kms_key_id
Secrets Manager 암호화 키 점검 cloudFormation/aws/secretsmanager_secret_without_kms
보안 그룹 VPC 선택 점검 cloudFormation/aws/security_groups_without_vpc_attached
보안 그룹 및 규칙 설명 누락 cloudFormation/aws/security_group_rule_without_description
보안 그룹 단일 IP 허용 범위 점검 cloudFormation/aws/security_group_ingress_has_cidr_not_recommended
Shield Advanced 필요성 점검 cloudFormation/aws/shield_advanced_not_in_use
SimpleDB 도메인 사용 검토 cloudFormation/aws/sdb_domain_declared_as_a_resource
StackSet 계정 제거 시 스택 보존 점검 cloudFormation/aws/stack_retention_disabled
UserData에 인코딩된 개인 키가 포함된 구성 cloudFormation/aws/user_data_contains_encoded_private_key
VPC Flow Logs 수집 범위 점검 cloudFormation/aws/vpc_flowlogs_disabled
VPC의 Network Firewall 검사 경로 점검 cloudFormation/aws/vpc_without_network_firewall
VPC 게이트웨이 연결 한도 초과 cloudFormation/aws/vpc_attached_with_too_many_gateways
서브넷 없는 VPC 용도 점검 cloudFormation/aws/vpc_without_attached_subnet
특권 모드가 활성화된 AWS Batch 작업 정의 cloudFormation/aws/batch_job_definition_with_privileged_container_properties
겹치는 Network ACL 포트 규칙 cloudFormation/aws/ec2_network_acl_overlapping_ports
AWS 소유 키를 사용하는 DynamoDB cloudFormation/aws/dynamodb_with_aws_owned_cmk
S3 공개 정책 차단 설정 점검 cloudFormation/aws/s3_bucket_with_public_policy
전체 주소 대역을 허용하는 RDS 연결 보안 그룹 cloudFormation/aws/db_security_group_with_public_scope
서브넷 CIDR에 /0을 지정한 RDS 구성 cloudFormation/aws/rds_associated_with_public_subnet
PublicReadWrite ACL이 지정된 S3 버킷 cloudFormation/aws/s3_bucket_acl_allows_read_or_write_to_all_users
와일드카드 주체를 사용하는 ECR 리포지토리 정책 cloudFormation/aws/ecr_repository_is_publicly_accessible
Principal이 와일드카드이거나 없는 SNS 토픽 정책 cloudFormation/aws/sns_topic_is_publicly_accessible
공개 접근 설정이 활성화되거나 누락된 AWS DMS 복제 인스턴스 cloudFormation/aws/amazon_dms_replication_instance_is_publicly_accessible
공개 접근을 활성화한 RDS 인스턴스 cloudFormation/aws/rds_db_instance_publicly_accessible
Network ACL 프로토콜 허용 범위 점검 cloudFormation/aws/ec2_permissive_network_acl_protocols
관리 포트가 외부에 노출된 보안 그룹 cloudFormation/aws/security_groups_with_exhibited_admin_ports
ECS 서비스 역할의 권한 점검 필요 cloudFormation/aws/ecs_service_admin_role_is_present
데이터베이스의 기본 KMS 키 사용 cloudFormation/aws/default_kms_key_usage
Web ACL의 기본 허용 정책 점검 cloudFormation/aws/webacl_allow_defaultaction
접근 범위가 넓은 보안 그룹 cloudFormation/aws/db_security_group_open_to_large_scope
과도한 데이터 조회 권한을 가진 IAM 정책 cloudFormation/aws/iam_policy_allows_for_data_exfiltration
Route53 호스팅 영역의 서비스 레코드 점검 cloudFormation/aws/route53_record_undefined
AWS 액세스 키의 소유자와 권한 점검 필요 cloudFormation/aws/root_account_has_active_access_keys
모든 주소에 전체 포트를 허용하는 보안 그룹 cloudFormation/aws/fully_open_ingress
삭제 작업의 Principal이 와일드카드인 S3 버킷 정책 cloudFormation/aws/s3_bucket_allows_delete_actions_from_all_principals
와일드카드 주체에 대한 S3 Get 권한 cloudFormation/aws/s3_bucket_allows_get_actions_from_all_principals
Put 작업의 Principal이 와일드카드인 S3 버킷 정책 cloudFormation/aws/s3_bucket_allows_put_actions_from_all_principals
와일드카드 주체에 대한 S3 객체 복원 권한 cloudFormation/aws/s3_bucket_allows_restore_actions_from_all_principals
와일드카드 주체에 대한 S3 목록 조회 권한 cloudFormation/aws/s3_bucket_allows_list_actions_from_all_principals
S3 버킷 정책에서 주체가 와일드카드이거나 누락됨 cloudFormation/aws/s3_bucket_access_to_any_principal
Action과 Principal에 와일드카드를 지정한 S3 버킷 정책 cloudFormation/aws/s3_bucket_with_all_permissions
모든 사용자에게 목록 조회를 허용하는 S3 버킷 ACL cloudFormation/aws/s3_bucket_acl_allows_read_to_all_users
모든 역할을 대상으로 하는 AssumeRole 권한 cloudFormation/aws/iam_policy_grants_assumerole_permission_across_all_services
IAM 역할의 계정 단위 신뢰 범위 점검 cloudFormation/aws/iam_role_allows_all_principals_to_assume
KMS 키 정책의 주체 제한 점검 cloudFormation/aws/kms_allows_wildcard_principal
모든 포트를 전체 인터넷에 허용한 보안 그룹 cloudFormation/aws/security_groups_with_meta_ip
민감한 포트가 외부에 공개된 EC2 보안 그룹 cloudFormation/aws/ec2_sensitive_port_is_publicly_exposed
민감한 포트가 외부에 공개된 ELB 보안 그룹 cloudFormation/aws/elb_sensitive_port_is_exposed_to_entire_network
보안 그룹 SSH 전체 공개 cloudFormation/aws/security_groups_with_unrestricted_access_to_ssh
보안 그룹 egress 전체 공개 cloudFormation/aws/security_group_egress_cidr_open_to_world
보안 그룹 egress 전체 프로토콜 허용 cloudFormation/aws/security_group_egress_with_all_protocols
보안 그룹 egress 포트 범위 점검 cloudFormation/aws/security_group_egress_with_port_range
보안 그룹 ingress 전체 프로토콜 허용 cloudFormation/aws/security_group_ingress_with_all_protocols
보안 그룹 ingress 포트 범위 점검 cloudFormation/aws/security_group_ingress_with_port_range
보안 그룹의 제한 없는 아웃바운드 허용 cloudFormation/aws/security_groups_allows_unrestricted_outbound_traffic
KMS 키 사용 가능 상태 점검 cloudFormation/aws/cmk_is_unusable
사용자 없는 IAM 그룹 cloudFormation/aws/iam_group_without_users
사용자에 직접 연결된 IAM 정책 cloudFormation/aws/iam_policies_attached_to_user
사용자에 직접 연결된 IAM 정책 리소스 cloudFormation/aws/iam_policy_on_user
사용자에 직접 연결된 관리형 IAM 정책 cloudFormation/aws/iam_managed_policy_applied_to_a_user
서버 측 암호화가 구성되지 않은 Kinesis 스트림 cloudFormation/aws/kinesis_sse_not_configured
DynamoDB 암호화 키 설정 확인 필요 cloudFormation/aws/dynamodb_table_not_encrypted
S3 버킷의 기본 암호화 정책 점검 cloudFormation/aws/s3_bucket_without_server_side_encryption
서브넷에서 공인 IP 자동 할당 활성화 cloudFormation/aws/ec2_instance_subnet_has_public_ip_mapping_on_launch
서브넷을 통한 EC2 공인 인스턴스 노출 cloudFormation/aws/ec2_public_instance_exposed_through_subnet
외부에 허용된 포트 범위 점검 cloudFormation/aws/unknown_port_exposed_to_internet
EBS 암호화 모니터링 구성 확인 필요 cloudFormation/aws/config_rule_for_encryption_volumes_disabled
Amazon MQ 암호화 키 설정 확인 필요 cloudFormation/aws/amazon_mq_broker_encryption_disabled
EKS 암호화 키 설정 점검 cloudFormation/aws/eks_cluster_encryption_disabled
SageMaker 노트북 인스턴스 암호화 키 설정 점검 cloudFormation/aws/sagemaker_data_encryption_disabled
암호화가 비활성화된 API Gateway 캐시 cloudFormation/aws/api_gateway_cache_encrypted_disabled
EBS 볼륨 암호화 확인 필요 cloudFormation/aws/ebs_volume_encryption_disabled
암호화가 비활성화된 EFS 파일 시스템 cloudFormation/aws/efs_not_encrypted
암호화가 설정되지 않은 WorkSpaces cloudFormation/aws/workspace_without_encryption
저장 암호화가 비활성화된 DAX 클러스터 cloudFormation/aws/dax_cluster_not_encrypted
EBS 블록 디바이스 암호화 확인 필요 cloudFormation/aws/block_device_is_not_encrypted
데이터베이스 저장 암호화 확인 필요 cloudFormation/aws/cmk_unencrypted_storage
ELB TLS 보안 정책 점검 cloudFormation/aws/elb_using_weak_ciphers
실행 역할을 공유하는 Lambda 함수 cloudFormation/aws/lambda_functions_without_unique_iam_roles
외부에서 접근 가능한 Amazon MQ 브로커 cloudFormation/aws/mq_broker_is_publicly_accessible
외부에서 접근 가능한 Amazon MSK 브로커 cloudFormation/aws/msk_broker_is_publicly_accessible
Redshift 공개 접근 설정 점검 cloudFormation/aws/redshift_publicly_accessible
모든 AWS 계정에 목록 조회를 허용하는 S3 버킷 ACL cloudFormation/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
인터넷에 공개된 RDP 포트 cloudFormation/aws/remote_desktop_port_open_to_internet
저장 데이터 암호화가 비활성화된 Neptune 데이터베이스 클러스터 cloudFormation/aws/neptune_database_cluster_encryption_disabled
RDS 인스턴스 저장 암호화 설정 점검 cloudFormation/aws/rds_storage_not_encrypted
RDS 클러스터 저장 암호화 설정 점검 cloudFormation/aws/rds_storage_encryption_disabled
Redshift 저장 암호화 설정 점검 cloudFormation/aws/redshift_not_encrypted
MSK 클러스터 암호화 설정 점검 cloudFormation/aws/msk_cluster_encryption_disabled
ECS와 EFS 간 전송 암호화 확인 필요 cloudFormation/aws/ecs_cluster_not_encrypted_at_rest
저장 시 암호화가 비활성화된 ElastiCache Redis 복제 그룹 cloudFormation/aws/elasticache_with_disabled_at_rest_encryption
저장 시 암호화가 비활성화된 Elasticsearch 도메인 cloudFormation/aws/elasticsearch_not_encrypted_at_rest
권한이 과도할 수 있는 Lambda 실행 역할 cloudFormation/aws/lambda_functions_with_full_privileges
모든 작업과 리소스를 허용하는 IAM 정책 cloudFormation/aws/iam_policy_grants_full_permissions
전체 권한을 허용하는 IAM 정책 cloudFormation/aws/iam_policies_with_full_privileges
KMS 키 정책의 권한 점검 필요 cloudFormation/aws/kms_key_with_full_permissions
전체 출발지를 허용하는 보안 그룹 인바운드 규칙 cloudFormation/aws/unrestricted_security_group_ingress
정적 웹사이트 호스팅이 설정된 S3 버킷 cloudFormation/aws/s3_static_website_host_enabled
트래픽 규칙이 남아 있는 기본 보안 그룹 cloudFormation/aws/default_security_groups_with_unrestricted_traffic
평문 마스터 비밀번호가 포함된 DocumentDB 클러스터 cloudFormation/aws/docdb_cluster_master_password_in_plaintext
평문 비밀번호가 포함된 DMS MongoDB 엔드포인트 설정 cloudFormation/aws/dms_endpoint_mongo_db_settings_password_exposed
평문 비밀번호가 포함된 DMS 엔드포인트 cloudFormation/aws/dms_endpoint_password_exposed
평문 비밀번호가 포함된 Directory Service Microsoft AD cloudFormation/aws/directory_service_microsoft_ad_password_set_to_plaintext_or_default_ref
평문 비밀번호가 포함된 Directory Service Simple AD cloudFormation/aws/directory_service_simple_ad_password_exposed
템플릿의 IAM 로그인 비밀번호 노출 가능성 cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext
평문으로 노출된 Alexa ASK 스킬 리프레시 토큰 cloudFormation/aws/refresh_token_is_exposed
Network ACL 차단 범위 점검 cloudFormation/aws/ec2_network_acl_ineffective_denied_traffic

관련 문서262

ACM 인증서 도메인 이름 오류

인증서에 유효한 도메인과 필요한 범위를 지정하세요.

ALB HTTP 리스너 사용

클라이언트와 ALB 사이 통신에 HTTPS를 사용하세요.

ALB WAF 미연동

공개 ALB에 필요한 AWS WAF 웹 요청 필터링을 구성하세요.

ALB 액세스 로그 비활성화

ALB 액세스 로그를 S3에 저장해 요청 흐름을 조사할 수 있게 하세요.

API Gateway 인증 구성 점검

보호할 API 경로에 적절한 인증을 연결하고 실제 권한 검사를 확인하세요.

API Gateway 상세 CloudWatch 지표 설정 점검

메서드별 분석이 필요한 API에 상세 지표를 적용하세요.

API Gateway 배포 스테이지의 액세스 로그 설정 점검

운영 스테이지의 요청 기록을 남기고 실제 로그 전달을 확인하세요.

API Gateway 배포 스테이지의 사용량 계획 미연결

API 키별 사용량 관리가 필요하면 배포 스테이지를 사용량 계획에 연결하세요.

API Gateway 스테이지 로그 설정 점검

API 요청과 오류를 조사할 수 있도록 스테이지의 로그 수집을 구성하세요.

API Gateway 스테이지의 사용량 계획 미연결

API 키별 제한이 필요한 스테이지를 사용량 계획에 연결하세요.

API Gateway X-Ray 추적 비활성화

REST API의 분산 추적 요구에 맞춰 X-Ray를 구성하세요.

API Gateway 메서드 인증 설정 점검

보호가 필요한 메서드에 호출자 인증과 작업별 접근 권한을 적용하세요.

API Gateway API 키 사용량 관리 설정 점검

사용량 계획이 필요한 메서드에 API 키를 적용하고 호출자 인증은 별도로 구성하세요.

API Gateway 사용자 지정 도메인 TLS 정책 점검

지원되는 TLS 정책으로 오래된 프로토콜을 제한하고 클라이언트 호환성을 확인하세요.

API Gateway 압축 임계값 점검

압축이 필요하면 유효한 바이트 단위 임계값을 지정하세요.

API Gateway 엔드포인트 공개 범위 점검

내부 전용 API의 네트워크 경로와 호출 권한을 필요한 범위로 제한하세요.

API Gateway 캐시 클러스터 미설정

캐시가 적합한 REST API에 응답 캐시를 구성하세요.

API Gateway 백엔드 클라이언트 인증서 설정 점검

HTTPS 백엔드가 API Gateway 호출을 확인해야 할 때 클라이언트 인증서를 구성하세요.

API Gateway의 Lambda 호출 범위 점검

API Gateway의 Lambda 호출 권한을 필요한 API 경로로 제한하고 사용자 인증은 별도로 확인하세요.

API Gateway의 WAF 보호 설정 점검

REST API 스테이지에 필요한 웹 요청 필터링을 적용하고 정상 요청에 미치는 영향을 확인하세요.

AWS Config Aggregator의 리전 범위 제한

중앙 점검에 필요한 리전이 집계 범위에 포함되는지 확인하세요.

AWS Support 정책 연결 대상 누락

지원 업무에 필요한 권한을 실제 담당 대상에 연결하세요.

액세스 키 수명 평가 기준 점검

액세스 키 수명 평가 기준과 실제 키 교체 절차를 함께 관리하세요.

Alexa Skill 비밀정보 저장 방식 점검

Alexa 인증 비밀값을 템플릿에 직접 기록하지 말고 접근이 제한된 비밀 저장소로 관리하세요.

Amazon MQ 브로커 로그 설정 점검

브로커 엔진에 맞는 운영·감사 로그를 수집하세요.

Amplify App Access Token 노출

Amplify App의 AccessToken을 템플릿에 직접 넣으면 배포 코드와 이력에 민감 정보가 남을 수 있습니다.

Amplify App Basic Auth 비밀번호 노출

Amplify App Basic Auth 비밀번호를 평문으로 저장하면 템플릿을 통해 자격 증명이 노출될 수 있습니다.

Amplify App OAuth Token 노출

Amplify App의 OAuth 토큰을 템플릿에 직접 두면 외부 저장소 연동 자격 증명이 코드와 이력에 남을 수 있습니다.

Amplify Branch Basic Auth 비밀번호 노출

Amplify Branch의 Basic Auth 비밀번호를 템플릿에 직접 넣으면 브랜치 보호용 자격 증명이 코드에 남을 수 있습니다.

Auto Scaling 그룹의 로드 밸런서 연결 점검

요청을 분산해야 하는 Auto Scaling 그룹에 로드 밸런서를 연결하세요.

CloudFormation 스택 알림 미설정

스택 이벤트를 받을 SNS 토픽을 구성하세요.

CloudFormation 템플릿에 자격 증명 직접 포함

CloudFormation 템플릿의 비밀값을 제거하고 용도에 맞는 역할·비밀 관리 방식을 사용하세요.

CloudFront 배포와 오리진 구성 점검

서비스에 필요한 CloudFront 배포와 오리진 구성을 확인하고 오리진 접근, HTTPS 및 애플리케이션 보안을 별도로 관리하세요.

CloudFront 도메인과 인증서 설정 점검

사용자 지정 도메인과 인증서의 이름·리전 및 TLS 정책을 확인하세요.

CloudFront 요청 로그 미구성

CloudFront 요청 로그를 수집하고 실제 전달 결과를 확인하세요.

CloudFront TLS 보안 정책 점검

CloudFront 사용자 연결에 필요한 최소 TLS 버전과 암호군을 확인하세요.

CloudFront 최소 TLS 버전 미흡

사용자 지정 도메인의 CloudFront 연결에 적절한 TLS 보안 정책을 적용하세요.

CloudFront가 HTTP 연결 허용

CloudFront 사용자 연결에 HTTPS를 적용하세요.

CloudFront에 WAF 미연동

CloudFront에 서비스에 맞는 AWS WAF 규칙을 적용하세요.

CloudFront와 원본 서버 간 암호화 미적용

CloudFront와 사용자 지정 원본 서버 사이에도 HTTPS를 사용하세요.

CloudTrail CloudWatch Logs 연동 미설정

CloudWatch로 감사 이벤트를 분석한다면 로그 전달을 구성하세요.

CloudTrail SNS 알림 토픽 미설정

로그 파일 전달 알림이 필요하면 SNS 토픽을 연결하세요.

CloudTrail 다중 리전 추적 비활성화

필요한 리전 전반의 활동을 기록하도록 트레일을 구성하세요.

CloudTrail 로그 KMS 키 미설정

로그의 키 관리 요구에 맞춰 KMS 암호화를 구성하세요.

CloudTrail 로그 파일 무결성 검증 비활성화

서명된 다이제스트로 CloudTrail 로그의 무결성을 확인하세요.

로그 전달이 중지된 CloudTrail 추적

감사에 필요한 CloudTrail 추적의 이벤트 기록과 로그 전달을 활성화하세요.

CloudTrail 로그 저장 버킷의 액세스 로깅 점검

CloudTrail 로그 저장 버킷에 대한 요청 기록의 범위와 보존 상태를 확인하세요.

CodeBuild 산출물 암호화 키 점검

CodeBuild 출력 산출물에 사용하는 암호화 키가 조직의 키 관리 요구사항을 충족하는지 확인하세요.

Cognito 사용자 풀 MFA 미설정

비밀번호 로그인에 필요한 추가 인증을 구성하세요.

DocumentDB 감사·프로파일러 로그 설정 점검

필요한 로그 생성과 CloudWatch 내보내기를 함께 구성하세요.