AWS

Terraform으로 관리하는 AWS 리소스의 보안과 구성 관련 문서입니다.

문서 목록

문서 경로
API Gateway 배포 단계의 사용량 계획 연결 점검 terraform/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
API Gateway 단계의 사용량 계획 연결 점검 terraform/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API Gateway X-Ray 추적 비활성화 terraform/aws/api_gateway_xray_disabled
API Gateway 응답 압축 설정 점검 terraform/aws/api_gateway_with_invalid_compression
API Gateway의 Lambda 호출 범위 점검 terraform/aws/public_lambda_via_api_gateway
API Gateway API Key 사용량 관리 점검 terraform/aws/api_gateway_method_does_not_contains_an_api_key
AWS Config 집계 대상 리전 점검 terraform/aws/config_configuration_aggregator_to_all_regions_disabled
AWS Config 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_aws_config_configuration_changes_alarm_missing
AWS Management Console 인증 실패 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_management_console_auth_failed_alarm_missing
AWS Organizations 변경 감지 알람 미설정 terraform/aws/cloudwatch_aws_organizations_changes_missing_alarm
AWS Shield Advanced 적용 필요성 점검 terraform/aws/shield_advanced_not_in_use
AWS 관리형 키로 암호화된 SNS 토픽 terraform/aws/sns_topic_encrypted_with_aws_managed_key
AWS 관리형 키로 암호화된 Secrets Manager 시크릿 terraform/aws/secretsmanager_secret_encrypted_with_aws_managed_key
API Gateway REST API 인증 구성 점검 terraform/aws/api_gateway_without_configured_authorizer
Auto Scaling 그룹 태그 누락 terraform/aws/autoscaling_groups_supply_tags
시작 구성 사용자 데이터의 Base64 개인 키 점검 terraform/aws/user_data_contains_encoded_private_key
CloudFront 콘텐츠 전달 구성 점검 terraform/aws/cdn_configuration_is_missing
CloudFormation 스택 알림 구성 점검 terraform/aws/stack_notifications_disabled
CloudFormation 스택 정책 미설정 terraform/aws/no_stack_policy
CloudFormation 스택 템플릿 미설정 terraform/aws/stack_without_template
CloudFront의 TLS 보안 정책 점검 terraform/aws/secure_ciphers_disabled
CloudTrail 로그 파일 전달 알림 미설정 terraform/aws/cloudtrail_sns_topic_name_undefined
CloudTrail 로그의 KMS 키 설정 점검 terraform/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrail 로그 무결성 검증 자료 미생성 terraform/aws/cloudtrail_log_file_validation_disabled
CloudTrail의 리전 및 글로벌 이벤트 범위 점검 terraform/aws/cloudtrail_multi_region_disabled
CloudTrail 설정 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_cloudtrail_configuration_changes_alarm_missing
CloudTrail의 CloudWatch Logs 연동 미설정 terraform/aws/cloudtrail_not_integrated_with_cloudwatch
CloudWatch Logs 목적지의 과도한 허용 정책 terraform/aws/cloudwatch_logs_destination_with_vulnerable_policy
API Gateway 메서드 상세 지표 비활성화 terraform/aws/cloudwatch_metrics_disabled
Route 53 공개 DNS 질의 로깅 미설정 terraform/aws/cloudwatch_logging_disabled
CloudWatch 로그 보존 기간 점검 terraform/aws/cloudwatch_without_retention_period_specified
API Gateway CloudWatch 로그 전달 설정 점검 terraform/aws/api_gateway_with_cloudwatch_logging_disabled
CodeBuild 프로젝트에 AWS 관리형 키 사용 terraform/aws/codebuild_project_encrypted_with_aws_managed_key
Cognito User Pool MFA 적용 범위 점검 terraform/aws/cognito_userpool_without_mfa
DocumentDB 암호화 키 관리 방식 점검 terraform/aws/docdb_cluster_encrypted_with_aws_managed_key
DynamoDB 게이트웨이 엔드포인트 라우팅 연결 점검 terraform/aws/dynamodb_vpc_endpoint_without_route_table_association
DynamoDB 시점 복구 비활성화 terraform/aws/dynamodb_table_point_in_time_recovery_disabled
EC2 EBS 최적화 설정 점검 terraform/aws/ec2_not_ebs_optimized
EC2 사용자 데이터의 AWS 자격 증명 점검 terraform/aws/hardcoded_aws_access_key
EC2 메타데이터의 IMDSv1 허용 여부 점검 terraform/aws/instance_uses_metadata_service_IMDSv1
EC2 인스턴스의 서브넷과 보안 그룹 선택 점검 terraform/aws/instance_with_no_vpc
EC2 인스턴스의 기본 VPC 사용 점검 terraform/aws/ec2_instance_using_default_vpc
EC2 인스턴스에 직접 배포하는 AWS 액세스 키 terraform/aws/ec2_instance_using_api_keys
ECR 리포지토리 암호화 키 관리 점검 terraform/aws/ecr_repository_not_encrypted
ECR 리포지토리 접근 정책 점검 terraform/aws/ecr_repository_without_policy
ECR 이미지 취약점 검사 설정 점검 terraform/aws/unscanned_ecr_image
ECS Container Insights 설정 점검 terraform/aws/ecs_cluster_container_insights_disabled
ECS 서비스의 필요한 태스크 수 점검 terraform/aws/ecs_service_without_running_tasks
EFS 고객 관리형 KMS 키 점검 terraform/aws/efs_without_kms
EKS 클러스터 제어 플레인 로그 유형 누락 terraform/aws/missing_cluster_log_types
EMR 클러스터 서브넷 선택 점검 terraform/aws/emr_without_vpc
ENCRYPTED_VOLUMES AWS Config 규칙이 없는 구성 terraform/aws/config_rule_for_encrypted_volumes_is_disabled
ElastiCache 엔진 선택 점검 terraform/aws/redis_disabled
ElastiCache 서브넷 그룹 선택 점검 terraform/aws/elasticache_without_vpc
ElastiCache 기본 포트와 접근 통제 점검 terraform/aws/elasticache_using_default_port
Elasticsearch 슬로우 로그 구성 점검 terraform/aws/elasticsearch_without_slow_logs
교차 계정 IAM 역할의 신뢰 조건 점검 terraform/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
GuardDuty 탐지기 비활성화 terraform/aws/guardduty_detector_disabled
S3 버킷의 HTTPS 강제 정책 점검 terraform/aws/s3_bucket_policy_accepts_http_requests
HTTP 포트 80의 인터넷 공개 terraform/aws/http_port_open
HTTPS를 강제하지 않는 Elasticsearch 도메인 terraform/aws/elasticsearch_with_https_disabled
HTTP로 수신하는 AWS ALB 리스너 terraform/aws/alb_listening_on_http
HTTP를 허용하는 CloudFront 뷰어 정책 terraform/aws/cloudfront_viewer_protocol_policy_allows_http
IAM Access Analyzer 구성 점검 terraform/aws/iam_access_analyzer_not_enabled
IAM 데이터베이스 인증이 비활성화된 Neptune 클러스터 terraform/aws/neptune_cluster_with_iam_database_authentication_disabled
IAM 비밀번호 만료 정책 점검 terraform/aws/misconfigured_password_policy_expiration
IAM 비밀번호 재사용 방지 점검 terraform/aws/password_without_reuse_prevention
IAM 비밀번호 최소 길이 점검 terraform/aws/iam_password_without_minimum_length
IAM 사용자 정책의 MFA 요구 조건 점검 terraform/aws/iam_user_policy_without_mfa
Elasticsearch 도메인의 IAM 접근 제어 점검 terraform/aws/elasticsearch_without_iam_authentication
IAM 정책 변경 감지 알람 누락 terraform/aws/cloudwatch_iam_policy_changes_alarm_missing
KMS 고객 관리형 키 회전 설정 점검 terraform/aws/cmk_rotation_disabled
KMS 암호화가 없는 AWS Kinesis Stream terraform/aws/kinesis_not_encrypted_with_kms
CloudWatch 로그 그룹 암호화 키 설정 점검 terraform/aws/cloudwatch_log_group_not_encrypted
KMS 키 삭제 대기 기간 점검 terraform/aws/kms_key_with_no_deletion_window
DocumentDB 암호화 키 설정 점검 terraform/aws/docdb_cluster_without_kms
Elasticsearch 암호화 키 설정 점검 terraform/aws/elasticsearch_encryption_with_kms_is_disabled
SageMaker 노트북 인스턴스 암호화 키 설정 점검 terraform/aws/sagemaker_notebook_instance_without_kms
Secrets Manager 시크릿의 암호화 키 설정 점검 terraform/aws/secretsmanager_secret_without_kms
Lambda 비동기 실패 이벤트 보관 설정 점검 terraform/aws/lambda_function_without_dead_letter_queue
Lambda InvokeFunction IAM 권한 범위 점검 terraform/aws/lambda_iam_invokefunction_misconfigured
Lambda 권한의 action 설정 점검 terraform/aws/lambda_permission_misconfigured
Lambda X-Ray 추적 설정 점검 terraform/aws/lambda_functions_without_x-ray_tracing
Lambda 환경 변수의 AWS 자격 증명 점검 terraform/aws/hardcoded_aws_access_key_in_lambda
IAM 사용자 접근의 MFA 요구 조건 점검 terraform/aws/authentication_without_mfa
MFA 없는 콘솔 로그인 감지 알람 누락 terraform/aws/cloudwatch_management_console_sign_in_without_mfa_alarm_missing
MQ 브로커 로그 설정 점검 terraform/aws/mq_broker_logging_disabled
MSK 클러스터 브로커 로그 설정 점검 terraform/aws/msk_cluster_logging_disabled
NACL 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_changes_to_nacl_alarm_missing
Neptune 감사 로그 내보내기 설정 점검 terraform/aws/neptune_logging_disabled
VPC의 Network Firewall 사용 여부 점검 terraform/aws/vpc_without_network_firewall
API Gateway 엔드포인트 공개 범위 점검 terraform/aws/api_gateway_endpoint_config_is_not_private
RDS for PostgreSQL 쿼리 로깅 설정 점검 terraform/aws/postgres_rds_logging_disabled
Principal이 없는 리소스 기반 정책 terraform/aws/policy_without_principal
전체 주소에서 RDP를 허용하는 AWS Network ACL terraform/aws/network_acl_with_unrestricted_access_to_rdp
모든 주소에서 RDP를 허용하는 AWS 보안 그룹 terraform/aws/remote_desktop_port_open_to_internet
RDS 기본 포트와 접근 통제 점검 terraform/aws/rds_using_default_port
RDS CloudWatch 로그 내보내기 설정 점검 terraform/aws/rds_without_logging
RDS 인스턴스 자동 백업 비활성화 terraform/aws/rds_with_backup_disabled
RDS 인스턴스의 IAM 데이터베이스 인증 미사용 terraform/aws/iam_database_auth_not_enabled
RDS 자동 마이너 업그레이드 비활성화 terraform/aws/automatic_minor_upgrades_disabled
RDS 클러스터 백업 보존 기간 점검 terraform/aws/rds_cluster_with_backup_disabled
RDS 스냅샷 태그 복사 설정 점검 terraform/aws/tags_not_copied_to_rds_cluster_snapshot
RDS 클러스터의 IAM 데이터베이스 인증 미사용 terraform/aws/iam_db_cluster_auth_not_enabled
RSA 키가 너무 짧은 TLS 인증서 terraform/aws/certificate_rsa_key_bytes_lower_than_256
Redshift 기본 포트와 접근 통제 점검 terraform/aws/redshift_using_default_port
Redshift 클러스터의 네트워크 선택 점검 terraform/aws/redshift_cluster_without_vpc
Redshift 감사 로그 설정 점검 terraform/aws/redshift_cluster_logging_disabled
S3 객체 CloudTrail 데이터 이벤트 수집 설정 점검 terraform/aws/s3_bucket_object_level_cloudtrail_logging_disabled
S3 버킷 MFA Delete 사용 여부 점검 terraform/aws/s3_bucket_without_enabled_mfa_delete
S3 서버 액세스 로깅 설정 점검 terraform/aws/s3_bucket_logging_disabled
S3 버킷 이벤트 알림 구성 점검 terraform/aws/s3_bucket_notifications_disabled
S3 버킷 정책 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_s3_policy_change_alarm_missing
SQL Analysis Services 포트 2383의 전체 공개 허용 terraform/aws/sql_analysis_services_port_2383_is_publicly_accessible
SQS VPC 엔드포인트 DNS 설정 점검 terraform/aws/sqs_vpc_endpoint_without_dns_resolution
SQS 큐의 서버 측 암호화 설정 점검 terraform/aws/sqs_with_sse_disabled
네트워크 ACL의 광범위한 SSH 허용 terraform/aws/network_acl_with_unrestricted_access_to_ssh
보안 그룹의 SSH 인터넷 전체 허용 terraform/aws/security_group_with_unrestricted_access_to_ssh
API Gateway 백엔드 클라이언트 인증서 설정 점검 terraform/aws/api_gateway_without_ssl_certificate
SSM 세션의 추가 KMS 암호화 설정 점검 terraform/aws/ssm_session_transit_encryption_disabled
IAM Identity Center 권한 세트 세션 시간 점검 terraform/aws/sso_permission_with_inadequate_user_session_duration
보안 그룹 규칙 설명 미작성 terraform/aws/security_group_rules_without_description
보안 그룹 용도 설명 점검 terraform/aws/security_group_without_description
Service Control Policy를 사용할 수 없는 AWS Organizations 설정 terraform/aws/service_control_policies_disabled
StackSet 스택 보존 설정 점검 terraform/aws/stack_retention_disabled
Terraform으로 직접 생성되는 AWS Identity Center 사용자 terraform/aws/sso_policy_with_full_priveleges_copy
VPC Flow Logs 수집 범위 점검 terraform/aws/vpc_flowlogs_disabled
VPC 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_vpc_changes_alarm_missing
API Gateway의 WAF 보호 설정 점검 terraform/aws/api_gateway_without_waf
CloudFront의 WAF 연결 설정 점검 terraform/aws/cloudfront_without_waf
WAF와 연동되지 않은 AWS ALB terraform/aws/alb_is_not_integrated_with_waf
WRITE_ACP 권한을 지정한 S3 버킷 ACL terraform/aws/s3_bucket_acl_grants_write_acp_permission
Effect: Allow와 NotAction을 함께 사용하는 SNS 토픽 정책 terraform/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
CloudFormation과 PassRole 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
CloudFormation 생성과 PassRole 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
cloudformation:CreateStack와 iam:PassRole로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
EC2 실행과 PassRole 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
EC2 실행과 PassRole 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
ec2:RunInstances와 iam:PassRole로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
Glue 생성과 PassRole 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
Glue 생성과 PassRole 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
glue:CreateDevEndpoint와 iam:PassRole로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
glue:UpdateDevEndpoint 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
glue:UpdateDevEndpoint 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
glue:UpdateDevEndpoint로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAM 그룹의 iam:AddUserToGroup 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM 사용자의 iam:AddUserToGroup 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM 역할의 iam:AddUserToGroup 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM 그룹의 iam:AttachGroupPolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM 사용자의 iam:AttachGroupPolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM 역할의 iam:AttachGroupPolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM 그룹의 iam:AttachRolePolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM 사용자의 iam:AttachRolePolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM 역할의 iam:AttachRolePolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM 그룹의 iam:AttachUserPolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM 사용자의 iam:AttachUserPolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM 역할의 iam:AttachUserPolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachUserPolicy
iam:CreateAccessKey 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateAccessKey
iam:CreateAccessKey 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateAccessKey
iam:CreateAccessKey로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateAccessKey
iam:CreateLoginProfile 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateLoginProfile
iam:CreateLoginProfile 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateLoginProfile
iam:CreateLoginProfile로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAM 그룹의 iam:CreatePolicyVersion 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM 사용자의 iam:CreatePolicyVersion 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM 역할의 iam:CreatePolicyVersion 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM 그룹의 iam:PutGroupPolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM 사용자의 iam:PutGroupPolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM 역할의 iam:PutGroupPolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM 그룹의 iam:PutRolePolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM 사용자의 iam:PutRolePolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM 역할의 iam:PutRolePolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM 그룹의 iam:PutUserPolicy 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM 사용자의 iam:PutUserPolicy 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM 역할의 iam:PutUserPolicy 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM 그룹의 iam:SetDefaultPolicyVersion 권한 점검 terraform/aws/group_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM 사용자의 iam:SetDefaultPolicyVersion 권한 점검 terraform/aws/user_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM 역할의 iam:SetDefaultPolicyVersion 권한 점검 terraform/aws/role_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
역할 신뢰 변경과 역할 전환 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
신뢰 정책 변경과 역할 전환 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
iam:UpdateAssumeRolePolicy와 sts:AssumeRole로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
iam:UpdateLoginProfile 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
iam:UpdateLoginProfile 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
iam:UpdateLoginProfile로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
Lambda 생성·호출과 PassRole 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
Lambda 생성·호출과 PassRole 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
lambda:CreateFunction, lambda:InvokeFunction, iam:PassRole로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_lambda_InvokeFunction
lambda:UpdateFunctionCode 권한이 과도한 IAM 그룹 terraform/aws/group_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
lambda:UpdateFunctionCode 권한이 과도한 IAM 사용자 terraform/aws/user_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
lambda:UpdateFunctionCode로 권한 상승이 가능한 IAM 역할 terraform/aws/role_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
privileged 컨테이너가 설정된 AWS Batch Job Definition terraform/aws/batch_job_definition_with_privileged_container_properties
EKS 암호화 키 설정 점검 terraform/aws/eks_cluster_encryption_disabled
개별 사용자에 직접 연결된 IAM 정책 terraform/aws/iam_policies_attached_to_user
고객 관리형 KMS 키 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_disabling_or_scheduled_deletion_of_customer_created_cmk_alarm_missing
S3 공개 ACL 무시 설정 점검 terraform/aws/s3_bucket_without_ignore_public_acl
공개 ACL과 공개 접근 차단을 함께 설정한 S3 버킷 terraform/aws/s3_bucket_public_acl_overridden_by_public_access_block
S3 공개 ACL 차단 설정 점검 terraform/aws/s3_bucket_allows_public_acl
S3 공개 버킷 정책 차단 설정 점검 terraform/aws/s3_bucket_with_public_policy
서브넷 CIDR에 /0을 지정한 RDS 구성 terraform/aws/rds_associated_with_public_subnet
전체 주소 범위를 허용하는 기존 DB 보안 그룹 terraform/aws/db_security_group_has_public_interface
공개 접근을 활성화한 DMS 복제 인스턴스 terraform/aws/amazon_dms_replication_instance_is_publicly_accessible
SQS 큐 정책의 공개 주체 허용 점검 terraform/aws/sqs_policy_with_public_access
공개 접근이 가능한 AWS MQ Broker terraform/aws/mq_broker_is_publicly_accessible
공개 접근이 가능한 AWS MSK Broker terraform/aws/msk_broker_is_publicly_accessible
공개 접근이 가능한 AWS Neptune Cluster Instance terraform/aws/neptune_cluster_instance_is_publicly_accessible
와일드카드 주체를 사용하는 ECR 리포지토리 정책 terraform/aws/ecr_repository_is_publicly_accessible
와일드카드 주체를 사용하는 SNS 토픽 정책 terraform/aws/sns_topic_is_publicly_accessible
CloudTrail 로그 버킷의 공개 접근 점검 terraform/aws/cloudtrail_log_files_s3_bucket_is_publicly_accessible
공개 접근 설정을 확인해야 하는 RDS 구성 terraform/aws/rds_db_instance_publicly_accessible
EC2 인스턴스의 공인 IP 할당 점검 terraform/aws/ec2_instance_has_public_ip
공인 IP가 할당된 ECS 서비스 terraform/aws/ecs_services_assigned_with_public_ip_address
공인 IP를 자동 할당하는 VPC 서브넷 terraform/aws/vpc_subnet_assigns_public_ip
접근 대역 점검이 필요한 기존 DB 보안 그룹 terraform/aws/db_security_group_open_to_large_scope
IAM 역할 신뢰 정책 점검 terraform/aws/iam_role_with_full_privileges
KMS 키 접근 정책 점검 terraform/aws/kms_key_with_full_permissions
Secrets Manager 비밀 접근 정책 점검 terraform/aws/secrets_manager_with_vulnerable_policy
AWS ECS 서비스 역할 권한 점검 terraform/aws/ecs_service_admin_role_is_present
ECS 태스크 정의의 네트워크 모드 점검 terraform/aws/ecs_task_definition_network_mode_not_recommended
과도한 권한이 있는 역할을 사용하는 AWS Lambda 함수 terraform/aws/lambda_function_with_privileged_role
EBS 기본 암호화가 비활성화된 계정·리전 설정 terraform/aws/ebs_default_encryption_disabled
AWS 기본 VPC 구성 점검 terraform/aws/default_vpc_exists
EC2 인스턴스의 기본 보안 그룹 사용 점검 terraform/aws/ec2_instance_using_default_security_group
네트워크 게이트웨이 변경 감지 알람 누락 terraform/aws/cloudwatch_network_gateways_changes_alarm_missing
노드 간 암호화가 없는 Elasticsearch 도메인 terraform/aws/elasticsearch_domain_not_encrypted_node_to_node
다중 AZ로 구성되지 않은 ElastiCache 노드 terraform/aws/elasticache_nodes_not_created_across_multi_az
데이터 유출에 악용될 수 있는 IAM 정책 terraform/aws/iam_policy_allows_for_data_exfiltration
라우팅 테이블 변경 감지 알람 누락 terraform/aws/cloudwatch_route_table_changes_alarm_missing
값이 비어 있는 AWS Route 53 레코드 terraform/aws/route53_record_undefined
CloudFront 요청 로그 설정 점검 terraform/aws/cloudfront_logging_disabled
로깅이 비활성화된 AWS CloudTrail terraform/aws/cloudtrail_logging_disabled
DocumentDB 로그 내보내기 설정 점검 terraform/aws/docdb_logging_disabled
CloudTrail 로그 버킷의 접근 로깅 설정 점검 terraform/aws/cloudtrail_log_files_s3_bucket_with_logging_disabled
로깅이 비활성화된 EKS 클러스터 terraform/aws/eks_cluster_log_disabled
Elasticsearch 로그 게시 설정 점검 terraform/aws/elasticsearch_logs_disabled
루트 사용자 사용 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_root_account_use_alarm_missing
root로 명명된 IAM 사용자의 접근 키 점검 terraform/aws/iam_access_key_is_exposed
만료된 TLS 인증서 terraform/aws/certificate_has_expired
IAM 서비스 역할의 신뢰 주체 점검 terraform/aws/iam_policy_grants_assumerole_permission_across_all_services
작업과 접근 주체에 와일드카드를 사용하는 S3 버킷 정책 terraform/aws/s3_bucket_with_all_permissions
모든 역할에 대한 iam:PassRole 허용 terraform/aws/iam_role_policy_passrole_allows_all
모든 인증된 AWS 계정에 읽기를 허용하는 S3 버킷 ACL terraform/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
SQS 큐 정책의 과도한 작업 허용 점검 terraform/aws/sqs_policy_allows_all_actions
IAM 역할의 계정 단위 신뢰 점검 terraform/aws/iam_role_allows_all_principals_to_assume
와일드카드 주체와 삭제 작업을 지정한 S3 버킷 정책 terraform/aws/s3_bucket_allows_delete_action_from_all_principals
와일드카드 주체와 Put 작업을 지정한 S3 버킷 정책 terraform/aws/s3_bucket_allows_put_action_from_all_principals
와일드카드 주체를 사용하는 S3 버킷 정책 terraform/aws/s3_bucket_access_to_any_principal
모든 주체에게 Get 권한을 허용하는 S3 버킷 정책 terraform/aws/s3_bucket_allows_get_action_from_all_principals
모든 주체에게 목록 조회를 허용하는 S3 버킷 정책 terraform/aws/s3_bucket_allows_list_action_from_all_principals
기본 보안 그룹의 트래픽 허용 점검 terraform/aws/vpc_default_security_group_accepts_all_traffic
전체 주소와의 통신을 허용하는 AWS 기본 보안 그룹 terraform/aws/default_security_groups_with_unrestricted_traffic
미사용 보안 그룹 점검 terraform/aws/security_groups_not_used
민감한 서비스 포트의 사설망 접근 점검 terraform/aws/sensitive_port_is_exposed_to_wide_private_network
관리·내부 서비스 포트가 전체 주소에 허용된 AWS 보안 그룹 terraform/aws/sensitive_port_is_exposed_to_entire_network
자동 백업이 비활성화된 ElastiCache Redis 클러스터 terraform/aws/elasticache_redis_cluster_without_backup
S3 버전 관리 설정 점검 terraform/aws/s3_bucket_without_versioning
보안 그룹 변경 감지 알람이 없는 CloudWatch terraform/aws/cloudwatch_security_group_changes_alarm_missing
AWS ElastiCache Redis OSS 엔진 버전 점검 terraform/aws/redis_not_compliant
API Gateway 커스텀 도메인 TLS 정책 점검 terraform/aws/api_gateway_without_security_policy
볼륨 암호화가 없는 AWS WorkSpaces Workspace terraform/aws/workspaces_workspace_volume_not_encrypted
IAM 사용자 초기 비밀번호 설정 점검 terraform/aws/no_password_policy_enabled
비암호화 EBS 볼륨에서 생성된 AWS Snapshot terraform/aws/ebs_volume_snapshot_not_encrypted
RDS 클러스터 스냅샷 암호화 점검 terraform/aws/rds_database_cluster_not_encrypted
비인가 API 호출에 대한 CloudWatch 모니터링 점검 필요 terraform/aws/cloudwatch_unauthorized_access_defined_alarm_missing
사용자 연결이 없는 IAM 그룹 terraform/aws/iam_group_without_users
IAM 사용자 비밀번호 변경 권한 점검 terraform/aws/aws_password_policy_with_unchangeable_passwords
비활성 KMS 고객 관리형 키 사용 점검 terraform/aws/cmk_is_unusable
삭제 보호가 비활성화된 AWS ALB terraform/aws/alb_deletion_protection_disabled
상세 모니터링이 비활성화된 EC2 인스턴스 terraform/aws/ec2_instance_monitoring_disabled
DynamoDB 테이블 암호화 키 설정 점검 terraform/aws/dynamodb_table_not_encrypted
S3 객체 서버 측 암호화 설정 점검 terraform/aws/s3_bucket_object_not_encrypted
Amazon Data Firehose 서버 측 암호화 설정 점검 terraform/aws/kinesis_sse_not_configured
S3 CORS 허용 범위 점검 terraform/aws/s3_bucket_with_unsecured_cors_rule
ELB 정책의 SSL/TLS 프로토콜 점검 terraform/aws/elb_using_insecure_protocols
포트 공개 범위 점검이 필요한 AWS 보안 그룹 terraform/aws/unknown_port_exposed_to_internet
MSK 클러스터 암호화 설정 점검 terraform/aws/msk_cluster_encryption_disabled
Athena 데이터베이스 생성 쿼리 결과 암호화 설정 점검 terraform/aws/athena_database_not_encrypted
SageMaker 엔드포인트 저장 암호화 키 설정 점검 terraform/aws/sagemaker_endpoint_configuration_encryption_disabled
Amazon MQ 브로커 암호화 키 설정 점검 terraform/aws/amazon_mq_broker_encryption_disabled
Glue Data Catalog 및 연결 비밀번호 암호화 점검 terraform/aws/glue_data_catalog_encryption_disabled
Glue Security Configuration 암호화 설정 점검 terraform/aws/glue_security_configuration_encryption_disabled
암호화가 없는 AWS SNS Topic terraform/aws/sns_topic_not_encrypted
암호화되지 않은 API Gateway 캐시 설정 terraform/aws/api_gateway_method_settings_cache_not_encrypted
암호화되지 않은 AWS AMI terraform/aws/ami_not_encrypted
암호화되지 않은 AWS EBS Volume terraform/aws/ebs_volume_encryption_disabled
암호화되지 않은 AWS EFS 파일 시스템 terraform/aws/efs_not_encrypted
암호화되지 않은 AWS 블록 디바이스 매핑 terraform/aws/block_device_is_not_encrypted
AWS Classic ELB 암호군 정책 점검 terraform/aws/elb_using_weak_ciphers
AWS AMI 계정 공유 범위 점검 terraform/aws/ami_shared_with_multiple_accounts
Elastic IP의 사용 목적과 연결 상태 점검 terraform/aws/aws_eip_not_attached_to_any_instance
Auto Scaling Group의 로드 밸런서 연결 점검 terraform/aws/auto_scaling_group_with_no_associated_elb
오래된 CA 인증서를 사용하는 RDS 인스턴스 terraform/aws/ca_certificate_identifier_is_outdated
Lambda 함수 정책의 과도한 작업 허용 점검 terraform/aws/lambda_with_vulnerable_policy
와일드카드 principal을 사용하는 Lambda 호출 권한 terraform/aws/lambda_permission_principal_is_wildcard
API Gateway REST API 정책의 과도한 접근 범위 terraform/aws/rest_api_with_vulnerable_policy
공개 접근 설정 점검이 필요한 AWS Redshift Cluster terraform/aws/redshift_publicly_accessible
AWS SQS 큐 정책의 접근 범위 점검 terraform/aws/sqs_queue_exposed
운영 태그 미설정 terraform/aws/resource_not_using_tags
API Gateway 메서드 인증 설정 점검 terraform/aws/api_gateway_with_open_access
민감한 서비스 포트의 접근 허용 범위 점검 terraform/aws/sensitive_port_is_exposed_to_small_public_network
잘못된 헤더를 삭제하지 않는 AWS ALB terraform/aws/alb_not_dropping_invalid_headers
Redshift 저장 암호화 점검 terraform/aws/redshift_not_encrypted
Amazon Aurora 저장 암호화 설정 점검 terraform/aws/aurora_with_disabled_at_rest_encryption
저장 데이터 암호화가 없는 AWS DAX Cluster terraform/aws/dax_cluster_not_encrypted
저장 데이터 암호화가 없는 AWS DocDB Cluster terraform/aws/docdb_cluster_not_encrypted
저장 데이터 암호화가 없는 AWS ElastiCache Replication Group terraform/aws/elasticache_replication_group_not_encrypted_at_rest
저장 데이터 암호화가 없는 AWS Elasticsearch 도메인 terraform/aws/elasticsearch_not_encrypted_at_rest
저장 데이터 암호화가 없는 AWS Neptune Cluster terraform/aws/neptune_database_cluster_encryption_disabled
저장소 암호화가 없는 AWS DB Instance terraform/aws/db_instance_storage_not_encrypted
RDS 클러스터 저장 암호화 점검 terraform/aws/rds_storage_not_encrypted
전송 중 암호화가 비활성화된 EFS 볼륨 terraform/aws/efs_volume_with_disabled_transit_encryption
전송 중 암호화가 비활성화된 ElastiCache Replication Group terraform/aws/elasticache_replication_group_not_encrypted_at_transit
VPC 피어링 경로의 목적지 범위 점검 terraform/aws/vpc_peering_route_table_with_unrestricted_cidr
IAM 정책의 과도한 관리 권한 점검 terraform/aws/iam_policies_with_full_privileges
Identity Center 권한 세트의 과도한 권한 점검 terraform/aws/sso_policy_with_full_priveleges
과도한 권한을 허용하는 AWS IAM 정책 terraform/aws/iam_policy_grants_full_permissions
공개 ACL을 지정한 S3 버킷 설정 terraform/aws/s3_bucket_acl_allows_read_or_write_to_all_users
EC2-Classic DB 보안 그룹에서 모든 IPv4 주소 허용 terraform/aws/db_security_group_with_public_scope
전체 인터넷에 노출된 EKS 퍼블릭 접근 CIDR terraform/aws/eks_cluster_has_public_access_cidrs
전체 주소 범위의 인바운드를 허용하는 AWS 보안 그룹 terraform/aws/unrestricted_security_group_ingress
SES 자격 증명 정책의 접근 권한 점검 terraform/aws/ses_policy_with_allowed_iam_actions
API Gateway 배포 Stage의 접근 로그 설정 점검 terraform/aws/api_gateway_deployment_without_access_log_setting
API Gateway Stage 로깅 설정 점검 terraform/aws/api_gateway_access_logging_disabled
접근 로그가 비활성화된 Classic ELB terraform/aws/elb_access_logging_disabled
ELBv2 로드 밸런서의 접근 로그 설정 점검 terraform/aws/elb_v2_lb_access_log_disabled
접근 보안 그룹이 없는 EKS 노드 원격 접근 terraform/aws/eks_node_group_remote_access_disabled
AWS S3 정적 웹사이트 호스팅의 공개 범위 점검 terraform/aws/s3_static_website_host_enabled
구형 TLS를 허용하는 CloudFront 보안 정책 terraform/aws/cloudfront_without_minimum_protocol_tls_1.2
CloudFront 사용자 지정 도메인의 인증서 설정 점검 terraform/aws/vulnerable_default_ssl_certificate
EFS 파일 시스템 정책의 접근 권한 점검 terraform/aws/efs_with_vulnerable_policy
AWS Glue Data Catalog 정책의 권한 점검 terraform/aws/glue_with_vulnerable_policy
Elasticsearch 도메인 정책의 접근 권한 점검 terraform/aws/elasticsearch_domain_with_vulnerable_policy
콘솔 로그인 권한이 있는 IAM 사용자 terraform/aws/iam_user_with_access_to_console
Athena 워크그룹 결과 암호화 설정 점검 terraform/aws/athena_workgroup_not_encrypted
태그 변경이 가능한 AWS ECR 리포지토리 terraform/aws/ecr_image_tag_not_immutable
퍼블릭 EC2와 프라이빗 EC2의 IAM 역할 공유 terraform/aws/public_and_private_ec2_share_role
S3 공개 버킷 접근 제한 설정 점검 terraform/aws/s3_bucket_without_restriction_of_public_bucket
퍼블릭 접근이 허용된 EKS 클러스터 terraform/aws/eks_cluster_has_public_access
한 IAM 사용자의 액세스 키 수 점검 terraform/aws/iam_user_too_many_access_keys
IAM 사용자의 활성 접근 키 점검 terraform/aws/root_account_has_active_access_keys
흐름 로그가 비활성화된 AWS Global Accelerator terraform/aws/global_accelerator_flow_logs_disabled

관련 문서340

API Gateway 배포 단계의 사용량 계획 연결 점검

API 키별 사용량 관리가 필요하면 배포한 단계를 사용량 계획에 연결하세요.

API Gateway 단계의 사용량 계획 연결 점검

키별 사용량 정책이 필요한 단계를 올바른 계획에 연결하세요.

API Gateway X-Ray 추적 비활성화

API Gateway REST API의 X-Ray 추적이 꺼져 있으면 요청 경로와 지연 원인 분석이 어려울 수 있습니다.

API Gateway 응답 압축 설정 점검

API 응답 특성에 맞게 압축 여부와 최소 크기를 선택하세요.

API Gateway의 Lambda 호출 범위 점검

API Gateway가 Lambda를 호출할 수 있는 범위를 필요한 스테이지, 메서드와 경로로 제한하세요.

API Gateway API Key 사용량 관리 점검

AWS API Gateway 메서드는 필요한 경우 API Key를 요구하도록 설정해야 합니다.

AWS Config 집계 대상 리전 점검

중앙에서 확인해야 하는 리전을 AWS Config 집계에 포함하세요.

AWS Config 변경 감지 알람이 없는 CloudWatch

AWS Config 변경을 CloudWatch 알람으로 모니터링하세요.

AWS Management Console 인증 실패 감지 알람이 없는 CloudWatch

AWS 콘솔 로그인 실패에 대한 알림을 설정하세요.

AWS Organizations 변경 감지 알람 미설정

AWS Organizations 변경을 감지하는 CloudWatch 로그 필터와 알람이 없으면 조직 단위 권한 변경을 늦게 발견할 수 있습니다.

AWS Shield Advanced 적용 필요성 점검

서비스의 DDoS 대응 요구에 맞게 추가 보호를 검토하세요.

AWS 관리형 키로 암호화된 SNS 토픽

SNS의 AWS 관리형 암호화 키가 조직의 키 통제 요구사항에 맞는지 확인하세요.

AWS 관리형 키로 암호화된 Secrets Manager 시크릿

Secrets Manager의 AWS 관리형 키가 조직의 키 관리 요구사항에 맞는지 확인하세요.

API Gateway REST API 인증 구성 점검

보호할 REST API 메서드에 적절한 인증을 연결하고 실제 권한 검사를 확인하세요.

Auto Scaling 그룹 태그 누락

그룹과 새 인스턴스에 필요한 운영 태그를 지정하세요.

시작 구성 사용자 데이터의 Base64 개인 키 점검

Base64로 인코딩해도 개인 키는 비밀로 보호되지 않습니다. EC2 사용자 데이터에서 실제 개인 키를 제거하세요.

CloudFront 콘텐츠 전달 구성 점검

서비스에 필요한 CloudFront 배포와 원본을 구성하세요.

CloudFormation 스택 알림 구성 점검

CloudFormation 스택 이벤트를 운영에 필요한 알림 경로로 전달하고 실패·롤백 알림의 수신을 확인하세요.

CloudFormation 스택 정책 미설정

스택 업데이트로부터 보호할 리소스를 스택 정책으로 지정하세요.

CloudFormation 스택 템플릿 미설정

생성할 스택의 템플릿 본문이나 URL을 지정하세요.

CloudFront의 TLS 보안 정책 점검

CloudFront의 클라이언트 연결에 적절한 최소 TLS 버전을 설정하세요.

CloudTrail 로그 파일 전달 알림 미설정

로그 파일 도착 알림이 필요하면 CloudTrail에 SNS 주제를 연결하세요.

CloudTrail 로그의 KMS 키 설정 점검

CloudTrail 로그의 기본 저장 암호화와 별도 KMS 키 통제를 구분해 구성하세요.

CloudTrail 로그 무결성 검증 자료 미생성

CloudTrail 로그의 변경 여부를 검증할 다이제스트 파일을 생성하세요.

CloudTrail의 리전 및 글로벌 이벤트 범위 점검

감사에 필요한 리전과 글로벌 서비스 이벤트를 Trail에 포함하세요.

CloudTrail 설정 변경 감지 알람이 없는 CloudWatch

CloudTrail 구성 변경과 로깅 중지를 모니터링하세요.

CloudTrail의 CloudWatch Logs 연동 미설정

CloudWatch에서 감사 로그를 분석하려면 CloudTrail 전달을 구성하세요.

CloudWatch Logs 목적지의 과도한 허용 정책

로그 구독 목적지에 필요한 발신 계정과 작업만 허용하세요.

API Gateway 메서드 상세 지표 비활성화

필요한 API 메서드의 상세 CloudWatch 지표를 활성화하세요.

Route 53 공개 DNS 질의 로깅 미설정

필요한 공개 호스팅 영역의 DNS 질의를 기록하세요.

CloudWatch 로그 보존 기간 점검

CloudWatch 로그 보존 기간을 운영·규정 요구에 맞게 정하고 필요한 기록의 손실과 과도한 보관을 방지하세요.

API Gateway CloudWatch 로그 전달 설정 점검

API Gateway 로그의 종류에 맞게 CloudWatch 전달 설정과 보존 기간을 확인하세요.

CodeBuild 프로젝트에 AWS 관리형 키 사용

CodeBuild 빌드 결과물의 키 정책 요구사항에 맞춰 AWS 관리형 키 또는 고객 관리형 키를 선택하세요.

Cognito User Pool MFA 적용 범위 점검

비밀번호 기반 로그인에 필요한 MFA를 적용하고 선택적 설정의 보호 범위를 확인하세요.

DocumentDB 암호화 키 관리 방식 점검

키 관리 요구 사항에 맞는 KMS 키를 선택하세요.

DynamoDB 게이트웨이 엔드포인트 라우팅 연결 점검

애플리케이션 서브넷의 라우팅 테이블을 엔드포인트에 연결하세요.

DynamoDB 시점 복구 비활성화

중요한 테이블의 복구 목표에 맞춰 시점 복구와 실제 복구 절차를 준비하세요.

EC2 EBS 최적화 설정 점검

인스턴스 유형의 기본 동작과 EBS 성능 요구를 함께 확인하세요.

EC2 사용자 데이터의 AWS 자격 증명 점검

EC2 사용자 데이터의 장기 AWS 자격 증명을 제거하고 인스턴스 역할을 통한 임시 자격 증명을 사용하세요.

EC2 메타데이터의 IMDSv1 허용 여부 점검

필요한 메타데이터 접근에는 IMDSv2를 요구하고 실제 적용 상태를 확인하세요.

EC2 인스턴스의 서브넷과 보안 그룹 선택 점검

EC2 네트워크 배치를 명시적으로 구성하세요.

EC2 인스턴스의 기본 VPC 사용 점검

기본 VPC 사용이 워크로드의 네트워크 설계에 맞는지 확인하세요.

EC2 인스턴스에 직접 배포하는 AWS 액세스 키

EC2에 장기 키를 넣는 대신 IAM 역할의 임시 자격 증명을 사용하세요.

ECR 리포지토리 암호화 키 관리 점검

필요한 키 관리 수준에 맞게 ECR 암호화를 구성하세요.

ECR 리포지토리 접근 정책 점검

이미지를 사용할 주체와 작업에 맞게 접근 권한을 제한하세요.

ECR 이미지 취약점 검사 설정 점검

저장된 이미지의 취약점을 검사하고 결과를 처리하세요.

ECS Container Insights 설정 점검

ECS Container Insights를 통해 필요한 운영 지표를 수집하세요.

ECS 서비스의 필요한 태스크 수 점검

서비스의 운영 목적에 맞는 태스크 수와 실제 실행 상태를 확인하세요.

EFS 고객 관리형 KMS 키 점검

EFS의 암호화 키를 조직의 키 관리 요구에 맞게 선택하세요.

EKS 클러스터 제어 플레인 로그 유형 누락

EKS 제어 플레인의 로그 유형을 빠짐없이 구성하세요.