Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

CIS AWS Compute Services v1.0.0

31 controls
30 checks mapped

The Center for Internet Security (CIS) Benchmarks are consensus-based, prescriptive configuration baselines for hardening cloud environments against the most common attack vectors.

Controls assessed

10.1 Ensure you are using VPC Endpoints for source code access1

App Runner needs access to your application source, so it can't be encrypted. Therefore, be sure to secure the connection between your development or deployment environment and App Runner.

2.1.2 Ensure Images (AMI's) are encrypted1

Amazon Machine Images should utilize EBS Encrypted snapshots

2.1.4 Ensure Images (AMI) are not older than 90 days1

Ensure that your AMIs are not older than 90 days.

2.1.5 Ensure Images are not Publicly Available1

EC2 allows you to make an AMI public, sharing it with all AWS accounts.

2.2.1 Ensure EBS volume encryption is enabled1

Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.

2.2.2 Ensure public access to EBS Snapshots is disabled1

To protect your data disable the public mode of EBS snapshots.

2.2.3 Ensure EBS volume snapshots are encrypted1

Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service.

2.2.4 Ensure unused EBS volumes are removed1

Identify any unused Elastic Block Store (EBS) volumes in your AWS account and remove them.

2.3 Ensure Tag Policies are enabled1

Tag policies help you standardize tags on all tagged resources across your organization.

2.4 Ensure an Organizational EC2 Tag Policy has been created1

A tag policy enables you to define tag compliance rules to help you maintain consistency in the tags attached to your organization's resources.

2.6 Ensure detailed monitoring is enable for production EC2 Instances1

Ensure that detailed monitoring is enabled for your Amazon EC2 instances.

2.7 Ensure Default EC2 Security groups are not being used1

When an EC2 instance is launched a specified custom security group should be assigned to the instance.

2.8 Ensure the Use of IMDSv2 is Enforced on All Existing Instances1

Ensure the Instance Metadata Service Version 2 (IMDSv2) method is enabled on all running instances.

2.9 Ensure use of AWS Systems Manager to manage EC2 instances1

An inventory and management of Amazon Elastic Compute Cloud (Amazon EC2) instances is made possible with AWS Systems Manager.

2.10 Ensure unused ENIs are removed1

Identify and delete any unused Amazon AWS Elastic Network Interfaces in order to adhere to best practices and to avoid reaching the service limit. An AWS Elastic Network Interface (ENI) is pronounced unused when is not attached anymore to an EC2 instance.

2.11 Ensure instances stopped for over 90 days are removed1

Enable this rule to help with the baseline configuration of Amazon Elastic Compute Cloud (Amazon EC2) instances by checking whether Amazon EC2 instances have been stopped for more than the allowed number of days, according to your organization's standards.

2.12 Ensure EBS volumes attached to an EC2 instance is marked for deletion upon instance termination1

This rule ensures that Amazon Elastic Block Store volumes that are attached to Amazon Elastic Compute Cloud (Amazon EC2) instances are marked for deletion when an instance is terminated. If an Amazon EBS volume isn't deleted when the instance that it's attached to is terminated, it may violate the concept of least functionality.

2.13 Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data1

User Data can be specified when launching an ec2 instance. Examples include specifying parameters for configuring the instance or including a simple script.

2.14 Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches1

Tags can help with managing, identifying, organizing, searching for, and filtering resources. Additionally, tags can help with security and compliance. Tags can be propagated from an Auto Scaling group to the EC2 instances that it launches.

3.3 Disable SSH and RDP ports for Lightsail instances when not needed1

Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should remove and disable these ports when not is use.

3.4 Ensure SSH is restricted to only IP address that should have this access1

Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should identify which IP address need access.

3.5 Ensure RDP is restricted to only IP address that should have this access1

Any ports enable within Lightsail by default are open and exposed to the world. For SSH and RDP access you should identify which IP address need access.

3.6 Disable IPv6 Networking if not in use within your organization1

Any protocols enable within Lightsail by default that aren't being used should be disabled.

4.1 Ensure AWS Config is enabled for Lambda and serverless1

With AWS Config, you can track configuration changes to the Lambda functions (including deleted functions), runtime environments, tags, handler name, code size, memory allocation, timeout settings, and concurrency settings, along with Lambda IAM execution role, subnet, and security group associations.

4.6 Ensure Lambda functions are not exposed to everyone1

A publicly accessible Amazon Lambda function is open to the public and can be reviewed by anyone. To protect against unauthorized users that are sending requests to invoke these functions they need to be changed so they are not exposed to the public

4.8 Ensure that Code Signing is enabled for Lambda functions1

Ensure that all your Amazon Lambda functions are configured to use the Code Signing feature in order to restrict the deployment of unverified code.

4.11 Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates1

Always using a recent version of the execution environment configured for your Amazon Lambda functions adheres to best practices for the newest software features, the latest security patches and bug fixes, and performance and reliability.

6.1 Ensure Managed Platform updates is configured1

AWS Elastic Beanstalk regularly releases platform updates to provide fixes, software updates, and new features. With managed platform updates, you can configure your environment to automatically upgrade to the latest version of a platform during a scheduled maintenance window.

6.2 Ensure Persistent logs is setup and configured to S31

Elastic Beanstalk can be configured to automatically stream logs to the CloudWatch service.

6.3 Ensure access logs are enabled1

When you enable load balancing, your AWS Elastic Beanstalk environment is equipped with an Elastic Load Balancing load balancer to distribute traffic among the instances in your environment.

6.4 Ensure that HTTPS is enabled on load balancer1

The simplest way to use HTTPS with an Elastic Beanstalk environment is to assign a server certificate to your environment's load balancer.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.