Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
AWS logo

Compute Best Practices

30 controls
9 services covered

Reviews EC2 and Auto Scaling posture — IMDSv2, Systems Manager management and patch compliance, launch templates, user data, instance profiles, monitoring, public administration paths, and operational hygiene.

What we check

EC2 Instances8
  • EC2 Instance Metadata Service v2 Enforced
  • EC2 Instances in a VPC (No Classic EC2)
  • EC2 Instance not launched with Key Pair
  • EC2 Instances Older than 1 Year
  • Ensure Restricted Remote Administration Ports (SSH/RDP) Access to EC2 Instances
  • EC2 Detailed Monitoring Enabled
  • EC2 Instances Managed by Systems Manager (SSM)
  • EC2 Instances Compliant with SSM Patching Requirements
EC2 Instance Roles8
  • IAM Instance Profile is Attached to EC2 Instance
  • EC2 instance IAM should not allow pass role and lambda invoke function access
  • EC2 instance IAM role should not allow management level access
  • EC2 instance IAM role should not allow data destruction access
  • EC2 instance IAM role should not allow cloud log tampering access
  • EC2 instance IAM role should not allow database management write access
  • EC2 instance IAM role should not allow destruction KMS access
  • EC2 instance IAM role should not allow destruction RDS access
Auto Scaling Launch Configurations4
  • Auto Scaling Launch Configuration Metadata Response Hop Limit is 1
  • Auto Scaling Launch Configuration has IMDSv2 Enforced
  • Auto Scaling Launch Configuration Instances Do Not Assign Public IPs
  • Auto Scaling Launch Config User Data Has No Sensitive Data
Auto Scaling Groups3
  • EC2 Auto Scaling Groups Should Use EC2 Launch Templates
  • Auto Scaling Group Has No Suspended Processes
  • Auto Scaling Group Propagates Tags to EC2 Instances
EC2 Network Interfaces2
  • EC2 network interfaces should have source/destination checking enabled
  • Ensure unused ENIs are removed
Systems Manager Automation2
  • EC2 Instance Compliant SSM Association Status
  • Systems Manager (SSM) Agent Auto-Update Enabled
EBS Volumes1
  • EC2 Instance EBS Optimization Enabled
EC2 AMIs1
  • Ensure Images (AMI) are not older than 90 days
EC2 User Data1
  • EC2 instances user data should not have secrets

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.