Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
AWS logo

Data Protection Best Practices

30 controls
17 services covered

Covers sensitive-data protection — Macie discovery, S3 public-access guardrails, KMS key health, Secrets Manager, encrypted SSM parameters, secrets in EC2 user data and CodeBuild, CloudTrail data events, and data-access IAM risks.

What we check

Secrets Manager Secrets5
  • Secrets Manager or Encrypted SSM Parameters Present
  • Secrets Manager Secrets Automatic Rotation is Enabled
  • Secret Resource Policy Configured
  • Secrets Manager Secrets Use Custom KMS Key
  • Secrets Manager Secrets Are Rotated Per Schedule
Macie Organization Settings3
  • Macie Auto-Enroll Accounts in the Organization
  • Macie Findings are Aggregated to a Dedicated Account
  • Macie Management is Delegated in the Organization
IAM Policies3
  • No IAM Principals with Unrestricted S3 Access
  • No IAM Principals with Unrestricted S3 Read Access
  • No IAM Principals with Access to Get All Secrets
IAM Identity Center Permission Sets3
  • No SSO Permission Set with Unrestricted S3 Access
  • No SSO Permission Set with Unrestricted S3 Read Access
  • No SSO Permission Set with Access to Get All Secrets
S3 Public Access Controls2
  • S3 Block Public Access is Enabled (Account-Level)
  • S3 general purpose buckets should block public access
KMS Keys2
  • Ensure that KMS Key Rotation is Enabled
  • KMS Keys Not Pending Deletion
Systems Manager Automation2
  • SSM Parameters Are Encrypted
  • SSM Automation should have CloudWatch logging enabled
Macie Settings1
  • Amazon Macie Enabled
Macie Findings1
  • Amazon Macie Active Findings
Macie S3 Bucket Monitoring1
  • Amazon S3 Buckets Are Protected by Macie
S3 Encryption1
  • S3 Bucket Key is Enabled
EMR Security Configurations1
  • EMR Security Configuration Encryption at Rest Enabled
Auto Scaling Launch Configurations1
  • Auto Scaling Launch Config User Data Has No Sensitive Data
CodeBuild Project Environments1
  • CodeBuild Environment Variables Do Not Contain Secrets
CloudFormation Stacks1
  • CloudFormation Stack Outputs Do Not Contain Secrets
CloudTrail S3 Log Buckets1
  • CloudTrail S3 Bucket Not Publicly Accessible
EC2 User Data1
  • EC2 instances user data should not have secrets

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.