Skip to content

Commit a177316

Browse files
bensoncegithub-actions[bot]
authored andcommitted
Automatic updates to AWS managed Config Rules
1 parent 9512c9f commit a177316

File tree

4 files changed

+757
-6
lines changed

4 files changed

+757
-6
lines changed

files/pack-rules-list.txt

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,8 @@ Operational-Best-Practices-for-NIST-Privacy-Framework
8181
Operational-Best-Practices-for-NYDFS-23-NYCRR-500
8282
Operational-Best-Practices-for-NZISM
8383
Operational-Best-Practices-for-Networking-Services
84+
Operational-Best-Practices-for-PCI-DSS-v4.0-excluding-global-resourcetypes
85+
Operational-Best-Practices-for-PCI-DSS-v4.0-including-global-resourcetypes
8486
Operational-Best-Practices-for-PCI-DSS
8587
Operational-Best-Practices-for-Publicly-Accessible-Resources
8688
Operational-Best-Practices-for-RBI-Basic-Cyber-Security-Framework

files/pack-rules.yaml

Lines changed: 229 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
generated_on: '2024-09-15T00:05:29Z'
1+
generated_on: '2024-12-01T00:05:29Z'
22
packs:
33
AWS-Control-Tower-Detective-Guardrails:
44
- autoscaling-launch-config-public-ip-disabled
@@ -6882,6 +6882,234 @@ packs:
68826882
- waf-regional-rulegroup-not-empty
68836883
- waf-regional-webacl-not-empty
68846884
- wafv2-logging-enabled
6885+
Operational-Best-Practices-for-PCI-DSS-v4.0-excluding-global-resourcetypes:
6886+
- access-keys-rotated
6887+
- acm-certificate-rsa-check
6888+
- acm-pca-root-ca-disabled
6889+
- api-gw-cache-enabled-and-encrypted
6890+
- api-gw-endpoint-type-check
6891+
- api-gw-xray-enabled
6892+
- api-gwv2-access-logs-enabled
6893+
- appsync-associated-with-waf
6894+
- appsync-logging-enabled
6895+
- athena-workgroup-encrypted-at-rest
6896+
- aurora-resources-protected-by-backup-plan
6897+
- autoscaling-launchconfig-requires-imdsv2
6898+
- backup-recovery-point-manual-deletion-disabled
6899+
- cloudtrail-enabled
6900+
- cloudtrail-security-trail-enabled
6901+
- cloudwatch-alarm-action-check
6902+
- cloudwatch-alarm-resource-check
6903+
- cloudwatch-alarm-settings-check
6904+
- codebuild-project-artifact-encryption
6905+
- codebuild-project-envvar-awscred-check
6906+
- codebuild-project-s3-logs-encrypted
6907+
- codebuild-project-source-repo-url-check
6908+
- codedeploy-lambda-allatonce-traffic-shift-disabled
6909+
- cw-loggroup-retention-period-check
6910+
- db-instance-backup-enabled
6911+
- dms-endpoint-ssl-configured
6912+
- dms-redis-tls-enabled
6913+
- dynamodb-in-backup-plan
6914+
- dynamodb-pitr-enabled
6915+
- dynamodb-resources-protected-by-backup-plan
6916+
- dynamodb-table-encrypted-kms
6917+
- ebs-in-backup-plan
6918+
- ebs-resources-protected-by-backup-plan
6919+
- ec2-client-vpn-not-authorize-all
6920+
- ec2-imdsv2-check
6921+
- ec2-instance-detailed-monitoring-enabled
6922+
- ec2-instance-profile-attached
6923+
- ec2-launch-template-public-ip-disabled
6924+
- ec2-no-amazon-key-pair
6925+
- ec2-resources-protected-by-backup-plan
6926+
- ec2-volume-inuse-check
6927+
- ecr-private-lifecycle-policy-configured
6928+
- ecs-task-definition-log-configuration
6929+
- ecs-task-definition-pid-mode-check
6930+
- efs-resources-protected-by-backup-plan
6931+
- eks-cluster-logging-enabled
6932+
- eks-cluster-oldest-supported-version
6933+
- eks-cluster-secrets-encrypted
6934+
- eks-endpoint-no-public-access
6935+
- eks-secrets-encrypted
6936+
- elastic-beanstalk-logs-to-cloudwatch
6937+
- elasticache-redis-cluster-automatic-backup-check
6938+
- elb-acm-certificate-required
6939+
- emr-block-public-access
6940+
- fsx-resources-protected-by-backup-plan
6941+
- iam-policy-in-use
6942+
- internet-gateway-authorized-vpc-only
6943+
- kinesis-stream-encrypted
6944+
- lambda-function-settings-check
6945+
- macie-auto-sensitive-data-discovery-check
6946+
- macie-status-check
6947+
- mq-cloudwatch-audit-log-enabled
6948+
- mq-cloudwatch-audit-logging-enabled
6949+
- msk-in-cluster-node-require-tls
6950+
- multi-region-cloudtrail-enabled
6951+
- nacl-no-unrestricted-ssh-rdp
6952+
- neptune-cluster-backup-retention-check
6953+
- neptune-cluster-cloudwatch-log-export-enabled
6954+
- neptune-cluster-encrypted
6955+
- neptune-cluster-iam-database-authentication
6956+
- neptune-cluster-snapshot-encrypted
6957+
- neptune-cluster-snapshot-public-prohibited
6958+
- netfw-logging-enabled
6959+
- netfw-policy-default-action-fragment-packets
6960+
- netfw-policy-default-action-full-packets
6961+
- rds-in-backup-plan
6962+
- redshift-backup-enabled
6963+
- redshift-cluster-kms-enabled
6964+
- redshift-enhanced-vpc-routing-enabled
6965+
- restricted-ssh
6966+
- s3-access-point-public-access-blocks
6967+
- s3-account-level-public-access-blocks
6968+
- s3-bucket-blacklisted-actions-prohibited
6969+
- s3-bucket-default-lock-enabled
6970+
- s3-bucket-mfa-delete-enabled
6971+
- s3-bucket-policy-not-more-permissive
6972+
- s3-bucket-versioning-enabled
6973+
- s3-resources-protected-by-backup-plan
6974+
- secretsmanager-scheduled-rotation-success-check
6975+
- secretsmanager-secret-periodic-rotation
6976+
- secretsmanager-secret-unused
6977+
- security-account-information-provided
6978+
- service-catalog-shared-within-organization
6979+
- sns-topic-message-delivery-notification-enabled
6980+
- step-functions-state-machine-logging-enabled
6981+
- transfer-family-server-no-ftp
6982+
- wafv2-rulegroup-logging-enabled
6983+
- wafv2-rulegroup-not-empty
6984+
- wafv2-webacl-not-empty
6985+
Operational-Best-Practices-for-PCI-DSS-v4.0-including-global-resourcetypes:
6986+
- access-keys-rotated
6987+
- acm-certificate-rsa-check
6988+
- acm-pca-root-ca-disabled
6989+
- api-gw-cache-enabled-and-encrypted
6990+
- api-gw-endpoint-type-check
6991+
- api-gw-xray-enabled
6992+
- api-gwv2-access-logs-enabled
6993+
- appsync-associated-with-waf
6994+
- appsync-logging-enabled
6995+
- athena-workgroup-encrypted-at-rest
6996+
- aurora-resources-protected-by-backup-plan
6997+
- autoscaling-launchconfig-requires-imdsv2
6998+
- backup-recovery-point-manual-deletion-disabled
6999+
- cloudformation-stack-notification-check
7000+
- cloudfront-accesslogs-enabled
7001+
- cloudfront-associated-with-waf
7002+
- cloudfront-custom-ssl-certificate
7003+
- cloudfront-no-deprecated-ssl-protocols
7004+
- cloudfront-origin-access-identity-enabled
7005+
- cloudfront-s3-origin-access-control-enabled
7006+
- cloudfront-security-policy-check
7007+
- cloudfront-sni-enabled
7008+
- cloudfront-traffic-to-origin-encrypted
7009+
- cloudfront-viewer-policy-https
7010+
- cloudtrail-enabled
7011+
- cloudtrail-security-trail-enabled
7012+
- cloudwatch-alarm-action-check
7013+
- cloudwatch-alarm-resource-check
7014+
- cloudwatch-alarm-settings-check
7015+
- codebuild-project-artifact-encryption
7016+
- codebuild-project-envvar-awscred-check
7017+
- codebuild-project-s3-logs-encrypted
7018+
- codebuild-project-source-repo-url-check
7019+
- codedeploy-lambda-allatonce-traffic-shift-disabled
7020+
- codepipeline-deployment-count-check
7021+
- cw-loggroup-retention-period-check
7022+
- dax-encryption-enabled
7023+
- dax-tls-endpoint-encryption
7024+
- db-instance-backup-enabled
7025+
- dms-endpoint-ssl-configured
7026+
- dms-redis-tls-enabled
7027+
- docdb-cluster-encrypted
7028+
- docdb-cluster-snapshot-public-prohibited
7029+
- dynamodb-in-backup-plan
7030+
- dynamodb-pitr-enabled
7031+
- dynamodb-resources-protected-by-backup-plan
7032+
- dynamodb-table-encrypted-kms
7033+
- dynamodb-table-encryption-enabled
7034+
- ebs-in-backup-plan
7035+
- ebs-resources-protected-by-backup-plan
7036+
- ec2-client-vpn-not-authorize-all
7037+
- ec2-imdsv2-check
7038+
- ec2-instance-detailed-monitoring-enabled
7039+
- ec2-instance-profile-attached
7040+
- ec2-launch-template-public-ip-disabled
7041+
- ec2-no-amazon-key-pair
7042+
- ec2-resources-protected-by-backup-plan
7043+
- ec2-transit-gateway-auto-vpc-attach-disabled
7044+
- ec2-volume-inuse-check
7045+
- ecr-private-lifecycle-policy-configured
7046+
- ecs-task-definition-log-configuration
7047+
- ecs-task-definition-pid-mode-check
7048+
- efs-in-backup-plan
7049+
- efs-resources-protected-by-backup-plan
7050+
- eks-cluster-logging-enabled
7051+
- eks-cluster-oldest-supported-version
7052+
- eks-cluster-secrets-encrypted
7053+
- eks-endpoint-no-public-access
7054+
- eks-secrets-encrypted
7055+
- elastic-beanstalk-logs-to-cloudwatch
7056+
- elasticache-redis-cluster-automatic-backup-check
7057+
- elb-acm-certificate-required
7058+
- emr-block-public-access
7059+
- fsx-resources-protected-by-backup-plan
7060+
- iam-policy-in-use
7061+
- internet-gateway-authorized-vpc-only
7062+
- kinesis-stream-encrypted
7063+
- lambda-function-settings-check
7064+
- macie-auto-sensitive-data-discovery-check
7065+
- macie-status-check
7066+
- mq-cloudwatch-audit-log-enabled
7067+
- mq-cloudwatch-audit-logging-enabled
7068+
- msk-in-cluster-node-require-tls
7069+
- multi-region-cloudtrail-enabled
7070+
- nacl-no-unrestricted-ssh-rdp
7071+
- neptune-cluster-backup-retention-check
7072+
- neptune-cluster-cloudwatch-log-export-enabled
7073+
- neptune-cluster-encrypted
7074+
- neptune-cluster-iam-database-authentication
7075+
- neptune-cluster-snapshot-encrypted
7076+
- neptune-cluster-snapshot-public-prohibited
7077+
- netfw-logging-enabled
7078+
- netfw-policy-default-action-fragment-packets
7079+
- netfw-policy-default-action-full-packets
7080+
- rds-cluster-iam-authentication-enabled
7081+
- rds-db-security-group-not-allowed
7082+
- rds-in-backup-plan
7083+
- rds-instance-iam-authentication-enabled
7084+
- rds-resources-protected-by-backup-plan
7085+
- redshift-backup-enabled
7086+
- redshift-cluster-kms-enabled
7087+
- redshift-enhanced-vpc-routing-enabled
7088+
- restricted-ssh
7089+
- s3-access-point-public-access-blocks
7090+
- s3-account-level-public-access-blocks
7091+
- s3-bucket-blacklisted-actions-prohibited
7092+
- s3-bucket-default-lock-enabled
7093+
- s3-bucket-mfa-delete-enabled
7094+
- s3-bucket-policy-not-more-permissive
7095+
- s3-bucket-versioning-enabled
7096+
- s3-resources-protected-by-backup-plan
7097+
- secretsmanager-scheduled-rotation-success-check
7098+
- secretsmanager-secret-periodic-rotation
7099+
- secretsmanager-secret-unused
7100+
- security-account-information-provided
7101+
- service-catalog-shared-within-organization
7102+
- shield-drt-access
7103+
- sns-topic-message-delivery-notification-enabled
7104+
- step-functions-state-machine-logging-enabled
7105+
- transfer-family-server-no-ftp
7106+
- waf-classic-logging-enabled
7107+
- waf-global-rule-not-empty
7108+
- waf-global-rulegroup-not-empty
7109+
- waf-global-webacl-not-empty
7110+
- wafv2-rulegroup-logging-enabled
7111+
- wafv2-rulegroup-not-empty
7112+
- wafv2-webacl-not-empty
68857113
Operational-Best-Practices-for-Publicly-Accessible-Resources:
68867114
- autoscaling-launch-config-public-ip-disabled
68877115
- dms-replication-not-public

0 commit comments

Comments
 (0)