|
1 | | -generated_on: '2024-09-15T00:05:29Z' |
| 1 | +generated_on: '2024-12-01T00:05:29Z' |
2 | 2 | packs: |
3 | 3 | AWS-Control-Tower-Detective-Guardrails: |
4 | 4 | - autoscaling-launch-config-public-ip-disabled |
@@ -6882,6 +6882,234 @@ packs: |
6882 | 6882 | - waf-regional-rulegroup-not-empty |
6883 | 6883 | - waf-regional-webacl-not-empty |
6884 | 6884 | - wafv2-logging-enabled |
| 6885 | + Operational-Best-Practices-for-PCI-DSS-v4.0-excluding-global-resourcetypes: |
| 6886 | + - access-keys-rotated |
| 6887 | + - acm-certificate-rsa-check |
| 6888 | + - acm-pca-root-ca-disabled |
| 6889 | + - api-gw-cache-enabled-and-encrypted |
| 6890 | + - api-gw-endpoint-type-check |
| 6891 | + - api-gw-xray-enabled |
| 6892 | + - api-gwv2-access-logs-enabled |
| 6893 | + - appsync-associated-with-waf |
| 6894 | + - appsync-logging-enabled |
| 6895 | + - athena-workgroup-encrypted-at-rest |
| 6896 | + - aurora-resources-protected-by-backup-plan |
| 6897 | + - autoscaling-launchconfig-requires-imdsv2 |
| 6898 | + - backup-recovery-point-manual-deletion-disabled |
| 6899 | + - cloudtrail-enabled |
| 6900 | + - cloudtrail-security-trail-enabled |
| 6901 | + - cloudwatch-alarm-action-check |
| 6902 | + - cloudwatch-alarm-resource-check |
| 6903 | + - cloudwatch-alarm-settings-check |
| 6904 | + - codebuild-project-artifact-encryption |
| 6905 | + - codebuild-project-envvar-awscred-check |
| 6906 | + - codebuild-project-s3-logs-encrypted |
| 6907 | + - codebuild-project-source-repo-url-check |
| 6908 | + - codedeploy-lambda-allatonce-traffic-shift-disabled |
| 6909 | + - cw-loggroup-retention-period-check |
| 6910 | + - db-instance-backup-enabled |
| 6911 | + - dms-endpoint-ssl-configured |
| 6912 | + - dms-redis-tls-enabled |
| 6913 | + - dynamodb-in-backup-plan |
| 6914 | + - dynamodb-pitr-enabled |
| 6915 | + - dynamodb-resources-protected-by-backup-plan |
| 6916 | + - dynamodb-table-encrypted-kms |
| 6917 | + - ebs-in-backup-plan |
| 6918 | + - ebs-resources-protected-by-backup-plan |
| 6919 | + - ec2-client-vpn-not-authorize-all |
| 6920 | + - ec2-imdsv2-check |
| 6921 | + - ec2-instance-detailed-monitoring-enabled |
| 6922 | + - ec2-instance-profile-attached |
| 6923 | + - ec2-launch-template-public-ip-disabled |
| 6924 | + - ec2-no-amazon-key-pair |
| 6925 | + - ec2-resources-protected-by-backup-plan |
| 6926 | + - ec2-volume-inuse-check |
| 6927 | + - ecr-private-lifecycle-policy-configured |
| 6928 | + - ecs-task-definition-log-configuration |
| 6929 | + - ecs-task-definition-pid-mode-check |
| 6930 | + - efs-resources-protected-by-backup-plan |
| 6931 | + - eks-cluster-logging-enabled |
| 6932 | + - eks-cluster-oldest-supported-version |
| 6933 | + - eks-cluster-secrets-encrypted |
| 6934 | + - eks-endpoint-no-public-access |
| 6935 | + - eks-secrets-encrypted |
| 6936 | + - elastic-beanstalk-logs-to-cloudwatch |
| 6937 | + - elasticache-redis-cluster-automatic-backup-check |
| 6938 | + - elb-acm-certificate-required |
| 6939 | + - emr-block-public-access |
| 6940 | + - fsx-resources-protected-by-backup-plan |
| 6941 | + - iam-policy-in-use |
| 6942 | + - internet-gateway-authorized-vpc-only |
| 6943 | + - kinesis-stream-encrypted |
| 6944 | + - lambda-function-settings-check |
| 6945 | + - macie-auto-sensitive-data-discovery-check |
| 6946 | + - macie-status-check |
| 6947 | + - mq-cloudwatch-audit-log-enabled |
| 6948 | + - mq-cloudwatch-audit-logging-enabled |
| 6949 | + - msk-in-cluster-node-require-tls |
| 6950 | + - multi-region-cloudtrail-enabled |
| 6951 | + - nacl-no-unrestricted-ssh-rdp |
| 6952 | + - neptune-cluster-backup-retention-check |
| 6953 | + - neptune-cluster-cloudwatch-log-export-enabled |
| 6954 | + - neptune-cluster-encrypted |
| 6955 | + - neptune-cluster-iam-database-authentication |
| 6956 | + - neptune-cluster-snapshot-encrypted |
| 6957 | + - neptune-cluster-snapshot-public-prohibited |
| 6958 | + - netfw-logging-enabled |
| 6959 | + - netfw-policy-default-action-fragment-packets |
| 6960 | + - netfw-policy-default-action-full-packets |
| 6961 | + - rds-in-backup-plan |
| 6962 | + - redshift-backup-enabled |
| 6963 | + - redshift-cluster-kms-enabled |
| 6964 | + - redshift-enhanced-vpc-routing-enabled |
| 6965 | + - restricted-ssh |
| 6966 | + - s3-access-point-public-access-blocks |
| 6967 | + - s3-account-level-public-access-blocks |
| 6968 | + - s3-bucket-blacklisted-actions-prohibited |
| 6969 | + - s3-bucket-default-lock-enabled |
| 6970 | + - s3-bucket-mfa-delete-enabled |
| 6971 | + - s3-bucket-policy-not-more-permissive |
| 6972 | + - s3-bucket-versioning-enabled |
| 6973 | + - s3-resources-protected-by-backup-plan |
| 6974 | + - secretsmanager-scheduled-rotation-success-check |
| 6975 | + - secretsmanager-secret-periodic-rotation |
| 6976 | + - secretsmanager-secret-unused |
| 6977 | + - security-account-information-provided |
| 6978 | + - service-catalog-shared-within-organization |
| 6979 | + - sns-topic-message-delivery-notification-enabled |
| 6980 | + - step-functions-state-machine-logging-enabled |
| 6981 | + - transfer-family-server-no-ftp |
| 6982 | + - wafv2-rulegroup-logging-enabled |
| 6983 | + - wafv2-rulegroup-not-empty |
| 6984 | + - wafv2-webacl-not-empty |
| 6985 | + Operational-Best-Practices-for-PCI-DSS-v4.0-including-global-resourcetypes: |
| 6986 | + - access-keys-rotated |
| 6987 | + - acm-certificate-rsa-check |
| 6988 | + - acm-pca-root-ca-disabled |
| 6989 | + - api-gw-cache-enabled-and-encrypted |
| 6990 | + - api-gw-endpoint-type-check |
| 6991 | + - api-gw-xray-enabled |
| 6992 | + - api-gwv2-access-logs-enabled |
| 6993 | + - appsync-associated-with-waf |
| 6994 | + - appsync-logging-enabled |
| 6995 | + - athena-workgroup-encrypted-at-rest |
| 6996 | + - aurora-resources-protected-by-backup-plan |
| 6997 | + - autoscaling-launchconfig-requires-imdsv2 |
| 6998 | + - backup-recovery-point-manual-deletion-disabled |
| 6999 | + - cloudformation-stack-notification-check |
| 7000 | + - cloudfront-accesslogs-enabled |
| 7001 | + - cloudfront-associated-with-waf |
| 7002 | + - cloudfront-custom-ssl-certificate |
| 7003 | + - cloudfront-no-deprecated-ssl-protocols |
| 7004 | + - cloudfront-origin-access-identity-enabled |
| 7005 | + - cloudfront-s3-origin-access-control-enabled |
| 7006 | + - cloudfront-security-policy-check |
| 7007 | + - cloudfront-sni-enabled |
| 7008 | + - cloudfront-traffic-to-origin-encrypted |
| 7009 | + - cloudfront-viewer-policy-https |
| 7010 | + - cloudtrail-enabled |
| 7011 | + - cloudtrail-security-trail-enabled |
| 7012 | + - cloudwatch-alarm-action-check |
| 7013 | + - cloudwatch-alarm-resource-check |
| 7014 | + - cloudwatch-alarm-settings-check |
| 7015 | + - codebuild-project-artifact-encryption |
| 7016 | + - codebuild-project-envvar-awscred-check |
| 7017 | + - codebuild-project-s3-logs-encrypted |
| 7018 | + - codebuild-project-source-repo-url-check |
| 7019 | + - codedeploy-lambda-allatonce-traffic-shift-disabled |
| 7020 | + - codepipeline-deployment-count-check |
| 7021 | + - cw-loggroup-retention-period-check |
| 7022 | + - dax-encryption-enabled |
| 7023 | + - dax-tls-endpoint-encryption |
| 7024 | + - db-instance-backup-enabled |
| 7025 | + - dms-endpoint-ssl-configured |
| 7026 | + - dms-redis-tls-enabled |
| 7027 | + - docdb-cluster-encrypted |
| 7028 | + - docdb-cluster-snapshot-public-prohibited |
| 7029 | + - dynamodb-in-backup-plan |
| 7030 | + - dynamodb-pitr-enabled |
| 7031 | + - dynamodb-resources-protected-by-backup-plan |
| 7032 | + - dynamodb-table-encrypted-kms |
| 7033 | + - dynamodb-table-encryption-enabled |
| 7034 | + - ebs-in-backup-plan |
| 7035 | + - ebs-resources-protected-by-backup-plan |
| 7036 | + - ec2-client-vpn-not-authorize-all |
| 7037 | + - ec2-imdsv2-check |
| 7038 | + - ec2-instance-detailed-monitoring-enabled |
| 7039 | + - ec2-instance-profile-attached |
| 7040 | + - ec2-launch-template-public-ip-disabled |
| 7041 | + - ec2-no-amazon-key-pair |
| 7042 | + - ec2-resources-protected-by-backup-plan |
| 7043 | + - ec2-transit-gateway-auto-vpc-attach-disabled |
| 7044 | + - ec2-volume-inuse-check |
| 7045 | + - ecr-private-lifecycle-policy-configured |
| 7046 | + - ecs-task-definition-log-configuration |
| 7047 | + - ecs-task-definition-pid-mode-check |
| 7048 | + - efs-in-backup-plan |
| 7049 | + - efs-resources-protected-by-backup-plan |
| 7050 | + - eks-cluster-logging-enabled |
| 7051 | + - eks-cluster-oldest-supported-version |
| 7052 | + - eks-cluster-secrets-encrypted |
| 7053 | + - eks-endpoint-no-public-access |
| 7054 | + - eks-secrets-encrypted |
| 7055 | + - elastic-beanstalk-logs-to-cloudwatch |
| 7056 | + - elasticache-redis-cluster-automatic-backup-check |
| 7057 | + - elb-acm-certificate-required |
| 7058 | + - emr-block-public-access |
| 7059 | + - fsx-resources-protected-by-backup-plan |
| 7060 | + - iam-policy-in-use |
| 7061 | + - internet-gateway-authorized-vpc-only |
| 7062 | + - kinesis-stream-encrypted |
| 7063 | + - lambda-function-settings-check |
| 7064 | + - macie-auto-sensitive-data-discovery-check |
| 7065 | + - macie-status-check |
| 7066 | + - mq-cloudwatch-audit-log-enabled |
| 7067 | + - mq-cloudwatch-audit-logging-enabled |
| 7068 | + - msk-in-cluster-node-require-tls |
| 7069 | + - multi-region-cloudtrail-enabled |
| 7070 | + - nacl-no-unrestricted-ssh-rdp |
| 7071 | + - neptune-cluster-backup-retention-check |
| 7072 | + - neptune-cluster-cloudwatch-log-export-enabled |
| 7073 | + - neptune-cluster-encrypted |
| 7074 | + - neptune-cluster-iam-database-authentication |
| 7075 | + - neptune-cluster-snapshot-encrypted |
| 7076 | + - neptune-cluster-snapshot-public-prohibited |
| 7077 | + - netfw-logging-enabled |
| 7078 | + - netfw-policy-default-action-fragment-packets |
| 7079 | + - netfw-policy-default-action-full-packets |
| 7080 | + - rds-cluster-iam-authentication-enabled |
| 7081 | + - rds-db-security-group-not-allowed |
| 7082 | + - rds-in-backup-plan |
| 7083 | + - rds-instance-iam-authentication-enabled |
| 7084 | + - rds-resources-protected-by-backup-plan |
| 7085 | + - redshift-backup-enabled |
| 7086 | + - redshift-cluster-kms-enabled |
| 7087 | + - redshift-enhanced-vpc-routing-enabled |
| 7088 | + - restricted-ssh |
| 7089 | + - s3-access-point-public-access-blocks |
| 7090 | + - s3-account-level-public-access-blocks |
| 7091 | + - s3-bucket-blacklisted-actions-prohibited |
| 7092 | + - s3-bucket-default-lock-enabled |
| 7093 | + - s3-bucket-mfa-delete-enabled |
| 7094 | + - s3-bucket-policy-not-more-permissive |
| 7095 | + - s3-bucket-versioning-enabled |
| 7096 | + - s3-resources-protected-by-backup-plan |
| 7097 | + - secretsmanager-scheduled-rotation-success-check |
| 7098 | + - secretsmanager-secret-periodic-rotation |
| 7099 | + - secretsmanager-secret-unused |
| 7100 | + - security-account-information-provided |
| 7101 | + - service-catalog-shared-within-organization |
| 7102 | + - shield-drt-access |
| 7103 | + - sns-topic-message-delivery-notification-enabled |
| 7104 | + - step-functions-state-machine-logging-enabled |
| 7105 | + - transfer-family-server-no-ftp |
| 7106 | + - waf-classic-logging-enabled |
| 7107 | + - waf-global-rule-not-empty |
| 7108 | + - waf-global-rulegroup-not-empty |
| 7109 | + - waf-global-webacl-not-empty |
| 7110 | + - wafv2-rulegroup-logging-enabled |
| 7111 | + - wafv2-rulegroup-not-empty |
| 7112 | + - wafv2-webacl-not-empty |
6885 | 7113 | Operational-Best-Practices-for-Publicly-Accessible-Resources: |
6886 | 7114 | - autoscaling-launch-config-public-ip-disabled |
6887 | 7115 | - dms-replication-not-public |
|
0 commit comments