| SEC01 | BP01 | Compliant | - [hasOrganization]
| |
| SEC01 | BP02 | Need Attention | - [rootMfaActive] - Enable MFA on root user
- [hasAlternateContact] - Configure AWS account contacts
- [rootHasAccessKey]
- [rootConsoleLogin30days]
- [passwordPolicy]
- [enableGuardDuty]
| AWS MFA IAM Best Practices Alternate Contact |
| SEC01 | BP03 | Need Attention | - [mfaActive]
- [passwordPolicyWeak]
- [passwordLastChange90] - Rotate password
- [hasAccessKeyNoRotate30days]
| Managing IAM Password |
| SEC01 | BP04 | Compliant | - [enableGuardDuty]
| |
| SEC01 | BP05 | Not available | | |
| SEC01 | BP06 | Not available | | |
| SEC01 | BP07 | Not available | | |
| SEC01 | BP08 | Not available | | |
| SEC02 | BP01 | Need Attention | - [mfaActive]
- [passwordPolicyWeak]
- [passwordLastChange90] - Rotate password
- [hasAccessKeyNoRotate30days]
| Managing IAM Password |
| SEC02 | BP02 | Compliant | - [EC2IamProfile]
| |
| SEC02 | BP03 | Not available | | |
| SEC02 | BP04 | Compliant | - [hasExternalIdentityProvider]
| |
| SEC02 | BP05 | Need Attention | - [passwordLastChange90] - Rotate password
- [hasAccessKeyNoRotate30days]
- [eksClusterRoleLeastPrivilege]
- [InlinePolicyFullAccessOneServ] - Limit access in policy
- [GLOBAL]Role::AWSReservedSSO_YoPayment-AWS-Data-Pgw-Dev_5af8cd0c694d6669, Role::AWSReservedSSO_YoPayment-AWS-Developer-Pgw-Dev_c207ab9d1e5199f5, Role::AWSReservedSSO_YoPayment-AWS-Platform-Pgw-Dev_c9b162f22c1c139b, Role::YoPayment-AWS-Terraform-Pgw-Dev
- [InlinePolicyFullAdminAccess]
- [FullAdminAccess] - Limit permissions.
- [GLOBAL]Role::aws-controltower-AdministratorExecutionRole, Role::AWSControlTowerExecution, Role::AWSReservedSSO_AWSAdministratorAccess_6ad2f92126b0c1d0, Role::AWSReservedSSO_YoPayment-AWS-Admin-Pgw-Dev_999b53209cafbc21, Role::stacksets-exec-bb8cf4473e8495ef76fab8d8a00a5618
- [lambdaRoleReused]
- [EC2IamProfile]
| Managing IAM Password AWS Docs AWS Docs Organization GuardRail Blog |
| SEC02 | BP06 | Need Attention | - [userNotUsingGroup] - Place IAM user within User Group
- [GLOBAL]User::pgw-cassandra-user
- [groupEmptyUsers]
| IAM Group |
| SEC03 | BP01 | Not available | | |
| SEC03 | BP02 | Need Attention | - [eksClusterRoleLeastPrivilege]
- [InlinePolicyFullAccessOneServ] - Limit access in policy
- [GLOBAL]Role::AWSReservedSSO_YoPayment-AWS-Data-Pgw-Dev_5af8cd0c694d6669, Role::AWSReservedSSO_YoPayment-AWS-Developer-Pgw-Dev_c207ab9d1e5199f5, Role::AWSReservedSSO_YoPayment-AWS-Platform-Pgw-Dev_c9b162f22c1c139b, Role::YoPayment-AWS-Terraform-Pgw-Dev
- [InlinePolicyFullAdminAccess]
- [FullAdminAccess] - Limit permissions.
- [GLOBAL]Role::aws-controltower-AdministratorExecutionRole, Role::AWSControlTowerExecution, Role::AWSReservedSSO_AWSAdministratorAccess_6ad2f92126b0c1d0, Role::AWSReservedSSO_YoPayment-AWS-Admin-Pgw-Dev_999b53209cafbc21, Role::stacksets-exec-bb8cf4473e8495ef76fab8d8a00a5618
- [lambdaRoleReused]
- [EC2IamProfile]
| AWS Docs AWS Docs Organization GuardRail Blog |
| SEC03 | BP03 | Not available | | |
| SEC03 | BP04 | Need Attention | - [groupEmptyUsers]
- [userNoActivity90days] - Inactive user
- [GLOBAL]User::yopayment-dev-ses-user
- [HasDataEventsCaptured]
| IAM Credential Reports Rotate Keys |
| SEC03 | BP05 | Not available | | |
| SEC03 | BP06 | Need Attention | - [userNoActivity90days] - Inactive user
- [GLOBAL]User::yopayment-dev-ses-user
| IAM Credential Reports Rotate Keys |
| SEC03 | BP07 | Compliant | - [PubliclyAccessible]
- [S3AccountPublicAccessBlock]
| |
| SEC03 | BP08 | Compliant | - [hasOrganization]
| |
| SEC03 | BP09 | Not available | | |
| SEC04 | BP01 | Need Attention | - [NeedToEnableCloudTrail]
- [HasOneMultiRegionTrail]
- [EnableTrailS3BucketLifecycle]
- [HasInsightSelectors] - Enable Insight Selectors
- [ap-southeast-1]Cloudtrail::SWOCloudTrail-Organizational, Cloudtrail::aws-controltower-BaselineCloudTrail
- [enableGuardDuty]
| Insight events |
| SEC04 | BP02 | Not available | | |
| SEC04 | BP03 | Not available | | |
| SEC04 | BP04 | Not available | | |
| SEC05 | BP01 | Need Attention | - [cloudfront] - Need at least 1 cloudfront
| |
| SEC05 | BP02 | Need Attention | - [SGSensitivePortOpenToAll]
- [SGAllTCPOpen]
- [SGAllUDPOpen]
- [SGDefaultInUsed]
- [SGEncryptionInTransit] - Encryption in Transit
- [ap-southeast-1]SG::sg-0251261a4780396ef, SG::sg-0af4192d63016f4c6, SG::sg-084f2463febd93807
- [us-east-1]SG::sg-03ec10c6bdf83dac6
- [ELBListenerInsecure] - Insecure Listener
- [ap-southeast-1]ELB::pgw-dev-alb, ELB::pay1-wallet-dev-alb
- [PubliclyAccessible]
| Data protection in Amazon EC2 ALB Configuration Guide |
| SEC05 | BP03 | Not available | | |
| SEC05 | BP04 | Not available | | |
| SEC06 | BP01 | Not available | | |
| SEC06 | BP02 | Not available | | |
| SEC06 | BP03 | Need Attention | - [Has 3 actives lambda]
- [Has 3 actives rds]
- [ecs] - Need at least 1 ecs
- [eks] - Need at least 1 eks
- [Has 2 actives dynamodb]
- [Has 4 actives elasticache]
|
|
| SEC06 | BP04 | Not available | | |
| SEC06 | BP05 | Not available | | |
| SEC06 | BP06 | Not available | | |
| SEC07 | BP01 | Not available | | |
| SEC07 | BP02 | Not available | | |
| SEC07 | BP03 | Not available | | |
| SEC07 | BP04 | Not available | | |
| SEC08 | BP01 | Not available | | |
| SEC08 | BP02 | Need Attention | - [RequiresKmsKey] - Enable SSE
- [ap-southeast-1]Cloudtrail::SWOCloudTrail-Organizational
- [EBSEncrypted]
- [EncryptedAtRest]
- [eksSecretsEncryption]
- [lambdaCMKEncryptionDisabled] - Customer Managed Key Not In Used
- [ap-southeast-1]Lambda::aws-controltower-NotificationForwarder, Lambda::SecretsManagerrds-rotation-lambda
- [us-east-1]Lambda::aws-controltower-NotificationForwarder
- [StorageEncrypted]
- [ServerSideEncrypted]
| Encrypt CloudTrail using AWS KMS CloudTrail Security Best Practices Lambda securing environment variables |
| SEC08 | BP03 | Not available | | |
| SEC08 | BP04 | Need Attention | - [eksClusterRoleLeastPrivilege]
- [InlinePolicyFullAccessOneServ] - Limit access in policy
- [GLOBAL]Role::AWSReservedSSO_YoPayment-AWS-Data-Pgw-Dev_5af8cd0c694d6669, Role::AWSReservedSSO_YoPayment-AWS-Developer-Pgw-Dev_c207ab9d1e5199f5, Role::AWSReservedSSO_YoPayment-AWS-Platform-Pgw-Dev_c9b162f22c1c139b, Role::YoPayment-AWS-Terraform-Pgw-Dev
- [InlinePolicyFullAdminAccess]
- [FullAdminAccess] - Limit permissions.
- [GLOBAL]Role::aws-controltower-AdministratorExecutionRole, Role::AWSControlTowerExecution, Role::AWSReservedSSO_AWSAdministratorAccess_6ad2f92126b0c1d0, Role::AWSReservedSSO_YoPayment-AWS-Admin-Pgw-Dev_999b53209cafbc21, Role::stacksets-exec-bb8cf4473e8495ef76fab8d8a00a5618
- [lambdaRoleReused]
- [EC2IamProfile]
- [BucketVersioning] - Enable Versioning
- [ap-southeast-1]Bucket::archiver-system.dev.sg.pgw, Bucket::images-upload.dev.sgp-pay1-wallet, Bucket::logs.dev.sg.pgw
- [ObjectLock] - Enable Object Lock
- [ap-southeast-1]Bucket::262130478988-pgw-dev-tf-state, Bucket::archiver-system.dev.sg.pgw, Bucket::images-upload.dev.sg.pgw, Bucket::images-upload.dev.sgp-pay1-wallet, Bucket::logs.dev.sg.pgw, Bucket::payment-gateway-dev-tf-state, Bucket::pgw-config.dev.sg.pgw
- [PublicAccessBlock]
| AWS Docs AWS Docs Organization GuardRail Blog AWS Docs Manage Versioning Example AWS Docs |
| SEC08 | BP05 | Not available | | |
| SEC09 | BP01 | Not available | | |
| SEC09 | BP02 | Need Attention | - [viewerPolicyHttps]
- [DeprecatedSSLProtocol]
- [SGEncryptionInTransit] - Encryption in Transit
- [ap-southeast-1]SG::sg-0251261a4780396ef, SG::sg-0af4192d63016f4c6, SG::sg-084f2463febd93807
- [us-east-1]SG::sg-03ec10c6bdf83dac6
- [ELBListenerInsecure] - Insecure Listener
- [ap-southeast-1]ELB::pgw-dev-alb, ELB::pay1-wallet-dev-alb
| Data protection in Amazon EC2 ALB Configuration Guide |
| SEC09 | BP03 | Not available | | |
| SEC09 | BP04 | Not available | | |
| SEC10 | BP01 | Not available | | |
| SEC10 | BP02 | Not available | | |
| SEC10 | BP03 | Not available | | |
| SEC10 | BP04 | Not available | | |
| SEC10 | BP05 | Not available | | |
| SEC10 | BP06 | Not available | | |
| SEC10 | BP07 | Not available | | |
| SEC11 | BP01 | Not available | | |
| SEC11 | BP02 | Not available | | |
| SEC11 | BP03 | Not available | | |
| SEC11 | BP04 | Not available | | |
| SEC11 | BP05 | Not available | | |
| SEC11 | BP06 | Not available | | |
| SEC11 | BP07 | Not available | | |
| SEC11 | BP08 | Not available | | |