AWS Cloud Security Configuration Check List:

Identity and Access Management:

  1. Avoid the use of the “root” account
  2. Ensure multi-factor authentication (MFA)is enabled for all IAM users that have a console password.
  3. Implement strong IAM password  policies across accounts.

Logging:

  1. Ensure that CloudTrail is enabled all regions.
  2. Ensure the S3 bucket used to store cloudTrail logs is not publicly accessible.

Monitoring:
1. Ensure a log metric filter and alarm exist for usage of the “root” account.
2. Ensure a log metric filter and alarm exist for IAM policy changes.
Networking:
1. Ensure no security groups allow ingress from 0.0.0.0/0 to port 22.
2. Ensure the default security group of every VPC restricts all traffic.
3. Ensure routing tables for VPC peering are “least access”.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s