From 465e35bf549239930447a6689397c98c825258eb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Mesquita?= <151409184+jfgmesquita@users.noreply.github.com> Date: Tue, 25 Aug 2026 16:38:33 +0100 Subject: [PATCH] fix(compliance): correct AWS FSBP check mapping for IAM.9 and EKS.1 (#12372) Co-authored-by: pedrooot --- prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md | 1 + .../aws/aws_foundational_security_best_practices_aws.json | 6 ++++-- 2 files changed, 5 insertions(+), 2 deletions(-) create mode 100644 prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md diff --git a/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md b/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md new file mode 100644 index 0000000000..f3b3085687 --- /dev/null +++ b/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md @@ -0,0 +1 @@ +AWS FSBP compliance mapping for `IAM.9` and `EKS.1` referenced missing/renamed checks; both now point to their real, existing check IDs diff --git a/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json b/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json index b58a74bcaa..c09f6821df 100644 --- a/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json +++ b/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json @@ -1782,7 +1782,7 @@ "Name": "EKS cluster endpoints should not be publicly accessible", "Description": "This control checks whether an Amazon EKS cluster endpoint is publicly accessible. The control fails if an EKS cluster has an endpoint that is publicly accessible.", "Checks": [ - "eks_endpoints_not_publicly_accessible" + "eks_cluster_not_publicly_accessible" ], "Attributes": [ { @@ -2634,7 +2634,9 @@ "Id": "IAM.9", "Name": "MFA should be enabled for the root user", "Description": "The root user has complete access to all the services and resources in an AWS account. MFA adds an extra layer of protection on top of a user name and password. With MFA enabled, when a user signs in to the AWS Management Console, they're prompted for their user name and password and for an authentication code from their AWS MFA device.", - "Checks": [], + "Checks": [ + "iam_root_mfa_enabled" + ], "Attributes": [ { "ItemId": "IAM.9",