mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-07-23 12:31:54 +00:00
chore(docs): update BridgeCrew links in metadata to our local docs link (#3858)
Co-authored-by: puchy22 <rubendltv22@gmail.com>
This commit is contained in:
@@ -249,11 +249,11 @@ Each Prowler check has metadata associated which is stored at the same level of
|
||||
# Code holds different methods to remediate the FAIL finding
|
||||
"Code": {
|
||||
# CLI holds the command in the provider native CLI to remediate it
|
||||
"CLI": "https://docs.bridgecrew.io/docs/public_8#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/public_8#cli-command",
|
||||
# NativeIaC holds the native IaC code to remediate it, use "https://docs.bridgecrew.io/docs"
|
||||
"NativeIaC": "",
|
||||
# Other holds the other commands, scripts or code to remediate it, use "https://www.trendmicro.com/cloudoneconformity"
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_8#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/public_8#aws-console",
|
||||
# Terraform holds the Terraform code to remediate it, use "https://docs.bridgecrew.io/docs"
|
||||
"Terraform": ""
|
||||
},
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "No command available.",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_18-maintain-contact-details#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_18-maintain-contact-details#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_18-maintain-contact-details#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_18-maintain-contact-details#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "No command available.",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_19#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_19#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "No command available.",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_15",
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_15",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+2
-2
@@ -19,9 +19,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/public_6-api-gateway-authorizer-set#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/public-policies/public_6-api-gateway-authorizer-set#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/public_6-api-gateway-authorizer-set#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/public-policies/public_6-api-gateway-authorizer-set#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Implement Amazon Cognito or a Lambda function to control access to your API.",
|
||||
|
||||
+1
-1
@@ -21,7 +21,7 @@
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-api-gateway-stage-have-logging-level-defined-as-appropiate#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/ensure-api-gateway-stage-have-logging-level-defined-as-appropiate#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Monitoring is an important part of maintaining the reliability, availability and performance of API Gateway and your AWS solutions. You should collect monitoring data from all of the parts of your AWS solution. CloudTrail provides a record of actions taken by a user, role, or an AWS service in API Gateway. Using the information collected by CloudTrail, you can determine the request that was made to API Gateway, the IP address from which the request was made, who made the request, etc.",
|
||||
|
||||
+2
-2
@@ -20,8 +20,8 @@
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/bc_aws_logging_30#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_logging_30#cloudformation"
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_30#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_30#cloudformation"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Monitoring is an important part of maintaining the reliability, availability and performance of API Gateway and your AWS solutions. You should collect monitoring data from all of the parts of your AWS solution. CloudTrail provides a record of actions taken by a user, role, or an AWS service in API Gateway. Using the information collected by CloudTrail, you can determine the request that was made to API Gateway, the IP address from which the request was made, who made the request, etc.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws athena update-work-group --region <REGION> --work-group <workgroup_name> --configuration-updates ResultConfigurationUpdates={EncryptionConfiguration={EncryptionOption=SSE_S3|SSE_KMS|CSE_KMS}}",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Athena/encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-athena-workgroup-is-encrypted#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-that-athena-workgroup-is-encrypted#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.",
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws athena update-work-group --region <REGION> --work-group <workgroup_name> --configuration-updates EnforceWorkGroupConfiguration=True",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_33#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_33#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_33#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_33#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure that workgroup configuration is enforced so it cannot be overriden by client-side settings.",
|
||||
@@ -29,4 +29,4 @@
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
}
|
||||
}
|
||||
|
||||
+3
-3
@@ -13,10 +13,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/lambda-functions.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/bc_aws_secrets_3#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_secrets_3#cloudformation",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_3#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_3#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_secrets_3#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_3#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use Secrets Manager to securely provide database credentials to Lambda functions and secure the databases as well as use the credentials to connect and query them without hardcoding the secrets in code or passing them through environmental variables.",
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-secretsmanager-secret-generatesecretstring.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/bc_aws_secrets_2#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_2#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
|
||||
+2
-2
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/CloudFront/security-policy.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/networking_32#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/networking_32#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/networking_32#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/networking_32#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use HTTPS everywhere possible. It will enforce privacy and protect against account hijacking and other threats.",
|
||||
|
||||
+3
-3
@@ -13,10 +13,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/AccessLogs.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/logging_20#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/logging_20#cloudformation",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/logging-policies/logging_20#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/logging_20#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_20#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_20#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Real-time monitoring can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. Enable logging for services with defined log rotation. These logs are useful for Incident Response and forensics investigation among other use cases.",
|
||||
|
||||
+2
-2
@@ -13,9 +13,9 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/secure-connections-supported-viewer-protocols-ciphers.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/networking_33#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/networking-policies/networking_33#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/networking_33#aws-cloudfront-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/networking-policies/networking_33#aws-cloudfront-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/CloudFront/cloudfront-integrated-with-waf.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_27#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/bc_aws_general_27#cloudfront-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_27#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_27#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_27#cloudfront-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_27#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use AWS WAF to protect your service from common web exploits. These could affect availability and performance; compromise security; or consume excessive resources.",
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@
|
||||
"Code": {
|
||||
"CLI": "aws cloudtrail update-trail --name <trail_name> --cloudwatch-logs-log-group- arn <cloudtrail_log_group_arn> --cloudwatch-logs-role-arn <cloudtrail_cloudwatchLogs_role_arn>",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_4#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_4#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws cloudtrail update-trail --name <trail_name> --kms-id <cloudtrail_kms_key> aws kms put-key-policy --key-id <cloudtrail_kms_key> --policy <cloudtrail_kms_key_policy>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/logging_7#fix---buildtime",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/logging_7#fix---buildtime",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
},
|
||||
|
||||
+2
-2
@@ -18,9 +18,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws cloudtrail update-trail --name <trail_name> --enable-log-file-validation",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/logging_2#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/logging_2#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_2#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_2#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure LogFileValidationEnabled is set to true for each trail.",
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_6#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_6#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_3#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_3#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+3
-3
@@ -18,9 +18,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws cloudtrail create-trail --name <trail_name> --bucket-name <s3_bucket_for_cloudtrail> --is-multi-region-trail aws cloudtrail update-trail --name <trail_name> --is-multi-region-trail ",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/logging_1#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_1#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_1#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/logging_1#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_1#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_1#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure Logging is set to ON on all regions (even if they are not being used at the moment.",
|
||||
|
||||
+4
-4
@@ -12,17 +12,17 @@
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
"Description": "Ensure CloudTrail logging management events in All Regions",
|
||||
"Risk": "AWS CloudTrail enables governance, compliance, operational auditing, and risk auditing of your AWS account. To meet FTR requirements, you must have management events enabled for all AWS accounts and in all regions and aggregate these logs into an Amazon Simple Storage Service (Amazon S3) bucket owned by a separate AWS account.",
|
||||
"RelatedUrl": "https://docs.bridgecrew.io/docs/logging_14",
|
||||
"RelatedUrl": "https://docs.prowler.com/checks/aws/logging-policies/logging_14",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws cloudtrail update-trail --name <trail_name> --is-multi-region-trail",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_14",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_14#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_14",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_14#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable CloudTrail logging management events in All Regions",
|
||||
"Url": "https://docs.bridgecrew.io/docs/logging_14"
|
||||
"Url": "https://docs.prowler.com/checks/aws/logging-policies/logging_14"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_11#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_11#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_11#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_11#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_12#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_12#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_12#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_12#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_13#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_13#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_13#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_13#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "If you are using CloudTrails and CloudWatch, perform the following to setup the metric filter, alarm, SNS topic, and subscription: 1. Create a metric filter based on filter pattern provided which checks for route table changes and the <cloudtrail_log_group_name> taken from audit step 1. aws logs put-metric-filter --log-group-name <cloudtrail_log_group_name> -- filter-name `<route_table_changes_metric>` --metric-transformations metricName= `<route_table_changes_metric>` ,metricNamespace='CISBenchmark',metricValue=1 --filter-pattern '{($.eventSource = ec2.amazonaws.com) && (($.eventName = CreateRoute) || ($.eventName = CreateRouteTable) || ($.eventName = ReplaceRoute) || ($.eventName = ReplaceRouteTableAssociation) || ($.eventName = DeleteRouteTable) || ($.eventName = DeleteRoute) || ($.eventName = DisassociateRouteTable)) }' Note: You can choose your own metricName and metricNamespace strings. Using the same metricNamespace for all Foundations Benchmark metrics will group them together. 2. Create an SNS topic that the alarm will notify aws sns create-topic --name <sns_topic_name> Note: you can execute this command once and then re-use the same topic for all monitoring alarms. 3. Create an SNS subscription to the topic created in step 2 aws sns subscribe --topic-arn <sns_topic_arn> --protocol <protocol_for_sns> - -notification-endpoint <sns_subscription_endpoints> Note: you can execute this command once and then re-use the SNS subscription for all monitoring alarms. 4. Create an alarm that is associated with the CloudWatch Logs Metric Filter created in step 1 and an SNS topic created in step 2 aws cloudwatch put-metric-alarm --alarm-name `<route_table_changes_alarm>` --metric-name `<route_table_changes_metric>` --statistic Sum --period 300 - -threshold 1 --comparison-operator GreaterThanOrEqualToThreshold -- evaluation-periods 1 --namespace 'CISBenchmark' --alarm-actions <sns_topic_arn>",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_14#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_14#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_14#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_14#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "associate-kms-key --log-group-name <value> --kms-key-id <value>",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_21#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_21#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+3
-3
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/AWS_Logs.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/logging_13#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/logging_13#cloudformation",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/logging-policies/logging_13#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/logging_13#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_13#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_13#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Add Log Retention policy of specific days to log groups. This will persist logs and traces for a long time.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_9#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_9#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_9#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_9#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_5#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_5#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_5#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_5#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_6#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_6#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_6#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_6#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_7#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_7#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_7#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_7#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_8#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_8#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_8#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_8#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_4#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_4#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_4#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_4#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_3#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_3#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_3#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_3#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_10#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_10#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_10#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_10#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_2#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_2#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_2#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_2#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+2
-2
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/monitoring_1#procedure",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_1#procedure",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/monitoring_1#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/monitoring-policies/monitoring_1#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended that a metric filter and alarm be established for unauthorized requests.",
|
||||
|
||||
+3
-3
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "https://aws.amazon.com/blogs/mt/aws-config-best-practices/",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/logging_5-enable-aws-config-regions#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/logging-policies/logging_5-enable-aws-config-regions#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/logging_5-enable-aws-config-regions#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/logging_5-enable-aws-config-regions#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/logging_5-enable-aws-config-regions#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/logging_5-enable-aws-config-regions#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is recommended to enable AWS Config in all regions.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws docdb create-db-cluster --db-cluster-identifier <db_cluster_id> --port 27017 --engine docdb --master-username <yourMasterUsername> --master-user-password <yourMasterPassword> --storage-encrypted",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_28#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_28#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws dax create-cluster --cluster-name <cluster_name> --node-type <node_type> --replication-factor <nodes_number> --iam-role-arn <role_arn> --sse-specification Enabled=true",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_23#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_23#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_23#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_23#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Re-create the cluster to enable encryption at rest if it was not enabled at creation.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-dynamodb-tables-are-encrypted#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-that-dynamodb-tables-are-encrypted#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Specify an encryption key when you create a new table or switch the encryption keys on an existing table by using the AWS Management Console.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws dynamodb update-continuous-backups --table-name <table_name> --point-in-time-recovery-specification PointInTimeRecoveryEnabled=true",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_6#cloudformation--serverless",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_6#cloudformation--serverless",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_6#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_6#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable point-in-time recovery, this is not enabled by default.",
|
||||
|
||||
@@ -15,9 +15,9 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/public_8#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/public-policies/public_8#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_8#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/public-policies/public_8#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+2
-2
@@ -17,8 +17,8 @@
|
||||
"Code": {
|
||||
"CLI": "aws ec2 enable-ebs-encryption-by-default",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/ensure-ebs-default-encryption-is-enabled#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-ebs-default-encryption-is-enabled#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/general-policies/ensure-ebs-default-encryption-is-enabled#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-ebs-default-encryption-is-enabled#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.",
|
||||
|
||||
+2
-2
@@ -15,9 +15,9 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/public_7#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/public-policies/public_7#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_7#aws-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/public-policies/public_7#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws ec2 --region <REGION> enable-ebs-encryption-by-default",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_3-encrypt-eps-volume#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/general_3-encrypt-eps-volume#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_3-encrypt-eps-volume#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_3-encrypt-ebs-volume#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/general-policies/general_3-encrypt-ebs-volume#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_3-encrypt-ebs-volume#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Encrypt all EBS Snapshot and Enable Encryption by default. You can configure your AWS account to enforce the encryption of the new EBS volumes and snapshot copies that you create. For example; Amazon EBS encrypts the EBS volumes created when you launch an instance and the snapshots that you copy from an unencrypted snapshot.",
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws ec2 release-address --public-ip <theIPyoudontneed>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_19#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/general_19#ec2-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_19#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_19#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/general-policies/general_19#ec2-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_19#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure Elastic IPs are not unassigned.",
|
||||
|
||||
+2
-2
@@ -18,7 +18,7 @@
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EC2/instance-detailed-monitoring.html",
|
||||
"NativeIaC": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EC2/instance-detailed-monitoring.html",
|
||||
"Other": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-cloudwatch-new.html#enable-detailed-monitoring-instance",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-detailed-monitoring-is-enabled-for-ec2-instances#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/ensure-that-detailed-monitoring-is-enabled-for-ec2-instances#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable detailed monitoring for EC2 instances to gain better insights into performance metrics.",
|
||||
@@ -29,4 +29,4 @@
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
}
|
||||
}
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws ec2 modify-instance-metadata-options --instance-id <instance-id> --http-tokens required --http-endpoint enabled",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_31#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_31#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EC2/require-imds-v2.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_31#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_31#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "If you don't need IMDS you can turn it off. Using aws-cli you can force the instance to use only IMDSv2.",
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/public_12#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_12#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/public_12#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/public-policies/public_12#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/public-policies/public_12#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/public-policies/public_12#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use an ALB and apply WAF ACL.",
|
||||
|
||||
+3
-3
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/bc_aws_secrets_1#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_secrets_1#cloudformation",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_1#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_1#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_secrets_1#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/secrets-policies/bc_aws_secrets_1#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Implement automated detective control (e.g. using tools like Prowler) to scan accounts for passwords and secrets. Use secrets manager service to store and retrieve passwords and secrets.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-22#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-22#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-22#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-22#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Apply Zero Trust approach. Implement a process to scan and remediate unrestricted or overly permissive network acls. Recommended best practices is to narrow the definition for the minimum ports required.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-3389#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-3389#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-3389#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/ensure-aws-nacl-does-not-allow-ingress-from-00000-to-port-3389#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Apply Zero Trust approach. Implement a process to scan and remediate unrestricted or overly permissive network acls. Recommended best practices is to narrow the definition for the minimum ports required.",
|
||||
|
||||
+4
-4
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/networking_1-port-security#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/networking_1-port-security#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/networking_1-port-security#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/networking_1-port-security#terraform"
|
||||
"CLI": "https://docs.prowler.com/checks/aws/networking-policies/networking_1-port-security#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/networking_1-port-security#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/networking-policies/networking_1-port-security#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/networking_1-port-security#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use a Zero Trust approach. Narrow ingress traffic as much as possible. Consider north-south as well as east-west traffic.",
|
||||
|
||||
+4
-4
@@ -15,10 +15,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/networking_2#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/networking_2#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/networking_2#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/networking_2#terraform"
|
||||
"CLI": "https://docs.prowler.com/checks/aws/networking-policies/networking_2#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/networking_2#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/networking-policies/networking_2#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/networking_2#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use a Zero Trust approach. Narrow ingress traffic as much as possible. Consider north-south as well as east-west traffic.",
|
||||
|
||||
+2
-2
@@ -17,8 +17,8 @@
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/networking_4#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/networking_4#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/networking-policies/networking_4#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/networking_4#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Apply Zero Trust approach. Implement a process to scan and remediate unrestricted or overly permissive security groups. Recommended best practices is to narrow the definition for the minimum ports required.",
|
||||
|
||||
+2
-2
@@ -17,8 +17,8 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/public_1-ecr-repositories-not-public#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_1-ecr-repositories-not-public#aws-console",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/public-policies/public_1-ecr-repositories-not-public#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/public-policies/public_1-ecr-repositories-not-public#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+2
-2
@@ -17,9 +17,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws ecr create-repository --repository-name <repo_name> --image-scanning-configuration scanOnPush=true--region <region_name>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_8#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_8#cli-command",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_8#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_8#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable ECR image scanning and review the scan findings for information about the security of the container images that are being deployed.",
|
||||
|
||||
+2
-2
@@ -18,9 +18,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws efs create-file-system --creation-token $(uuidgen) --performance-mode generalPurpose --encrypted --kms-key-id user/customer-managedCMKalias",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_17#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_17#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_17#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_17#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure that encryption at rest is enabled for EFS file systems. Encryption at rest can only be enabled during the file system creation.",
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EKS/enable-envelope-encryption.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_kubernetes_3#fix---builtime",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/kubernetes-policies-1/bc_aws_kubernetes_3#fix---builtime",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
},
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EKS/security-groups.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_kubernetes_1#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/kubernetes-policies-1/bc_aws_kubernetes_1#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable and configure Network Policy to enhance network security within the EKS cluster.",
|
||||
|
||||
+2
-2
@@ -17,8 +17,8 @@
|
||||
"Code": {
|
||||
"CLI": "aws eks update-cluster-config --region <region_name> --name <cluster_name> --logging '{\"clusterLogging\":[{\"types\":[\"api\",\"audit\",\"authenticator\",\"controllerManager\",\"scheduler\"],\"enabled\":true}]}'",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/bc_aws_kubernetes_4#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_kubernetes_4#fix---buildtime"
|
||||
"Other": "https://docs.prowler.com/checks/aws/kubernetes-policies-1/bc_aws_kubernetes_4#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/kubernetes-policies-1/bc_aws_kubernetes_4#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Make sure you logging for EKS control plane is enabled.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws elb set-load-balancer-policies-of-listener --load-balancer-name <lb_name> --load-balancer-port 443 --policy-names ELBSecurityPolicy-TLS-1-2-2017-01",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELB/elb-security-policy.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_43#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_43#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use a Security policy with ciphers that are as strong as possible. Drop legacy and insecure ciphers.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws elb modify-load-balancer-attributes --load-balancer-name <lb_name> --load-balancer-attributes '{AccessLog:{Enabled:true,EmitInterval:60,S3BucketName:<bucket_name>}}'",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_logging_23#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_23#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELB/elb-access-log.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_logging_23#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_23#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable ELB logging, create a log lifecycle and define use cases.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws elbv2 modify-load-balancer-attributes --load-balancer-arn <lb_arn> --attributes Key=deletion_protection.enabled,Value=true",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELBv2/deletion-protection.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_networking_62#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_networking_62#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable deletion protection attribute, this is not enabled by default.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws elbv2 modify-listener --listener-arn <lb_arn> --ssl-policy ELBSecurityPolicy-TLS13-1-2-Ext2-2021-06",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELBv2/security-policy.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_43#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_43#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use a Security policy with ciphers that are as strong as possible. Drop legacy and insecure ciphers.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws elbv2 modify-load-balancer-attributes --load-balancer-arn <lb_arn> --attributes Key=access_logs.s3.enabled,Value=true Key=access_logs.s3.bucket,Value=<bucket_name> Key=access_logs.s3.prefix,Value=<prefix>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_logging_22#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_22#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELBv2/access-log.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_logging_22#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_22#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable ELB logging, create a log lifecycle and define use cases.",
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
"Code": {
|
||||
"CLI": "aws elbv2 create-listener --load-balancer-arn <lb_arn> --protocol HTTPS --port 443 --ssl-policy <ssl_policy> --certificates CertificateArn=<certificate_arn>,IsDefault=true",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/networking_36#aws-ec2-console",
|
||||
"Other": "https://docs.prowler.com/checks/aws/networking-policies/networking_36#aws-ec2-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-amazon-emr-clusters-security-groups-are-not-open-to-the-world#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/networking-policies/ensure-that-amazon-emr-clusters-security-groups-are-not-open-to-the-world#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Only make acceptable EMR clusters public.",
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-glacier-vault-access-policy-is-not-public-by-only-allowing-specific-services-or-principals-to-access-it#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-glacier-vault-access-policy-is-not-public-by-only-allowing-specific-services-or-principals-to-access-it#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Ensure vault policy does not have principle as *.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue put-data-catalog-encryption-settings --data-catalog-encryption-settings ConnectionPasswordEncryption={ReturnConnectionPasswordEncrypted=True,AwsKmsKeyId=<ksm_key_arn>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_37#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_37#cloudformation",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_37#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_37#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "On the AWS Glue console; you can enable this option on the Data catalog settings page.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue put-data-catalog-encryption-settings --data-catalog-encryption-settings EncryptionAtRest={CatalogEncryptionMode=SSE-KMS,SseAwsKmsKeyId=<ksm_key_arn>",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_37#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_37#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/data-catalog-encryption-at-rest.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_37#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_37#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name cw-encrypted-sec-config --encryption-configuration {'CloudWatchEncryption': [{'CloudWatchEncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/cloud-watch-logs-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption in the Security configurations.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name jb-encrypted-sec-config --encryption-configuration {'JobBookmarksEncryption': [{'JobBookmarksEncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/job-bookmark-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption in the Security configurations.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name s3-encrypted-sec-config --encryption-configuration {'S3Encryption': [{'S3EncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/s3-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Specify AWS KMS keys to use for input and output from S3 and EBS.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name s3-encrypted-sec-config --encryption-configuration {'S3Encryption': [{'S3EncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/s3-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Provide the encryption properties that are used by crawlers, jobs and development endpoints.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name cw-encrypted-sec-config --encryption-configuration {'CloudWatchEncryption': [{'CloudWatchEncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/cloud-watch-logs-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption in the Security configurations.",
|
||||
|
||||
+2
-2
@@ -16,9 +16,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws glue create-security-configuration --name jb-encrypted-sec-config --encryption-configuration {'JobBookmarksEncryption': [{'JobBookmarksEncryptionMode': 'SSE-KMS','KmsKeyArn': <kms_arn>}]}",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_general_41#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Glue/job-bookmark-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_general_41#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_41#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption in the Security configurations.",
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/GuardDuty/guardduty-enabled.html",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/GuardDuty/guardduty-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-guardduty-is-enabled-to-specific-orgregion#fix---buildtime"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-guardduty-is-enabled-to-specific-orgregion#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable GuardDuty and analyze its findings.",
|
||||
|
||||
+3
-3
@@ -17,10 +17,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/iam_47#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_47#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/iam_47#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is more secure to start with a minimum set of permissions and grant additional permissions as necessary; rather than starting with permissions that are too lenient and then trying to tighten them later. List policies an analyze if permissions are the least possible to conduct business activities.",
|
||||
|
||||
+3
-3
@@ -17,10 +17,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/iam_47#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_47#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/iam_47#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is more secure to start with a minimum set of permissions and grant additional permissions as necessary; rather than starting with permissions that are too lenient and then trying to tighten them later. List policies an analyze if permissions are the least possible to conduct business activities.",
|
||||
|
||||
+3
-3
@@ -17,10 +17,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/iam_47#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_47#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/iam_47#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is more secure to start with a minimum set of permissions and grant additional permissions as necessary; rather than starting with permissions that are too lenient and then trying to tighten them later. List policies an analyze if permissions are the least possible to conduct business activities.",
|
||||
|
||||
+3
-3
@@ -17,10 +17,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/iam_47#cli-command",
|
||||
"CLI": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#cli-command",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/iam_47#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/iam_47#terraform"
|
||||
"Other": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/iam-policies/iam_47#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "It is more secure to start with a minimum set of permissions and grant additional permissions as necessary; rather than starting with permissions that are too lenient and then trying to tighten them later. List policies an analyze if permissions are the least possible to conduct business activities.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"CLI": "aws kms enable-key-rotation --key-id <key_id>",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-kms-have-rotation-policy#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-kms-have-rotation-policy#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "For every KMS Customer Master Keys (CMKs), ensure that Rotate this key every year is enabled.",
|
||||
|
||||
+4
-4
@@ -16,10 +16,10 @@
|
||||
"RelatedUrl": "",
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://docs.bridgecrew.io/docs/elasticsearch_7#cli-command",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/elasticsearch_7#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/elasticsearch_7#fix---runtime",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/elasticsearch_7#fix---buildtime"
|
||||
"CLI": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_7#cli-command",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_7#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_7#fix---runtime",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_7#fix---buildtime"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Elasticsearch/Opensearch log. Create use cases for them. Using audit logs check for access denied events.",
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Elasticsearch/encryption-at-rest.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/elasticsearch_3-enable-encryptionatrest#fix---builtime",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_3-enable-encryptionatrest#fix---builtime",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Elasticsearch/encryption-at-rest.html",
|
||||
"Terraform": ""
|
||||
},
|
||||
|
||||
+2
-2
@@ -18,8 +18,8 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/elasticsearch_6#fix---builtime",
|
||||
"Other": "https://docs.bridgecrew.io/docs/elasticsearch_6#aws-console",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_6#fix---builtime",
|
||||
"Other": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_6#aws-console",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Elasticsearch/node-to-node-encryption.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/elasticsearch_5#fix---builtime",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/elasticsearch-policies/elasticsearch_5#fix---builtime",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Elasticsearch/node-to-node-encryption.html",
|
||||
"Terraform": ""
|
||||
},
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Elasticsearch/elasticsearch-domain-exposed.html",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://docs.bridgecrew.io/docs/public_3#fix---runtime",
|
||||
"Other": "https://docs.prowler.com/checks/aws/public-policies/public_3#fix---runtime",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "aws rds modify-db-instance --db-instance-identifier <db_instance_id> --backup-retention-period 7 --apply-immediately",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/rds-automated-backups-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-rds-instances-have-backup-policy#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-that-rds-instances-have-backup-policy#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable automated backup for production data. Define a retention period and periodically test backup restoration. A Disaster Recovery process should be in place to govern Data Protection approach.",
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "aws rds modify-db-instance --db-instance-identifier <db_instance_id> --deletion-protection --apply-immediately",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/instance-deletion-protection.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-rds-clusters-and-instances-have-deletion-protection-enabled#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-that-rds-clusters-and-instances-have-deletion-protection-enabled#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable deletion protection using the AWS Management Console for production DB instances.",
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "aws rds create-db-instance --db-instance-identifier <db_instance_id> --db-instance-class <instance_class> --engine <engine> --storage-encrypted true",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-enhanced-monitoring-is-enabled-for-amazon-rds-instances#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/ensure-that-enhanced-monitoring-is-enabled-for-amazon-rds-instances#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To use Enhanced Monitoring, you must create an IAM role; and then enable Enhanced Monitoring.",
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
"CLI": "aws rds modify-db-instance --db-instance-identifier <db_instance_id> --cloudwatch-logs-export-configuration {'EnableLogTypes':['audit',error','general','slowquery']} --apply-immediately",
|
||||
"NativeIaC": "",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/log-exports.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-that-respective-logs-of-amazon-relational-database-service-amazon-rds-are-enabled#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/iam-policies/ensure-that-respective-logs-of-amazon-relational-database-service-amazon-rds-are-enabled#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Use CloudWatch Logs to perform real-time analysis of the log data. Create alarms and view metrics.",
|
||||
|
||||
+2
-2
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws rds modify-db-instance --db-instance-identifier <db_instance_id> --auto-minor-version-upgrade --apply-immediately",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/ensure-aws-db-instance-gets-all-minor-upgrades-automatically#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/ensure-aws-db-instance-gets-all-minor-upgrades-automatically#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/rds-auto-minor-version-upgrade.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/ensure-aws-db-instance-gets-all-minor-upgrades-automatically#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-aws-db-instance-gets-all-minor-upgrades-automatically#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable auto minor version upgrade for all databases and environments.",
|
||||
|
||||
+2
-2
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws rds create-db-instance --db-instance-identifier <db_instance_id> --multi-az true",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_73#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_73#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/rds-multi-az.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_73#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_73#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable multi-AZ deployment for production databases.",
|
||||
|
||||
+2
-2
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws rds modify-db-instance --db-instance-identifier <db_instance_id> --no-publicly-accessible --apply-immediately",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/public_2#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/public-policies/public_2#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/rds-publicly-accessible.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/public_2#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/public-policies/public_2#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Using an AWS Config rule check for RDS public instances periodically and check there is a business reason for it.",
|
||||
|
||||
+2
-2
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "aws rds create-db-instance --db-instance-identifier <db_instance_id> --db-instance-class <instance_class> --engine <engine> --storage-encrypted true",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/general_4#cloudformation",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_4#cloudformation",
|
||||
"Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/rds-encryption-enabled.html",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/general_4#terraform"
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_4#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.",
|
||||
|
||||
+3
-3
@@ -14,9 +14,9 @@
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Redshift/redshift-cluster-audit-logging-enabled.html",
|
||||
"NativeIaC": "https://docs.bridgecrew.io/docs/bc_aws_logging_12#cloudformation",
|
||||
"Other": "https://docs.bridgecrew.io/docs/bc_aws_logging_12#aws-console",
|
||||
"Terraform": "https://docs.bridgecrew.io/docs/bc_aws_logging_12#terraform"
|
||||
"NativeIaC": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_12#cloudformation",
|
||||
"Other": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_12#aws-console",
|
||||
"Terraform": "https://docs.prowler.com/checks/aws/logging-policies/bc_aws_logging_12#terraform"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable logs. Create an S3 lifecycle policy. Define use cases, metrics and automated responses where applicable.",
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user