mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 10:14:20 +00:00
Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f7669649f0 | ||
|
|
510fc1108c | ||
|
|
19a2875e28 | ||
|
|
a2526d946b | ||
|
|
19269ff2a8 | ||
|
|
03d4c23551 | ||
|
|
18dc77f5ae | ||
|
|
39f20b883b | ||
|
|
94fbf76f5d | ||
|
|
c6156b20d3 | ||
|
|
286c1e4840 |
@@ -158,7 +158,7 @@ SENTRY_RELEASE=local
|
||||
# REO_DEV_CLIENT_ID=
|
||||
|
||||
#### Prowler release version ####
|
||||
NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.41.0
|
||||
NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.41.1
|
||||
|
||||
# Social login credentials
|
||||
SOCIAL_GOOGLE_OAUTH_CALLBACK_URL="${AUTH_URL}/api/auth/callback/google"
|
||||
|
||||
+34
@@ -17,6 +17,40 @@ ignore:
|
||||
- vulnerability: CVE-2026-71556
|
||||
package:
|
||||
name: github.com/go-git/go-git/v5
|
||||
# CVE-2026-84304 is the same temporary exception documented in .trivyignore.yaml:
|
||||
# Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.83.1 fix is not in any release.
|
||||
# Prowler only runs `trivy image` / `trivy fs`, never client/server mode, so no gRPC
|
||||
# endpoint exists in the image. Pinned to the embedded version so the rule stops
|
||||
# matching on its own once Trivy bumps grpc. Remove with the Trivy exception by 2026-10-15.
|
||||
# https://github.com/aquasecurity/trivy/pull/11176
|
||||
- vulnerability: CVE-2026-84304
|
||||
package:
|
||||
name: google.golang.org/grpc
|
||||
version: v1.82.1
|
||||
# CVE-2026-84445 is the same temporary exception documented in .trivyignore.yaml:
|
||||
# Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.82.2 / 1.83.2 fix is not in any
|
||||
# release. The panic needs a gRPC server built with `xds.NewGRPCServer()`; Prowler only
|
||||
# runs `trivy image` / `trivy fs`, so the image serves no gRPC at all. Pinned to the
|
||||
# embedded version so the rule stops matching on its own once Trivy bumps grpc. Remove
|
||||
# with the Trivy exception by 2026-10-15.
|
||||
# https://github.com/advisories/GHSA-2v4p-qf9q-27wj
|
||||
- vulnerability: CVE-2026-84445
|
||||
package:
|
||||
name: google.golang.org/grpc
|
||||
version: v1.82.1
|
||||
# CVE-2026-56855 / CVE-2026-78662 are the same temporary exception documented in
|
||||
# .trivyignore.yaml: Trivy 0.74.0 still embeds golang.org/x/crypto v0.55.0, while the
|
||||
# 0.56.0 fix (published 2026-09-02) hasn't reached any Trivy release, or even Trivy
|
||||
# main, yet. Pinned to the embedded version so the rule stops matching on its own once
|
||||
# Trivy bumps it. Remove with the Trivy exception by 2026-10-15.
|
||||
- vulnerability: CVE-2026-56855
|
||||
package:
|
||||
name: golang.org/x/crypto
|
||||
version: v0.55.0
|
||||
- vulnerability: CVE-2026-78662
|
||||
package:
|
||||
name: golang.org/x/crypto
|
||||
version: v0.55.0
|
||||
- vulnerability: CVE-2026-56852
|
||||
package:
|
||||
name: golang.org/x/text
|
||||
|
||||
@@ -113,6 +113,18 @@ vulnerabilities:
|
||||
purls:
|
||||
- "pkg:npm/fast-uri"
|
||||
expired_at: 2027-01-31
|
||||
- id: CVE-2026-75899
|
||||
purls:
|
||||
- "pkg:npm/fast-uri"
|
||||
expired_at: 2027-01-31
|
||||
- id: CVE-2026-75975
|
||||
purls:
|
||||
- "pkg:npm/fast-uri"
|
||||
expired_at: 2027-01-31
|
||||
- id: CVE-2026-76172
|
||||
purls:
|
||||
- "pkg:npm/fast-uri"
|
||||
expired_at: 2027-01-31
|
||||
- id: CVE-2026-69192
|
||||
purls:
|
||||
- "pkg:npm/ip-address"
|
||||
@@ -148,6 +160,62 @@ vulnerabilities:
|
||||
- "pkg:golang/github.com/go-git/go-git/v5"
|
||||
expired_at: 2026-09-15
|
||||
|
||||
# CVE-2026-84304 is a DoS in grpc-go <= 1.83.0: a peer fragments a gRPC stream into
|
||||
# millions of tiny HTTP/2 DATA frames until the receiver runs out of heap. Fixed in
|
||||
# 1.83.1 (published 2026-09-01). Trivy 0.74.0, the latest published release and the
|
||||
# version the images ship, pins 1.82.1 as an indirect dependency:
|
||||
# https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod
|
||||
# Upstream bump still open: https://github.com/aquasecurity/trivy/pull/11176
|
||||
# Trivy only speaks gRPC in client/server mode (`trivy server`, `--server`). Prowler
|
||||
# invokes it exclusively as `trivy image` and `trivy fs` on a local path, so no gRPC
|
||||
# listener or connection ever exists in the image and the affected path is not
|
||||
# reachable. Remove this temporary suppression as soon as a Trivy release pins
|
||||
# grpc >= 1.83.1.
|
||||
- id: CVE-2026-84304
|
||||
purls:
|
||||
- "pkg:golang/google.golang.org/grpc"
|
||||
expired_at: 2026-10-15
|
||||
|
||||
# CVE-2026-84445 is a DoS in grpc-go servers built with `xds.NewGRPCServer()`: a request
|
||||
# carrying neither `:authority` nor `Host` reaches the xDS routing interceptor, which
|
||||
# indexes an empty slice of authorities and panics. The per-RPC goroutine does not
|
||||
# recover, so the whole server process dies. Fixed in 1.82.2 and 1.83.2 (published
|
||||
# 2026-09-08). Trivy 0.74.0, the latest published release and the version the images
|
||||
# ship, pins 1.82.1 as an indirect dependency:
|
||||
# https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod
|
||||
# Trivy main already carries 1.83.2, but no published release includes it yet.
|
||||
# The reachability argument is the one made for CVE-2026-84304 above, only narrower:
|
||||
# this panic needs an xDS-managed gRPC server. Prowler invokes Trivy exclusively as
|
||||
# `trivy image` and `trivy fs` on a local path, never `trivy server`, so the image runs
|
||||
# no gRPC server at all, xDS or otherwise. Remove this temporary suppression as soon as
|
||||
# a Trivy release pins grpc >= 1.83.2.
|
||||
# https://github.com/advisories/GHSA-2v4p-qf9q-27wj
|
||||
- id: CVE-2026-84445
|
||||
purls:
|
||||
- "pkg:golang/google.golang.org/grpc@v1.82.1"
|
||||
expired_at: 2026-10-15
|
||||
|
||||
# CVE-2026-56855 and CVE-2026-78662 are DoS deadlocks in x/crypto/ssh: a malicious peer
|
||||
# can flood or misuse channel messages (RFC 4254) to block the whole connection.
|
||||
# Fixed in golang.org/x/crypto v0.56.0 (published 2026-09-02). Trivy 0.74.0, the latest
|
||||
# published release and the version the images ship, still pins v0.55.0, and Trivy main
|
||||
# has not bumped it either:
|
||||
# https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod
|
||||
# x/crypto/ssh is pulled in transitively through go-git's ssh transport, the same
|
||||
# dependency chain as the CVE-2026-71556 entry above. Prowler invokes Trivy only with
|
||||
# `fs` on an existing local path or with `image`; it never asks Trivy to clone over SSH
|
||||
# or to run `trivy server`, so no SSH connection -- as client or server -- ever exists in
|
||||
# the image and the affected code path is not reachable. Remove this temporary
|
||||
# suppression as soon as a fixed Trivy release is available.
|
||||
- id: CVE-2026-56855
|
||||
purls:
|
||||
- "pkg:golang/golang.org/x/crypto@v0.55.0"
|
||||
expired_at: 2026-10-15
|
||||
- id: CVE-2026-78662
|
||||
purls:
|
||||
- "pkg:golang/golang.org/x/crypto@v0.55.0"
|
||||
expired_at: 2026-10-15
|
||||
|
||||
- id: CVE-2026-56852
|
||||
purls:
|
||||
- "pkg:golang/golang.org/x/text"
|
||||
|
||||
+2
-2
@@ -45,7 +45,7 @@ dependencies = [
|
||||
"gunicorn==26.0.0",
|
||||
"uvloop==0.22.1",
|
||||
"lxml==6.1.0",
|
||||
"prowler @ git+https://github.com/prowler-cloud/prowler.git@master",
|
||||
"prowler @ git+https://github.com/prowler-cloud/prowler.git@v5.41",
|
||||
"psycopg2-binary==2.9.9",
|
||||
"pytest-celery[redis] (==1.3.0)",
|
||||
"sentry-sdk[django] (==2.56.0)",
|
||||
@@ -71,7 +71,7 @@ name = "prowler-api"
|
||||
package-mode = false
|
||||
# Needed for the SDK compatibility
|
||||
requires-python = ">=3.11,<3.13"
|
||||
version = "1.42.0"
|
||||
version = "1.42.1"
|
||||
|
||||
# Shared ruff baseline (kept in sync with mcp_server/pyproject.toml).
|
||||
# target-version tracks this project's lowest supported Python.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
openapi: 3.0.3
|
||||
info:
|
||||
title: Prowler API
|
||||
version: 1.42.0
|
||||
version: 1.42.1
|
||||
description: |-
|
||||
Prowler API specification.
|
||||
|
||||
|
||||
Generated
+3
-3
@@ -4836,7 +4836,7 @@ wheels = [
|
||||
[[package]]
|
||||
name = "prowler"
|
||||
version = "5.41.0"
|
||||
source = { git = "https://github.com/prowler-cloud/prowler.git?rev=master#f05a490cd74a2c0f11a5d66d8ce29d03fa5c64a2" }
|
||||
source = { git = "https://github.com/prowler-cloud/prowler.git?rev=v5.41#18453e592e0a2550c726a754fda79870de428abf" }
|
||||
dependencies = [
|
||||
{ name = "alibabacloud-actiontrail20200706" },
|
||||
{ name = "alibabacloud-credentials" },
|
||||
@@ -4938,7 +4938,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "prowler-api"
|
||||
version = "1.42.0"
|
||||
version = "1.42.1"
|
||||
source = { virtual = "." }
|
||||
dependencies = [
|
||||
{ name = "cartography" },
|
||||
@@ -5038,7 +5038,7 @@ requires-dist = [
|
||||
{ name = "matplotlib", specifier = "==3.10.8" },
|
||||
{ name = "neo4j", specifier = "==6.1.0" },
|
||||
{ name = "openai", specifier = "==1.109.1" },
|
||||
{ name = "prowler", git = "https://github.com/prowler-cloud/prowler.git?rev=master" },
|
||||
{ name = "prowler", git = "https://github.com/prowler-cloud/prowler.git?rev=v5.41" },
|
||||
{ name = "psycopg2-binary", specifier = "==2.9.9" },
|
||||
{ name = "pytest-celery", extras = ["redis"], specifier = "==1.3.0" },
|
||||
{ name = "reportlab", specifier = "==4.4.10" },
|
||||
|
||||
@@ -32,6 +32,8 @@ LABEL maintainer="https://github.com/prowler-cloud"
|
||||
# High CVEs fixed in Alpine 3.23 but not yet in the pinned base image:
|
||||
# sqlite-libs 3.53.4-r0 CVE-2026-11822, CVE-2026-11824 (image ships 3.51.2-r0)
|
||||
# libcrypto3/libssl3 3.5.8-r0 CVE-2026-14456 (image ships 3.5.7-r0)
|
||||
# libuuid 2.41.6-r1 CVE-2026-53612, -53613, -53614, -76642, -78408, -78410
|
||||
# (image ships 2.41.4-r0; -78408 is the one that needs -r1 rather than -r0)
|
||||
# The base image pins python 3.13.14, which has not been rebuilt since those
|
||||
# packages were published, so the upgrade is taken here rather than by moving
|
||||
# the pin -- the newest published python:3.13-alpine3.23 carries the same
|
||||
@@ -43,7 +45,8 @@ LABEL maintainer="https://github.com/prowler-cloud"
|
||||
RUN apk add --no-cache --upgrade \
|
||||
"sqlite-libs>=3.53.4-r0" \
|
||||
"libcrypto3>=3.5.8-r0" \
|
||||
"libssl3>=3.5.8-r0"
|
||||
"libssl3>=3.5.8-r0" \
|
||||
"libuuid>=2.41.6-r1"
|
||||
|
||||
# Create non-root user for security
|
||||
# Using specific UID/GID for consistency across environments
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
`libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410
|
||||
@@ -0,0 +1 @@
|
||||
Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test
|
||||
@@ -0,0 +1 @@
|
||||
`Jira.test_connection()` now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection
|
||||
@@ -0,0 +1 @@
|
||||
Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal
|
||||
@@ -0,0 +1 @@
|
||||
Duplicate requirement `3.2.1` in ProwlerThreatScore for Azure (SQL auditing retention is now `3.2.4`) and doubled check id in requirement `1.2.1` of ProwlerThreatScore for GCP
|
||||
@@ -277,7 +277,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"guardduty_is_enabled",
|
||||
"guardduty_is_enabled"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -497,7 +496,7 @@
|
||||
"Checks": []
|
||||
},
|
||||
{
|
||||
"Id": "Create Cost Anomaly Detection monitors to alert spending anomalies",
|
||||
"Id": "Create Cost Anomaly Detection monitors to alert spending anomalies (Prod)",
|
||||
"Description": "Develop monitoring systems for detecting cost anomalies and generating alerts for irregular spending patterns.",
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -510,7 +509,7 @@
|
||||
"Checks": []
|
||||
},
|
||||
{
|
||||
"Id": "Create Cost Anomaly Detection monitors to alert spending anomalies",
|
||||
"Id": "Create Cost Anomaly Detection monitors to alert spending anomalies (QA)",
|
||||
"Description": "Establish monitoring systems for cost anomaly detection to promptly notify about unusual spending patterns.",
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -618,7 +617,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "Export scan results as metrics in centralized collector",
|
||||
"Id": "Export scan results as metrics in centralized collector (EC2)",
|
||||
"Description": "Export scan results as metrics to a centralized collector.",
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -667,7 +666,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "Export scan results as metrics in centralized collector",
|
||||
"Id": "Export scan results as metrics in centralized collector (ECR)",
|
||||
"Description": "Generate metric data from scan results and store it in a centralized collector.",
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -1189,7 +1188,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "Export metrics in centralized collector",
|
||||
"Id": "Export metrics in centralized collector (Shield Advanced)",
|
||||
"Description": "Exporting metrics to a centralized collector for data aggregation and analysis.",
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -1367,7 +1366,7 @@
|
||||
"Checks": []
|
||||
},
|
||||
{
|
||||
"Id": "Export metrics in centralized collector",
|
||||
"Id": "Export metrics in centralized collector (WAFv2)",
|
||||
"Description": "Exporting metrics to a centralized collector for comprehensive data aggregation.",
|
||||
"Attributes": [
|
||||
{
|
||||
|
||||
@@ -334,7 +334,6 @@
|
||||
"iam_role_cross_service_confused_deputy_prevention",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_user_hardware_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_administrator_access_with_mfa"
|
||||
|
||||
@@ -472,11 +472,9 @@
|
||||
"emr_cluster_publicly_accesible",
|
||||
"glacier_vaults_policy_public_access",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"rds_instance_no_public_access",
|
||||
"rds_snapshots_public_access",
|
||||
"kms_key_not_publicly_accessible",
|
||||
"opensearch_service_domains_not_publicly_accessible",
|
||||
"redshift_cluster_public_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
@@ -493,7 +491,6 @@
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"elb_internet_facing",
|
||||
"elbv2_internet_facing",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"sns_topics_not_publicly_accessible",
|
||||
"sqs_queues_not_publicly_accessible",
|
||||
"ssm_documents_set_as_public",
|
||||
@@ -553,7 +550,6 @@
|
||||
"awslambda_function_invoke_api_operations_cloudtrail_logging_enabled",
|
||||
"cloudfront_distributions_logging_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_logs_s3_bucket_access_logging_enabled",
|
||||
"directoryservice_directory_log_forwarding_enabled",
|
||||
"eks_control_plane_logging_all_types_enabled",
|
||||
@@ -771,7 +767,6 @@
|
||||
"ec2_securitygroup_not_used",
|
||||
"ec2_securitygroup_with_many_ingress_egress_rules",
|
||||
"elbv2_desync_mitigation_mode",
|
||||
"elbv2_desync_mitigation_mode",
|
||||
"route53_domains_privacy_protection_enabled",
|
||||
"route53_domains_transferlock_enabled",
|
||||
"shield_advanced_protection_in_associated_elastic_ips",
|
||||
|
||||
@@ -268,7 +268,6 @@
|
||||
"iam_role_administratoraccess_policy",
|
||||
"iam_aws_attached_policy_no_administrative_privileges",
|
||||
"iam_customer_unattached_policy_no_administrative_privileges",
|
||||
"iam_role_administratoraccess_policy",
|
||||
"iam_user_administrator_access_policy",
|
||||
"organizations_delegated_administrators",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
@@ -1936,9 +1935,7 @@
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled",
|
||||
"cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled"
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -3866,7 +3863,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"acm_certificates_transparency_logs_enabled",
|
||||
"acm_certificates_transparency_logs_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"apigatewayv2_api_access_logging_enabled",
|
||||
@@ -3945,7 +3941,6 @@
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_hardware_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"s3_bucket_no_mfa_delete"
|
||||
]
|
||||
},
|
||||
@@ -5219,8 +5214,6 @@
|
||||
"iam_customer_unattached_policy_no_administrative_privileges",
|
||||
"iam_group_administrator_access_policy",
|
||||
"iam_inline_policy_no_administrative_privileges",
|
||||
"iam_policy_cloudshell_admin_not_attached",
|
||||
"iam_role_administratoraccess_policy",
|
||||
"iam_user_administrator_access_policy",
|
||||
"organizations_delegated_administrators",
|
||||
"rds_cluster_default_admin",
|
||||
@@ -5291,8 +5284,6 @@
|
||||
"iam_customer_unattached_policy_no_administrative_privileges",
|
||||
"iam_group_administrator_access_policy",
|
||||
"iam_inline_policy_no_administrative_privileges",
|
||||
"iam_policy_cloudshell_admin_not_attached",
|
||||
"iam_role_administratoraccess_policy",
|
||||
"iam_user_administrator_access_policy",
|
||||
"organizations_delegated_administrators",
|
||||
"rds_cluster_default_admin",
|
||||
@@ -6357,8 +6348,7 @@
|
||||
],
|
||||
"Checks": [
|
||||
"cognito_user_pool_blocks_compromised_credentials_sign_in_attempts",
|
||||
"cognito_user_pool_blocks_potential_malicious_sign_in_attempts",
|
||||
"cognito_user_pool_blocks_compromised_credentials_sign_in_attempts"
|
||||
"cognito_user_pool_blocks_potential_malicious_sign_in_attempts"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -6670,7 +6660,6 @@
|
||||
"sagemaker_training_jobs_intercontainer_encryption_enabled",
|
||||
"sagemaker_training_jobs_volume_and_output_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"sqs_queues_server_side_encryption_enabled",
|
||||
"storagegateway_fileshare_encryption_enabled",
|
||||
"transfer_server_in_transit_encryption_enabled",
|
||||
"workspaces_volume_encryption_enabled"
|
||||
@@ -7696,13 +7685,11 @@
|
||||
"dynamodb_accelerator_cluster_in_transit_encryption_enabled",
|
||||
"transfer_server_in_transit_encryption_enabled",
|
||||
"dms_endpoint_redis_in_transit_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_in_transit_encryption_enabled",
|
||||
"ec2_transitgateway_auto_accept_vpc_attachments",
|
||||
"elasticache_redis_cluster_in_transit_encryption_enabled",
|
||||
"kafka_cluster_in_transit_encryption_enabled",
|
||||
"kafka_connector_in_transit_encryption_enabled",
|
||||
"redshift_cluster_in_transit_encryption_enabled",
|
||||
"transfer_server_in_transit_encryption_enabled"
|
||||
"redshift_cluster_in_transit_encryption_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -10967,7 +10954,6 @@
|
||||
"kms_cmk_not_multi_region",
|
||||
"cloudfront_distributions_geo_restrictions_enabled",
|
||||
"cloudtrail_multi_region_enabled_logging_management_events",
|
||||
"kms_cmk_not_multi_region",
|
||||
"organizations_scp_check_deny_regions",
|
||||
"s3_multi_region_access_point_public_access_block"
|
||||
]
|
||||
|
||||
@@ -204,7 +204,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "1.1",
|
||||
"Id": "1.10",
|
||||
"Description": "Do not create access keys during initial setup for IAM users with a console password",
|
||||
"Checks": [
|
||||
"iam_user_no_setup_initial_access_key"
|
||||
|
||||
@@ -58,14 +58,12 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"codebuild_project_user_controlled_buildspec",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_public_snapshot",
|
||||
"ec2_ebs_default_encryption",
|
||||
@@ -85,7 +83,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_no_custom_policy_permissive_role_assumption",
|
||||
@@ -97,23 +94,18 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"kms_cmk_rotation_enabled",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_enhanced_monitoring_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_no_public_access",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_snapshots_public_access",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -125,7 +117,6 @@
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_object_versioning",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_training_jobs_volume_and_output_encryption_enabled",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
@@ -222,7 +213,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase"
|
||||
]
|
||||
@@ -246,7 +236,6 @@
|
||||
"ec2_ebs_default_encryption",
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_training_jobs_volume_and_output_encryption_enabled",
|
||||
@@ -273,7 +262,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
@@ -289,18 +277,14 @@
|
||||
"opensearch_service_domains_cloudwatch_logging_enabled",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"rds_instance_no_public_access",
|
||||
"rds_snapshots_public_access",
|
||||
"rds_snapshots_public_access",
|
||||
"redshift_cluster_audit_logging",
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_server_access_logging_enabled",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
@@ -349,7 +333,6 @@
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -409,11 +392,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -432,8 +413,7 @@
|
||||
"Checks": [
|
||||
"iam_user_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_hardware_mfa_enabled"
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -34,9 +34,7 @@
|
||||
"config_recorder_all_regions_enabled",
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ec2_instance_older_than_specific_days",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_instance_compliance_association_compliant",
|
||||
"ssm_managed_instance_compliance_patch_compliant"
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -63,7 +61,7 @@
|
||||
"autoscaling_group_multiple_instance_types",
|
||||
"autoscaling_group_capacity_rebalance_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_deletion_protection_enabled",
|
||||
"dynamodb_table_deletion_protection_enabled",
|
||||
"ec2_instance_imdsv2_enabled",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
@@ -73,13 +71,12 @@
|
||||
"eks_cluster_private_nodes_enabled",
|
||||
"eks_cluster_uses_a_supported_version",
|
||||
"elb_cross_zone_load_balancing_enabled",
|
||||
"elbv2_alb_multi_az_scheme",
|
||||
"elbv2_is_in_multiple_az",
|
||||
"elbv2_waf_acl_attached",
|
||||
"rds_instance_multi_az",
|
||||
"rds_cluster_multi_az",
|
||||
"vpc_subnet_auto_assign_public_ip_disabled",
|
||||
"vpc_default_security_group_restricts_traffic",
|
||||
"vpc_peering_connection_routing_tables_with_least_privilege",
|
||||
"vpc_subnet_no_public_ip_by_default",
|
||||
"vpc_peering_routing_tables_with_least_privilege",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced"
|
||||
]
|
||||
},
|
||||
@@ -143,11 +140,9 @@
|
||||
"guardduty_centrally_managed",
|
||||
"guardduty_ec2_malware_protection_enabled",
|
||||
"guardduty_eks_audit_log_enabled",
|
||||
"guardduty_eks_protection_enabled",
|
||||
"guardduty_eks_runtime_monitoring_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"guardduty_lambda_protection_enabled",
|
||||
"guardduty_malware_protection_enabled",
|
||||
"guardduty_no_high_severity_findings",
|
||||
"guardduty_rds_protection_enabled",
|
||||
"guardduty_s3_protection_enabled",
|
||||
@@ -193,7 +188,7 @@
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"ecs_cluster_container_insights_enabled",
|
||||
"eks_cluster_control_plane_audit_logging_enabled",
|
||||
"eks_control_plane_logging_all_types_enabled",
|
||||
"elb_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"inspector2_is_enabled",
|
||||
@@ -227,8 +222,7 @@
|
||||
"organizations_delegated_administrators",
|
||||
"organizations_scp_check_deny_regions",
|
||||
"organizations_tags_policies_enabled_and_attached",
|
||||
"resourceexplorer_indexes_found",
|
||||
"ssm_managed_instance_compliance_association_compliant",
|
||||
"resourceexplorer2_indexes_found",
|
||||
"trustedadvisor_premium_support_plan_subscribed"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -257,15 +251,12 @@
|
||||
"backup_vaults_exist",
|
||||
"backup_vaults_encrypted",
|
||||
"backup_recovery_point_encrypted",
|
||||
"backup_recovery_point_manual_deletion_disabled",
|
||||
"backup_recovery_point_minimum_retention_days",
|
||||
"dlm_ebs_snapshot_lifecycle_policy_exists",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_deletion_protection_enabled",
|
||||
"dynamodb_table_deletion_protection_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"fsx_file_system_copy_tags_to_backups",
|
||||
"fsx_file_system_copy_tags_to_backups_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_retention_policy",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_cluster_deletion_protection",
|
||||
"rds_snapshots_encrypted",
|
||||
@@ -287,33 +278,28 @@
|
||||
"acm_certificates_expiration_check",
|
||||
"apigateway_restapi_cache_encrypted",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dax_cluster_encryption_enabled",
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_table_encryption_uses_cmks",
|
||||
"ebs_volume_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_default_encryption",
|
||||
"ec2_instance_ebs_optimized",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"eks_cluster_envelope_encryption_enabled",
|
||||
"elasticache_redis_cluster_encryption_at_rest_enabled",
|
||||
"elasticache_redis_cluster_encryption_at_transit_enabled",
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"elasticache_redis_cluster_rest_encryption_enabled",
|
||||
"elasticache_redis_cluster_in_transit_encryption_enabled",
|
||||
"elbv2_ssl_listeners",
|
||||
"fsx_file_system_encryption_at_rest_enabled",
|
||||
"kinesis_stream_encrypted_at_rest",
|
||||
"kms_cmk_rotation_enabled",
|
||||
"kms_cmk_not_scheduled_for_deletion",
|
||||
"kms_cmk_not_deleted_unintentionally",
|
||||
"kms_key_not_publicly_accessible",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted_with_cmk",
|
||||
"rds_cluster_storage_encrypted",
|
||||
"redshift_cluster_encryption_at_rest",
|
||||
"redshift_cluster_encryption_in_transit",
|
||||
"s3_bucket_server_side_encryption_enabled",
|
||||
"redshift_cluster_encrypted_at_rest",
|
||||
"redshift_cluster_in_transit_encryption_enabled",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"sqs_queue_server_side_encryption_enabled",
|
||||
"sqs_queues_server_side_encryption_enabled",
|
||||
"kms_key_enclave_attestation_not_enforced"
|
||||
]
|
||||
},
|
||||
@@ -332,7 +318,7 @@
|
||||
"ecr_registry_scan_images_on_push_enabled",
|
||||
"ecr_repositories_lifecycle_policy_enabled",
|
||||
"ecr_repositories_not_publicly_accessible",
|
||||
"ecr_repositories_scan_on_push_enabled",
|
||||
"ecr_repositories_scan_images_on_push_enabled",
|
||||
"ecr_repositories_scan_vulnerabilities_in_latest_image",
|
||||
"ecr_repositories_tag_immutability",
|
||||
"inspector2_active_findings_exist",
|
||||
@@ -382,7 +368,7 @@
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"config_recorder_all_regions_enabled",
|
||||
"inspector2_is_enabled",
|
||||
"resourceexplorer_indexes_found"
|
||||
"resourceexplorer2_indexes_found"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
|
||||
@@ -21,7 +21,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"opensearch_service_domains_cloudwatch_logging_enabled",
|
||||
@@ -127,8 +126,7 @@
|
||||
"securityhub_enabled",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -161,7 +159,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
@@ -226,7 +223,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"ec2_instance_imdsv2_enabled",
|
||||
"elbv2_waf_acl_attached",
|
||||
@@ -276,13 +272,11 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -299,7 +293,6 @@
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"guardduty_is_enabled",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -323,11 +316,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -344,13 +335,11 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -371,7 +360,6 @@
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_no_root_access_key",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -482,12 +470,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -29,7 +29,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -68,7 +67,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -149,7 +147,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -174,7 +171,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"opensearch_service_domains_cloudwatch_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -220,7 +216,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -312,7 +307,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"kms_key_enclave_attestation_not_enforced"
|
||||
@@ -345,7 +339,6 @@
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -426,7 +419,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"kms_key_enclave_attestation_bypassable_path"
|
||||
@@ -457,13 +449,11 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"securityhub_enabled",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -521,10 +511,8 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
]
|
||||
},
|
||||
@@ -545,7 +533,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -572,7 +559,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -599,7 +585,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -723,7 +708,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -750,7 +734,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
@@ -804,13 +787,11 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -863,7 +844,6 @@
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"guardduty_is_enabled",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -888,11 +868,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -909,13 +887,11 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -935,7 +911,6 @@
|
||||
"Checks": [
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_root_hardware_mfa_enabled"
|
||||
]
|
||||
},
|
||||
@@ -954,7 +929,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -1056,42 +1030,6 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "ir-4-1",
|
||||
"Name": "IR-4(1) Automated Incident Handling Processes",
|
||||
"Description": "The organization employs automated mechanisms to support the incident handling process.",
|
||||
"Attributes": [
|
||||
{
|
||||
"ItemId": "ir-4-1",
|
||||
"Section": "Incident Response (IR)",
|
||||
"SubSection": "Incident Handling (IR-4)",
|
||||
"Service": "aws"
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"guardduty_is_enabled",
|
||||
"guardduty_no_high_severity_findings",
|
||||
"securityhub_enabled"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
"Check": "guardduty_is_enabled",
|
||||
"ConfigKey": "mute_non_default_regions",
|
||||
"Operator": "eq",
|
||||
"Value": false
|
||||
},
|
||||
{
|
||||
"Check": "securityhub_enabled",
|
||||
"ConfigKey": "mute_non_default_regions",
|
||||
"Operator": "eq",
|
||||
"Value": false
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "ir-6-1",
|
||||
"Name": "IR-6(1) Automated Reporting",
|
||||
@@ -1266,12 +1204,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1326,12 +1262,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -1362,12 +1296,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -1485,15 +1417,12 @@
|
||||
"Checks": [
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"kms_key_enclave_debug_attestation_detected"
|
||||
@@ -1513,7 +1442,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -1557,7 +1485,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"redshift_cluster_audit_logging",
|
||||
"securityhub_enabled"
|
||||
@@ -1593,7 +1520,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
@@ -1636,7 +1562,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
@@ -1677,7 +1602,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
@@ -1790,10 +1714,8 @@
|
||||
"Checks": [
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
|
||||
@@ -60,7 +60,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"redshift_cluster_automated_snapshot"
|
||||
@@ -115,7 +114,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -145,7 +143,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -365,7 +362,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -392,7 +388,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -437,7 +432,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -571,8 +565,7 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -716,7 +709,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_aws_attached_policy_no_administrative_privileges",
|
||||
@@ -726,7 +718,6 @@
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused"
|
||||
]
|
||||
@@ -747,7 +738,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase"
|
||||
]
|
||||
@@ -795,12 +785,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -820,8 +808,7 @@
|
||||
"elbv2_waf_acl_attached",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -859,7 +846,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -879,7 +865,6 @@
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_vsock_proxy_exposed"
|
||||
]
|
||||
},
|
||||
@@ -933,8 +918,7 @@
|
||||
"Checks": [
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1002,7 +986,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -1066,7 +1049,6 @@
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -30,12 +30,6 @@
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_password_policy_reuse_24",
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_aws_attached_policy_no_administrative_privileges",
|
||||
"iam_customer_attached_policy_no_administrative_privileges",
|
||||
"iam_inline_policy_no_administrative_privileges",
|
||||
@@ -85,7 +79,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"config_recorder_all_regions_enabled",
|
||||
@@ -122,8 +115,6 @@
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"elb_ssl_listeners",
|
||||
@@ -133,11 +124,9 @@
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
|
||||
@@ -24,11 +24,9 @@
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -47,7 +45,6 @@
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_snapshots_public_access",
|
||||
"redshift_cluster_audit_logging",
|
||||
"redshift_cluster_public_access",
|
||||
@@ -80,7 +77,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_policy_attached_only_to_group_or_roles",
|
||||
@@ -92,7 +88,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
@@ -103,13 +98,11 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"secretsmanager_automatic_rotation_enabled",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
@@ -130,7 +123,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -168,7 +160,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_policy_attached_only_to_group_or_roles",
|
||||
@@ -180,7 +171,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
@@ -191,13 +181,11 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"secretsmanager_automatic_rotation_enabled",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
@@ -215,7 +203,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -246,7 +233,6 @@
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
]
|
||||
},
|
||||
@@ -280,10 +266,8 @@
|
||||
"kms_cmk_rotation_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
@@ -304,14 +288,12 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -330,7 +312,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_rotate_access_key_90_days",
|
||||
|
||||
@@ -41,12 +41,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -66,7 +63,6 @@
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_default_encryption",
|
||||
@@ -76,12 +72,9 @@
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_object_versioning",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
@@ -101,10 +94,7 @@
|
||||
"Checks": [
|
||||
"rds_instance_backup_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -192,12 +182,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -215,12 +201,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -299,12 +281,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
|
||||
@@ -70,7 +70,6 @@
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_snapshots_public_access",
|
||||
"redshift_cluster_audit_logging",
|
||||
"redshift_cluster_public_access",
|
||||
@@ -85,7 +84,6 @@
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -106,7 +104,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
@@ -179,14 +176,12 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_server_access_logging_enabled",
|
||||
"securityhub_enabled",
|
||||
@@ -276,8 +271,6 @@
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_default_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
@@ -289,11 +282,9 @@
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
]
|
||||
@@ -353,7 +344,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -463,7 +453,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -502,14 +491,10 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -526,14 +511,10 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -550,14 +531,10 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -574,14 +551,10 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -642,7 +615,6 @@
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_public_ip",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
@@ -679,12 +651,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -705,7 +673,6 @@
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_default_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
@@ -714,10 +681,8 @@
|
||||
"kms_cmk_rotation_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
@@ -741,7 +706,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
@@ -828,7 +792,6 @@
|
||||
"iam_password_policy_reuse_24",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -852,7 +815,6 @@
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress",
|
||||
"ec2_confidential_workload_host_vsock_proxy_exposed"
|
||||
]
|
||||
@@ -872,7 +834,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elb_ssl_listeners",
|
||||
"guardduty_is_enabled",
|
||||
@@ -910,7 +871,6 @@
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"ec2_ebs_default_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
@@ -919,10 +879,8 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
|
||||
@@ -259,16 +259,7 @@
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"iam_no_root_access_key",
|
||||
"iam_password_policy_expires_passwords_within_90_days_or_less",
|
||||
"iam_password_policy_reuse_24",
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_password_policy_number",
|
||||
"iam_password_policy_symbol",
|
||||
"iam_password_policy_lowercase",
|
||||
"iam_password_policy_uppercase",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_rotate_access_key_90_days"
|
||||
"iam_no_root_access_key"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -997,11 +988,9 @@
|
||||
"emr_cluster_publicly_accesible",
|
||||
"glacier_vaults_policy_public_access",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"rds_instance_no_public_access",
|
||||
"rds_snapshots_public_access",
|
||||
"kms_key_not_publicly_accessible",
|
||||
"opensearch_service_domains_not_publicly_accessible",
|
||||
"redshift_cluster_public_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
@@ -1018,7 +1007,6 @@
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"elb_internet_facing",
|
||||
"elbv2_internet_facing",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"sns_topics_not_publicly_accessible",
|
||||
"sqs_queues_not_publicly_accessible",
|
||||
"ssm_documents_set_as_public",
|
||||
@@ -1091,11 +1079,10 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"codebuild_project_artifact_encryption",
|
||||
"codebuild_project_envvar_awscred_check",
|
||||
"codebuild_project_no_secrets_in_variables",
|
||||
"codebuild_project_logging_enabled",
|
||||
"codebuild_project_older_90_days",
|
||||
"codebuild_project_source_repo_url_check",
|
||||
"codebuild_project_source_repo_url_no_sensitive_credentials",
|
||||
"codebuild_project_user_controlled_buildspec"
|
||||
]
|
||||
},
|
||||
@@ -1378,7 +1365,6 @@
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"apigatewayv2_api_access_logging_enabled",
|
||||
"appsync_field_level_logging_enabled",
|
||||
"athena_workgroup_logging_enabled",
|
||||
"awslambda_function_invoke_api_operations_cloudtrail_logging_enabled",
|
||||
"bedrock_model_invocation_logging_enabled",
|
||||
"bedrock_model_invocation_logs_encryption_enabled",
|
||||
@@ -1631,7 +1617,6 @@
|
||||
"ec2_securitygroup_from_launch_wizard",
|
||||
"ec2_securitygroup_not_used",
|
||||
"ec2_securitygroup_with_many_ingress_egress_rules",
|
||||
"ec2_transitgateway_auto_accept_vpc_attachments",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"ec2_confidential_workload_host_public_ip",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress",
|
||||
@@ -1730,7 +1715,6 @@
|
||||
"ec2_securitygroup_from_launch_wizard",
|
||||
"ec2_securitygroup_not_used",
|
||||
"ec2_securitygroup_with_many_ingress_egress_rules",
|
||||
"ec2_transitgateway_auto_accept_vpc_attachments",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"ec2_confidential_workload_host_public_ip",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress"
|
||||
@@ -1828,7 +1812,6 @@
|
||||
"ec2_securitygroup_from_launch_wizard",
|
||||
"ec2_securitygroup_not_used",
|
||||
"ec2_securitygroup_with_many_ingress_egress_rules",
|
||||
"ec2_transitgateway_auto_accept_vpc_attachments",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"ec2_confidential_workload_host_public_ip",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress"
|
||||
@@ -1847,7 +1830,7 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"vpc_default_security_group_closed",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"vpc_flow_logs_enabled",
|
||||
"securityhub_enabled"
|
||||
],
|
||||
@@ -1931,9 +1914,6 @@
|
||||
"storagegateway_fileshare_encryption_enabled",
|
||||
"transfer_server_in_transit_encryption_enabled",
|
||||
"workspaces_volume_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"kafka_cluster_encryption_at_rest_uses_cmk",
|
||||
"kms_cmk_are_used",
|
||||
"kms_cmk_not_deleted_unintentionally",
|
||||
"kms_cmk_not_multi_region",
|
||||
|
||||
@@ -2603,7 +2603,6 @@
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"codebuild_project_logging_enabled",
|
||||
@@ -2793,7 +2792,6 @@
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_cross_account_sharing_disabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_not_publicly_accessible",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
@@ -2991,7 +2989,6 @@
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_cross_account_sharing_disabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_not_publicly_accessible",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
|
||||
@@ -2606,7 +2606,6 @@
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
"cloudwatch_changes_to_network_route_tables_alarm_configured",
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"codebuild_project_logging_enabled",
|
||||
@@ -2796,7 +2795,6 @@
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_cross_account_sharing_disabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_not_publicly_accessible",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
@@ -2994,7 +2992,6 @@
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_cross_account_sharing_disabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_no_critical_pii_in_logs",
|
||||
"cloudwatch_log_group_no_secrets_in_logs",
|
||||
"cloudwatch_log_group_not_publicly_accessible",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
|
||||
@@ -326,7 +326,6 @@
|
||||
"cloudwatch_changes_to_vpcs_alarm_configured",
|
||||
"cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled",
|
||||
"cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled",
|
||||
"cloudwatch_log_metric_filter_aws_organizations_changes",
|
||||
"cloudwatch_log_metric_filter_for_s3_bucket_policy_changes",
|
||||
"cloudwatch_log_metric_filter_policy_changes",
|
||||
"cloudwatch_log_metric_filter_security_group_changes"
|
||||
|
||||
@@ -29,7 +29,6 @@
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_no_root_access_key",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -46,8 +45,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -74,7 +72,6 @@
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_no_root_access_key",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -91,8 +88,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -122,8 +118,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -223,7 +218,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -286,8 +280,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -305,8 +298,7 @@
|
||||
"s3_account_level_public_access_blocks",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -325,7 +317,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -367,7 +358,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
@@ -398,7 +388,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"s3_bucket_server_access_logging_enabled",
|
||||
@@ -571,7 +560,6 @@
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_vsock_proxy_exposed"
|
||||
]
|
||||
},
|
||||
@@ -604,7 +592,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -622,7 +609,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -928,7 +914,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_log_file_validation_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -944,8 +929,7 @@
|
||||
"securityhub_enabled",
|
||||
"vpc_flow_logs_enabled",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -988,7 +972,6 @@
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_no_public_access",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
@@ -1060,7 +1043,6 @@
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -1077,8 +1059,7 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1155,7 +1136,6 @@
|
||||
"Checks": [
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
@@ -1212,7 +1192,6 @@
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"guardduty_is_enabled",
|
||||
"securityhub_enabled",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -1300,7 +1279,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -1340,7 +1318,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
|
||||
@@ -108,7 +108,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
@@ -239,8 +238,7 @@
|
||||
"redshift_cluster_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_public_access"
|
||||
"s3_bucket_policy_public_write_access"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -266,12 +264,10 @@
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -340,7 +336,6 @@
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -425,7 +420,6 @@
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -445,7 +439,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -471,7 +464,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -633,7 +625,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -746,7 +737,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -764,7 +754,6 @@
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled"
|
||||
]
|
||||
},
|
||||
@@ -784,7 +773,6 @@
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -804,7 +792,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -821,7 +808,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -840,7 +826,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -1101,8 +1086,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1135,8 +1119,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1237,7 +1220,6 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
@@ -1258,7 +1240,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -1513,7 +1494,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -28,7 +28,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -162,7 +161,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -201,7 +199,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -336,7 +333,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"kms_key_enclave_attestation_not_enforced"
|
||||
@@ -357,7 +353,6 @@
|
||||
"Checks": [
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
@@ -380,7 +375,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -408,7 +402,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -439,7 +432,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -470,7 +462,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -501,7 +492,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -532,7 +522,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -563,7 +552,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -594,7 +582,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -625,7 +612,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -655,7 +641,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -686,7 +671,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -710,7 +694,6 @@
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_no_root_access_key",
|
||||
"iam_root_mfa_enabled",
|
||||
@@ -748,7 +731,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -779,7 +761,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -810,7 +791,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -848,7 +828,6 @@
|
||||
"redshift_cluster_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -876,7 +855,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_role_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_bedrock",
|
||||
"iam_user_access_not_stale_to_sagemaker",
|
||||
@@ -901,7 +879,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -933,7 +910,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -988,7 +964,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -1019,7 +994,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -1050,7 +1024,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -1100,11 +1073,9 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -1144,7 +1115,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1178,7 +1148,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -1238,7 +1207,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_imdsv2_not_enforced",
|
||||
"kms_key_enclave_attestation_bypassable_path"
|
||||
@@ -1298,7 +1266,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -1340,7 +1307,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -1361,7 +1327,6 @@
|
||||
"iam_password_policy_minimum_length_14",
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -1405,12 +1370,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1437,12 +1400,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1488,10 +1449,8 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
]
|
||||
},
|
||||
@@ -1519,12 +1478,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1551,12 +1508,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1582,7 +1537,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -1624,7 +1578,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -1677,7 +1630,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1704,7 +1656,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1731,7 +1682,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1758,7 +1708,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1785,7 +1734,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1812,7 +1760,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1890,7 +1837,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -1918,7 +1864,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -1982,7 +1927,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2010,7 +1954,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2054,7 +1997,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -2120,7 +2062,6 @@
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
@@ -2160,7 +2101,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2219,7 +2159,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2247,7 +2186,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_bedrock_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2275,7 +2213,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2303,7 +2240,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -2331,7 +2267,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -2380,7 +2315,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -2407,7 +2341,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -2456,7 +2389,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -2505,7 +2437,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -2633,7 +2564,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -2882,7 +2812,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -2906,7 +2835,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -3045,7 +2973,6 @@
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"guardduty_is_enabled",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -3317,7 +3244,6 @@
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"rds_instance_backup_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -3432,7 +3358,6 @@
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning",
|
||||
@@ -3470,7 +3395,6 @@
|
||||
"Checks": [
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -3490,7 +3414,6 @@
|
||||
"Checks": [
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -3511,7 +3434,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -3533,7 +3455,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_automatic_upgrades",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -3555,7 +3476,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_automatic_upgrades",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -3577,7 +3497,6 @@
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"rds_instance_backup_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"redshift_cluster_automatic_upgrades",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -3603,10 +3522,8 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
]
|
||||
@@ -3625,7 +3542,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"rds_instance_storage_encrypted",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption"
|
||||
]
|
||||
},
|
||||
@@ -3644,7 +3560,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning",
|
||||
@@ -3667,7 +3582,6 @@
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -3702,7 +3616,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -3721,7 +3634,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -3740,7 +3652,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -3760,7 +3671,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -3779,7 +3689,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -3800,7 +3709,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -4040,23 +3948,6 @@
|
||||
"iam_password_policy_minimum_length_14"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "ia_5_1_h",
|
||||
"Name": "IA-5(1)(h)",
|
||||
"Description": "For password-based authentication: (h) Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].",
|
||||
"Attributes": [
|
||||
{
|
||||
"ItemId": "ia_5_1_h",
|
||||
"Section": "Identification and Authentication (IA)",
|
||||
"SubSection": "Authenticator Management (IA-5)",
|
||||
"SubGroup": "IA-5(1) Password-Based Authentication",
|
||||
"Service": "iam"
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"iam_password_policy_minimum_length_14"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "ia_5_8",
|
||||
"Name": "IA-5(8) Multiple System Accounts",
|
||||
@@ -4173,7 +4064,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -4214,7 +4104,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -4302,7 +4191,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -4351,7 +4239,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -4459,7 +4346,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_changes_to_network_acls_alarm_configured",
|
||||
"cloudwatch_changes_to_network_gateways_alarm_configured",
|
||||
@@ -4844,7 +4730,6 @@
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"redshift_cluster_automatic_upgrades",
|
||||
"s3_bucket_object_versioning"
|
||||
@@ -4987,7 +4872,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -5015,7 +4899,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
@@ -5078,7 +4961,6 @@
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress"
|
||||
]
|
||||
},
|
||||
@@ -5105,12 +4987,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5138,7 +5018,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -5160,7 +5039,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -5193,12 +5071,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_public_ip"
|
||||
]
|
||||
},
|
||||
@@ -5230,8 +5106,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5262,8 +5137,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5290,7 +5164,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -5318,12 +5191,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5351,12 +5222,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5382,7 +5251,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
@@ -5412,7 +5280,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
@@ -5442,7 +5309,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
@@ -5472,7 +5338,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
@@ -5503,12 +5368,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_confidential_workload_host_unrestricted_ingress"
|
||||
]
|
||||
},
|
||||
@@ -5536,7 +5399,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -5564,12 +5426,10 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -5657,10 +5517,8 @@
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
@@ -5690,10 +5548,8 @@
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
@@ -5792,10 +5648,8 @@
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled"
|
||||
@@ -5879,7 +5733,6 @@
|
||||
"iam_no_root_access_key",
|
||||
"iam_rotate_access_key_90_days",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_accesskey_unused",
|
||||
"iam_user_console_access_unused",
|
||||
"secretsmanager_automatic_rotation_enabled"
|
||||
@@ -5932,7 +5785,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -5957,10 +5809,8 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"kms_key_enclave_attestation_not_enforced",
|
||||
@@ -6080,7 +5930,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -6189,7 +6038,6 @@
|
||||
],
|
||||
"Checks": [
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
@@ -6235,7 +6083,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -6419,7 +6266,6 @@
|
||||
"Checks": [
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -6621,7 +6467,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -6648,7 +6493,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -6823,7 +6667,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
@@ -6868,7 +6711,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"rds_instance_integration_cloudwatch_logs",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -6908,7 +6750,6 @@
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_deletion_protection",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -6934,10 +6775,8 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"rds_instance_storage_encrypted",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_default_encryption",
|
||||
"s3_bucket_default_encryption",
|
||||
"sagemaker_notebook_instance_encryption_enabled"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -20,7 +20,6 @@
|
||||
"Checks": [
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -29,8 +28,7 @@
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"vpc_flow_logs_enabled",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -81,7 +79,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -106,7 +103,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -165,7 +161,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -259,7 +254,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"s3_bucket_server_access_logging_enabled",
|
||||
"securityhub_enabled"
|
||||
@@ -365,7 +359,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"guardduty_is_enabled",
|
||||
"s3_bucket_server_access_logging_enabled",
|
||||
"securityhub_enabled"
|
||||
@@ -402,7 +395,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"guardduty_is_enabled",
|
||||
@@ -537,7 +529,6 @@
|
||||
"Checks": [
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -838,7 +829,6 @@
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"awslambda_function_url_public",
|
||||
"rds_instance_no_public_access",
|
||||
@@ -850,8 +840,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -908,8 +897,7 @@
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured",
|
||||
"ec2_securitygroup_default_restrict_traffic",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -925,7 +913,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"redshift_cluster_audit_logging",
|
||||
"s3_bucket_server_access_logging_enabled"
|
||||
@@ -946,7 +933,6 @@
|
||||
"Checks": [
|
||||
"iam_root_hardware_mfa_enabled",
|
||||
"iam_root_mfa_enabled",
|
||||
"iam_user_mfa_enabled_console_access",
|
||||
"iam_user_mfa_enabled_console_access"
|
||||
]
|
||||
},
|
||||
@@ -1047,7 +1033,6 @@
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_s3_dataevents_read_enabled",
|
||||
"cloudtrail_s3_dataevents_write_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"ec2_ebs_public_snapshot",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1247,7 +1232,6 @@
|
||||
"s3_bucket_public_access",
|
||||
"s3_bucket_policy_public_write_access",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"s3_bucket_public_access",
|
||||
"sagemaker_notebook_instance_without_direct_internet_access_configured"
|
||||
]
|
||||
},
|
||||
@@ -1265,13 +1249,10 @@
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -1291,7 +1272,6 @@
|
||||
"Checks": [
|
||||
"config_recorder_all_regions_enabled",
|
||||
"ec2_instance_managed_by_ssm",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -1316,7 +1296,6 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled"
|
||||
]
|
||||
},
|
||||
@@ -1335,7 +1314,6 @@
|
||||
"Checks": [
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
@@ -1386,8 +1364,7 @@
|
||||
"rds_instance_no_public_access",
|
||||
"redshift_cluster_public_access",
|
||||
"ec2_networkacl_allow_ingress_any_port",
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22",
|
||||
"ec2_networkacl_allow_ingress_any_port"
|
||||
"ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1410,12 +1387,12 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "rp_1",
|
||||
"Id": "rc_rp_1",
|
||||
"Name": "RC.RP-1",
|
||||
"Description": "Recovery plan is executed during or after a cybersecurity incident.",
|
||||
"Attributes": [
|
||||
{
|
||||
"ItemId": "rp_1",
|
||||
"ItemId": "rc_rp_1",
|
||||
"Section": "Recover (RC)",
|
||||
"SubSection": "Recovery Planning (RC.RP)",
|
||||
"Service": "aws"
|
||||
@@ -1423,14 +1400,10 @@
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
@@ -1481,14 +1454,10 @@
|
||||
],
|
||||
"Checks": [
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"dynamodb_tables_pitr_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"efs_have_backup_enabled",
|
||||
"elbv2_deletion_protection",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_backup_enabled",
|
||||
"rds_instance_multi_az",
|
||||
"rds_instance_backup_enabled",
|
||||
"redshift_cluster_automated_snapshot",
|
||||
"s3_bucket_object_versioning"
|
||||
]
|
||||
|
||||
@@ -277,7 +277,7 @@
|
||||
"Checks": [
|
||||
"ec2_ebs_public_snapshot",
|
||||
"rds_instance_no_public_access",
|
||||
"eks_endpoints_not_publicly_accessible",
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"bedrock_vpc_endpoints_configured",
|
||||
"vpc_endpoint_for_ec2_enabled",
|
||||
"s3_account_level_public_access_blocks",
|
||||
@@ -474,7 +474,7 @@
|
||||
"s3_bucket_cross_region_replication",
|
||||
"ec2_ebs_public_snapshot",
|
||||
"rds_instance_no_public_access",
|
||||
"eks_endpoints_not_publicly_accessible",
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"vpc_endpoint_for_ec2_enabled",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
@@ -506,7 +506,7 @@
|
||||
"Checks": [
|
||||
"ec2_ebs_public_snapshot",
|
||||
"rds_instance_no_public_access",
|
||||
"eks_endpoints_not_publicly_accessible",
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"vpc_endpoint_for_ec2_enabled",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
@@ -742,7 +742,7 @@
|
||||
"elbv2_logging_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"wafv2_web_acl_logging_enabled",
|
||||
"wafv2_webacl_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"s3_bucket_lifecycle_enabled"
|
||||
],
|
||||
@@ -763,7 +763,7 @@
|
||||
"elbv2_logging_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"wafv2_web_acl_logging_enabled",
|
||||
"wafv2_webacl_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -794,7 +794,7 @@
|
||||
"Name": "Render PAN unreadable anywhere it is stored (including on portable digital media, backup media, and in logs) by using approaches like one-way hashes based on strong cryptography, truncation etc",
|
||||
"Description": "The following approaches should be used to render PAN unreadable anywhere it is stored: One-way hashes based on strong cryptography, (hash must be of the entire PAN), truncation (hashing cannot be used to replace the truncated segment of PAN), index tokens and pads (pads must be securely stored) and strong cryptography with associated key-management processes and procedures. Note: It is a relatively trivial effort for a malicious individual to reconstruct original PAN data if they have access to both the truncated and hashed version of a PAN. Where hashed and truncated versions of the same PAN are present in an entity's environment, additional controls must be in place to ensure that the hashed and truncated versions cannot be correlated to reconstruct the original PAN. PANs stored in primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception or troubleshooting logs) must all be protected. One-way hash functions based on strong cryptography can be used to render cardholder data unreadable. Hash functions are appropriate when there is no need to retrieve the original number (one-way hashes are irreversible). It is recommended, but not currently a requirement, that an additional, random input value be added to the cardholder data prior to hashing to reduce the feasibility of an attacker comparing the data against (and deriving the PAN from) tables of pre- computed hash values. The intent of truncation is to permanently remove a segment of PAN data so that only a portion (generally not to exceed the first six and last four digits) of the PAN is stored. An index token is a cryptographic token that replaces the PAN based on a given index for an unpredictable value. A one-time pad is a system in which a randomly generated private key is used only once to encrypt a message that is then decrypted using a matching one-time pad and key. The intent of strong cryptography (as defined in the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms) is that the encryption be based on an industry-tested and accepted algorithm (not a proprietary or `home- grown` algorithm) with strong cryptographic keys. By correlating hashed and truncated versions of a given PAN, a malicious individual may easily derive the original PAN value. Controls that prevent the correlation of this data will help ensure that the original PAN remains unreadable.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -807,7 +807,6 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging",
|
||||
@@ -816,7 +815,7 @@
|
||||
"elbv2_logging_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"wafv2_web_acl_logging_enabled",
|
||||
"wafv2_webacl_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -832,7 +831,7 @@
|
||||
"Name": "If disk encryption is used (rather than file- or column-level database encryption), logical access must be managed separately and independently of native operating system authentication and access control mechanisms (for example, by not using local user account databases or general network login credentials)",
|
||||
"Description": "Decryption keys must not be associated with user accounts. Note: This requirement applies in addition to all other PCI DSS encryption and key- management requirements. PANs stored in primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception or troubleshooting logs) must all be protected. One-way hash functions based on strong cryptography can be used to render cardholder data unreadable. Hash functions are appropriate when there is no need to retrieve the original number (one-way hashes are irreversible). It is recommended, but not currently a requirement, that an additional, random input value be added to the cardholder data prior to hashing to reduce the feasibility of an attacker comparing the data against (and deriving the PAN from) tables of pre- computed hash values. The intent of truncation is to permanently remove a segment of PAN data so that only a portion (generally not to exceed the first six and last four digits) of the PAN is stored. An index token is a cryptographic token that replaces the PAN based on a given index for an unpredictable value. A one-time pad is a system in which a randomly generated private key is used only once to encrypt a message that is then decrypted using a matching one-time pad and key. The intent of strong cryptography (as defined in the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms) is that the encryption be based on an industry-tested and accepted algorithm (not a proprietary or `home-grown` algorithm) with strong cryptographic keys. By correlating hashed and truncated versions of a given PAN, a malicious individual may easily derive the original PAN value. Controls that prevent the correlation of this data will help ensure that the original PAN remains unreadable.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -845,7 +844,6 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging"
|
||||
@@ -863,7 +861,7 @@
|
||||
"Name": "If disk encryption is used, inspect the configuration and observe the authentication process to verify that logical access to encrypted file systems is implemented via a mechanism that is separate from the native operating system's authentication mechanism (for example, not using local user account databases or general network login credentials)",
|
||||
"Description": "The intent of this requirement is to address the acceptability of disk-level encryption for rendering cardholder data unreadable. Disk-level encryption encrypts the entire disk/partition on a computer and automatically decrypts the information when an authorized user requests it. Many disk- encryption solutions intercept operating system read/write operations and carry out the appropriate cryptographic transformations without any special action by the user other than supplying a password or pass phrase upon system startup or at the beginning of a session. Based on these characteristics of disk-level encryption, to be compliant with this requirement, the method cannot: 1) Use the same user account authenticator as the operating system, or 2) Use a decryption key that is associated with or derived from the system's local user account database or general network login credentials. Full disk encryption helps to protect data in the event of physical loss of a disk and therefore may be appropriate for portable devices that store cardholder data.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -876,7 +874,6 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging"
|
||||
@@ -894,7 +891,7 @@
|
||||
"Name": "Examine the configurations and observe the processes to verify that cardholder data on removable media is encrypted wherever stored",
|
||||
"Description": "Note: If disk encryption is not used to encrypt removable media, the data stored on this media will need to be rendered unreadable through some other method. The intent of this requirement is to address the acceptability of disk-level encryption for rendering cardholder data unreadable. Disk-level encryption encrypts the entire disk/partition on a computer and automatically decrypts the information when an authorized user requests it. Many disk- encryption solutions intercept operating system read/write operations and carry out the appropriate cryptographic transformations without any special action by the user other than supplying a password or pass phrase upon system startup or at the beginning of a session. Based on these characteristics of disk-level encryption, to be compliant with this requirement, the method cannot: 1) Use the same user account authenticator as the operating system, or 2) Use a decryption key that is associated with or derived from the system's local user account database or general network login credentials. Full disk encryption helps to protect data in the event of physical loss of a disk and therefore may be appropriate for portable devices that store cardholder data.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -907,7 +904,6 @@
|
||||
"opensearch_service_domains_encryption_at_rest_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"ec2_ebs_volume_encryption",
|
||||
"rds_instance_storage_encrypted",
|
||||
"redshift_cluster_audit_logging"
|
||||
@@ -925,7 +921,7 @@
|
||||
"Name": "Examine documentation about the system used to protect the PAN, including the vendor, type of system/process, and the encryption algorithms (if applicable) to verify that the PAN is rendered unreadable using methods like truncation,one-way hashes based on strong cryptography etc",
|
||||
"Description": "Verify documentation about the system used to protect the PAN, including the vendor, type of system/process, and the encryption algorithms (if applicable) to verify that the PAN is rendered unreadable using any of the following methods: One-way hashes based on strong cryptography, truncation, index tokens and pads with the pads being securely stored, strong cryptography, with associated key-management processes and procedures. PANs stored in primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception or troubleshooting logs) must all be protected. One-way hash functions based on strong cryptography can be used to render cardholder data unreadable. Hash functions are appropriate when there is no need to retrieve the original number (one-way hashes are irreversible). It is recommended, but not currently a requirement, that an additional, random input value be added to the cardholder data prior to hashing to reduce the feasibility of an attacker comparing the data against (and deriving the PAN from) tables of pre- computed hash values. The intent of truncation is to permanently remove a segment of PAN data so that only a portion (generally not to exceed the first six and last four digits) of the PAN is stored. An index token is a cryptographic token that replaces the PAN based on a given index for an unpredictable value. A one-time pad is a system in which a randomly generated private key is used only once to encrypt a message that is then decrypted using a matching one-time pad and key. The intent of strong cryptography (as defined in the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms) is that the encryption be based on an industry-tested and accepted algorithm (not a proprietary or `home-grown` algorithm) with strong cryptographic keys. By correlating hashed and truncated versions of a given PAN, a malicious individual may easily derive the original PAN value. Controls that prevent the correlation of this data will help ensure that the original PAN remains unreadable.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -933,7 +929,6 @@
|
||||
"opensearch_service_domains_audit_logging_enabled",
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"rds_snapshots_encrypted",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"s3_bucket_default_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"ec2_ebs_default_encryption",
|
||||
@@ -957,7 +952,7 @@
|
||||
"Name": "Examine several tables or files from a sample of data repositories to verify the PAN is rendered unreadable (that is, not stored in plain-text)",
|
||||
"Description": "PANs stored in primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception or troubleshooting logs) must all be protected. One-way hash functions based on strong cryptography can be used to render cardholder data unreadable. Hash functions are appropriate when there is no need to retrieve the original number (one-way hashes are irreversible). It is recommended, but not currently a requirement, that an additional, random input value be added to the cardholder data prior to hashing to reduce the feasibility of an attacker comparing the data against (and deriving the PAN from) tables of pre- computed hash values. The intent of truncation is to permanently remove a segment of PAN data so that only a portion (generally not to exceed the first six and last four digits) of the PAN is stored. An index token is a cryptographic token that replaces the PAN based on a given index for an unpredictable value. A one-time pad is a system in which a randomly generated private key is used only once to encrypt a message that is then decrypted using a matching one-time pad and key. The intent of strong cryptography (as defined in the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms) is that the encryption be based on an industry-tested and accepted algorithm (not a proprietary or `home- grown` algorithm) with strong cryptographic keys. By correlating hashed and truncated versions of a given PAN, a malicious individual may easily derive the original PAN value. Controls that prevent the correlation of this data will help ensure that the original PAN remains unreadable.",
|
||||
"Checks": [
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"sagemaker_notebook_instance_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
@@ -965,7 +960,6 @@
|
||||
"opensearch_service_domains_audit_logging_enabled",
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"rds_snapshots_encrypted",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"s3_bucket_default_encryption",
|
||||
"efs_encryption_at_rest_enabled",
|
||||
"ec2_ebs_default_encryption",
|
||||
@@ -997,7 +991,7 @@
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"s3_bucket_default_encryption",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"wafv2_web_acl_logging_enabled",
|
||||
"wafv2_webacl_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -1084,7 +1078,7 @@
|
||||
"Description": "Following should be used to safeguard sensitive cardholder data during transmission over open, public networks: only trusted keys and certificates are accepted, the protocol in use only supports secure versions or configurations and the encryption strength is appropriate for the encryption methodology in use. Examples of open, public networks include but are not limited to the Internet, wireless technologies, including 802.11 and Bluetooth, cellular technologies, for example, Global System for Mobile communications (GSM), Code division multiple access (CDMA), general Packet Radio Service (GPRS) and satellite communications. Sensitive information must be encrypted during transmission over public networks, because it is easy and common for a malicious individual to intercept and/or divert data while in transit. Secure transmission of cardholder data requires using trusted keys/certificates, a secure protocol for transport, and proper encryption strength to encrypt cardholder data. Connection requests from systems that do not support the required encryption strength, and that would result in an insecure connection, should not be accepted. Note that some protocol implementations (such as SSL, SSH v1.0, and early TLS) have known vulnerabilities that an attacker can use to gain control of the affected system. Whichever security protocol is used, ensure it is configured to use only secure versions and configurations to prevent use of an insecure connection—for example, by using only trusted certificates and supporting only strong encryption (not supporting weaker, insecure protocols or methods). Verifying that certificates are trusted (for example, have not expired and are issued from a trusted source) helps ensure the integrity of the secure connection. Generally, the web page URL should begin with `HTTPS` and/or the web browser display a padlock icon somewhere in the window of the browser. Many TLS certificate vendors also provide a highly visible verification seal— sometimes referred to as a “security seal,” `secure site seal,` or “secure trust seal”)—which may provide the ability to click on the seal to reveal information about the website. Refer to industry standards and best practices for information on strong cryptography and secure protocols (e.g., NIST SP 800-52 and SP 800-57, OWASP, etc.) Note: SSL/early TLS is not considered strong cryptography and may not be used as a security control, except by POS POI terminals that are verified as not being susceptible to known exploits and the termination points to which they connect as defined in Appendix A2.",
|
||||
"Checks": [
|
||||
"acm_certificates_expiration_check",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"elbv2_ssl_listeners",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"elb_ssl_listeners",
|
||||
@@ -1110,7 +1104,7 @@
|
||||
"cloudfront_distributions_using_deprecated_ssl_protocols",
|
||||
"acm_certificates_expiration_check",
|
||||
"cloudfront_distributions_origin_traffic_encrypted",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"elbv2_ssl_listeners",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"elb_ssl_listeners"
|
||||
@@ -1178,7 +1172,7 @@
|
||||
"cloudfront_distributions_using_deprecated_ssl_protocols",
|
||||
"acm_certificates_expiration_check",
|
||||
"cloudfront_distributions_origin_traffic_encrypted",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"elbv2_ssl_listeners",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"elb_ssl_listeners"
|
||||
@@ -1497,7 +1491,7 @@
|
||||
"Checks": [
|
||||
"ec2_ebs_public_snapshot",
|
||||
"rds_instance_no_public_access",
|
||||
"eks_endpoints_not_publicly_accessible",
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"emr_cluster_master_nodes_no_public_ip",
|
||||
@@ -1528,7 +1522,7 @@
|
||||
"Checks": [
|
||||
"ec2_ebs_public_snapshot",
|
||||
"rds_instance_no_public_access",
|
||||
"eks_endpoints_not_publicly_accessible",
|
||||
"eks_cluster_not_publicly_accessible",
|
||||
"s3_account_level_public_access_blocks",
|
||||
"awslambda_function_not_publicly_accessible",
|
||||
"emr_cluster_master_nodes_no_public_ip",
|
||||
@@ -1637,7 +1631,7 @@
|
||||
"iam_password_policy_reuse_24",
|
||||
"codebuild_project_no_secrets_in_variables",
|
||||
"codebuild_project_source_repo_url_no_sensitive_credentials",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"elbv2_ssl_listeners",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"elb_ssl_listeners",
|
||||
@@ -1652,11 +1646,10 @@
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"rds_snapshots_encrypted",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"redshift_cluster_audit_logging"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -1674,7 +1667,7 @@
|
||||
"Checks": [
|
||||
"codebuild_project_no_secrets_in_variables",
|
||||
"codebuild_project_source_repo_url_no_sensitive_credentials",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"elbv2_ssl_listeners",
|
||||
"opensearch_service_domains_node_to_node_encryption_enabled",
|
||||
"elb_ssl_listeners",
|
||||
@@ -1689,11 +1682,10 @@
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"rds_snapshots_encrypted",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"redshift_cluster_audit_logging"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -1723,12 +1715,11 @@
|
||||
"eks_cluster_kms_cmk_encryption_in_secrets_enabled",
|
||||
"rds_snapshots_encrypted",
|
||||
"dynamodb_accelerator_cluster_encryption_enabled",
|
||||
"dynamodb_table_encryption_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"cloudtrail_kms_encryption_enabled",
|
||||
"cloudwatch_log_group_kms_encryption_enabled",
|
||||
"s3_bucket_enforces_ssl",
|
||||
"s3_bucket_secure_transport_policy",
|
||||
"sns_topics_kms_encryption_at_rest_enabled",
|
||||
"dynamodb_tables_kms_cmk_encryption_enabled",
|
||||
"redshift_cluster_audit_logging"
|
||||
],
|
||||
"Attributes": [
|
||||
@@ -2118,7 +2109,7 @@
|
||||
"cloudwatch_log_group_retention_policy_specific_days_enabled",
|
||||
"apigateway_restapi_logging_enabled",
|
||||
"cloudtrail_multi_region_enabled",
|
||||
"wafv2_web_acl_logging_enabled",
|
||||
"wafv2_webacl_logging_enabled",
|
||||
"cloudtrail_cloudwatch_logging_enabled",
|
||||
"vpc_flow_logs_enabled",
|
||||
"redshift_cluster_audit_logging"
|
||||
|
||||
@@ -109,9 +109,7 @@
|
||||
"guardduty_no_high_severity_findings",
|
||||
"rds_instance_minor_version_upgrade_enabled",
|
||||
"redshift_cluster_automatic_upgrades",
|
||||
"ssm_managed_compliant_patching",
|
||||
"ssm_managed_compliant_patching",
|
||||
"rds_instance_minor_version_upgrade_enabled"
|
||||
"ssm_managed_compliant_patching"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -643,8 +643,6 @@
|
||||
"ec2_client_vpn_endpoint_connection_logging_enabled",
|
||||
"ecs_task_definitions_logging_enabled",
|
||||
"elasticbeanstalk_environment_cloudwatch_logging_enabled",
|
||||
"elb_logging_enabled",
|
||||
"elbv2_logging_enabled",
|
||||
"glue_etl_jobs_logging_enabled",
|
||||
"mq_broker_logging_enabled",
|
||||
"networkfirewall_logging_enabled",
|
||||
|
||||
@@ -3157,8 +3157,6 @@
|
||||
"app_http_logs_enabled",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_storage_account_with_activity_logs_cmk_encrypted",
|
||||
"monitor_storage_account_with_activity_logs_is_private",
|
||||
"mysql_flexible_server_audit_log_connection_activated",
|
||||
"mysql_flexible_server_audit_log_enabled",
|
||||
"network_flow_log_captured_sent",
|
||||
@@ -5780,13 +5778,11 @@
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
"vm_ensure_unattached_disks_encrypted_with_cmk",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_app",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_api",
|
||||
"app_minimum_tls_version_12",
|
||||
"mysql_flexible_server_minimum_tls_version_12",
|
||||
"sqlserver_recommended_minimal_tls_version",
|
||||
"storage_ensure_minimum_tls_version_12",
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled"
|
||||
"storage_ensure_minimum_tls_version_12"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -5818,13 +5814,11 @@
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
"vm_ensure_unattached_disks_encrypted_with_cmk",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_app",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_api",
|
||||
"app_minimum_tls_version_12",
|
||||
"mysql_flexible_server_minimum_tls_version_12",
|
||||
"sqlserver_recommended_minimal_tls_version",
|
||||
"storage_ensure_minimum_tls_version_12",
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled"
|
||||
"storage_ensure_minimum_tls_version_12"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
{
|
||||
@@ -6577,7 +6571,6 @@
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
"app_minimum_tls_version_12",
|
||||
"mysql_flexible_server_minimum_tls_version_12",
|
||||
"sqlserver_recommended_minimal_tls_version",
|
||||
"storage_ensure_minimum_tls_version_12"
|
||||
],
|
||||
"ConfigRequirements": [
|
||||
@@ -7077,7 +7070,6 @@
|
||||
"app_http_logs_enabled",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_storage_account_with_activity_logs_cmk_encrypted",
|
||||
"monitor_storage_account_with_activity_logs_is_private",
|
||||
"mysql_flexible_server_audit_log_connection_activated",
|
||||
"mysql_flexible_server_audit_log_enabled",
|
||||
@@ -7920,8 +7912,6 @@
|
||||
"app_http_logs_enabled",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_storage_account_with_activity_logs_cmk_encrypted",
|
||||
"monitor_storage_account_with_activity_logs_is_private",
|
||||
"mysql_flexible_server_audit_log_connection_activated",
|
||||
"mysql_flexible_server_audit_log_enabled",
|
||||
"network_flow_log_captured_sent",
|
||||
@@ -7953,8 +7943,6 @@
|
||||
"app_http_logs_enabled",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_storage_account_with_activity_logs_cmk_encrypted",
|
||||
"monitor_storage_account_with_activity_logs_is_private",
|
||||
"mysql_flexible_server_audit_log_connection_activated",
|
||||
"mysql_flexible_server_audit_log_enabled",
|
||||
"network_flow_log_captured_sent",
|
||||
@@ -8991,7 +8979,6 @@
|
||||
"app_http_logs_enabled",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_storage_account_with_activity_logs_cmk_encrypted",
|
||||
"mysql_flexible_server_audit_log_connection_activated",
|
||||
"mysql_flexible_server_audit_log_enabled",
|
||||
"network_flow_log_captured_sent",
|
||||
|
||||
@@ -642,7 +642,7 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
" app_http_logs_enabled"
|
||||
"app_http_logs_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1185,7 +1185,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "op.mon.3.az.nw.1",
|
||||
"Id": "op.mon.3.az.nw.2",
|
||||
"Description": "Vigilancia",
|
||||
"Attributes": [
|
||||
{
|
||||
|
||||
@@ -17,26 +17,18 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"monitor_activity_log_alert_cmk_delete",
|
||||
"monitor_activity_log_alert_create_policy_assignment",
|
||||
"monitor_activity_log_alert_create_update_delete_network_sg",
|
||||
"monitor_activity_log_alert_create_update_delete_network_sg_rule",
|
||||
"monitor_activity_log_alert_create_update_delete_sql_server_fw_rule",
|
||||
"monitor_activity_log_alert_create_update_nsg",
|
||||
"monitor_activity_log_alert_create_update_public_ip_address",
|
||||
"monitor_activity_log_alert_create_update_security_solution",
|
||||
"monitor_activity_log_alert_delete_nsg",
|
||||
"monitor_activity_log_alert_delete_policy_assignment",
|
||||
"monitor_activity_log_alert_delete_public_ip_address",
|
||||
"monitor_activity_log_alert_delete_security_solution",
|
||||
"monitor_log_profile_all_categories",
|
||||
"monitor_log_profile_all_regions",
|
||||
"vm_agent_installed",
|
||||
"vm_antimalware_solution_installed",
|
||||
"vm_endpoint_protection_installed",
|
||||
"vm_guest_configuration_installed",
|
||||
"vm_guest_configuration_with_no_managed_identity",
|
||||
"vm_guest_configuration_with_user_identity"
|
||||
"monitor_alert_create_policy_assignment",
|
||||
"monitor_alert_create_update_sqlserver_fr",
|
||||
"monitor_alert_delete_sqlserver_fr",
|
||||
"monitor_alert_create_update_nsg",
|
||||
"monitor_alert_create_update_public_ip_address_rule",
|
||||
"monitor_alert_create_update_security_solution",
|
||||
"monitor_alert_delete_nsg",
|
||||
"monitor_alert_delete_policy_assignment",
|
||||
"monitor_alert_delete_public_ip_address_rule",
|
||||
"monitor_alert_delete_security_solution",
|
||||
"monitor_diagnostic_setting_with_appropriate_categories",
|
||||
"defender_assessments_vm_endpoint_protection_installed"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -64,17 +56,11 @@
|
||||
"keyvault_access_only_through_private_endpoints",
|
||||
"keyvault_private_endpoints",
|
||||
"network_bastion_host_exists",
|
||||
"network_flow_logs_enabled",
|
||||
"network_security_group_not_empty",
|
||||
"network_sg_ssh_access_restricted",
|
||||
"network_sg_rdp_access_restricted",
|
||||
"network_sg_open_all_ports_to_any_source",
|
||||
"network_flow_log_captured_sent",
|
||||
"network_ssh_internet_access_restricted",
|
||||
"network_rdp_internet_access_restricted",
|
||||
"network_watcher_enabled",
|
||||
"postgresql_flexible_server_public_network_access_disabled",
|
||||
"sqlserver_public_network_access_disabled",
|
||||
"storage_default_network_access_rule_set_to_deny",
|
||||
"vm_availability_zones_enabled",
|
||||
"vm_availability_set_deployed"
|
||||
"storage_default_network_access_rule_is_denied"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -111,8 +97,7 @@
|
||||
"app_function_identity_is_configured",
|
||||
"app_function_identity_without_admin_privileges",
|
||||
"app_ensure_auth_is_set_up",
|
||||
"app_register_with_identity",
|
||||
"vm_managed_identity_enabled"
|
||||
"app_register_with_identity"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -167,24 +152,16 @@
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"defender_auto_provisioning_vulnerabilty_assessments_machines_on",
|
||||
"keyvault_logging_enabled",
|
||||
"monitor_activity_log_retention_policy_set",
|
||||
"monitor_diagnostic_logs_categories",
|
||||
"monitor_diagnostic_setting_deployed_for_all_resources",
|
||||
"monitor_diagnostic_settings_captures_proper_categories",
|
||||
"monitor_log_profile_all_categories",
|
||||
"monitor_log_profile_all_regions",
|
||||
"monitor_log_profile_captures_all_activities",
|
||||
"monitor_log_profile_retention_policy_at_least_365",
|
||||
"network_flow_logs_enabled",
|
||||
"network_flow_log_retention_policy_at_least_90",
|
||||
"monitor_diagnostic_setting_with_appropriate_categories",
|
||||
"monitor_diagnostic_settings_exists",
|
||||
"network_flow_log_captured_sent",
|
||||
"network_flow_log_more_than_90_days",
|
||||
"network_watcher_enabled",
|
||||
"postgresql_flexible_server_audit_logs_enabled",
|
||||
"postgresql_flexible_server_log_checkpoints_enabled",
|
||||
"postgresql_flexible_server_log_connections_enabled",
|
||||
"postgresql_flexible_server_log_disconnections_enabled",
|
||||
"sqlserver_auditing_on",
|
||||
"sqlserver_auditing_retention_90_days",
|
||||
"storage_storage_account_logging_queue_read_write_delete_enabled"
|
||||
"postgresql_flexible_server_log_checkpoints_on",
|
||||
"postgresql_flexible_server_log_connections_on",
|
||||
"postgresql_flexible_server_log_disconnections_on",
|
||||
"sqlserver_auditing_enabled",
|
||||
"sqlserver_auditing_retention_90_days"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -199,21 +176,13 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"policy_ensure_asc_for_aks_is_enabled",
|
||||
"policy_ensure_asc_for_app_services_is_enabled",
|
||||
"policy_ensure_asc_for_azure_sql_is_enabled",
|
||||
"policy_ensure_asc_for_key_vault_is_enabled",
|
||||
"policy_ensure_asc_for_servers_is_enabled",
|
||||
"policy_ensure_asc_for_sql_servers_is_enabled",
|
||||
"policy_ensure_asc_for_storage_is_enabled",
|
||||
"policy_ensure_allowed_extensions_are_installed",
|
||||
"policy_ensure_allowed_locations_is_enabled",
|
||||
"policy_ensure_allowed_resource_types_is_enabled",
|
||||
"policy_ensure_audit_diagnostic_log_enabled_for_all_services",
|
||||
"policy_ensure_not_allowed_resource_types_is_enabled",
|
||||
"vm_guest_configuration_installed",
|
||||
"vm_guest_configuration_with_no_managed_identity",
|
||||
"vm_guest_configuration_with_user_identity"
|
||||
"defender_ensure_defender_for_containers_is_on",
|
||||
"defender_ensure_defender_for_app_services_is_on",
|
||||
"defender_ensure_defender_for_azure_sql_databases_is_on",
|
||||
"defender_ensure_defender_for_keyvault_is_on",
|
||||
"defender_ensure_defender_for_server_is_on",
|
||||
"defender_ensure_defender_for_sql_servers_is_on",
|
||||
"defender_ensure_defender_for_storage_is_on"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -229,18 +198,10 @@
|
||||
],
|
||||
"Checks": [
|
||||
"mysql_flexible_server_geo_redundant_backup_enabled",
|
||||
"mysql_flexible_server_retain_backup_35_days",
|
||||
"postgresql_flexible_server_geo_redundant_backup_enabled",
|
||||
"postgresql_flexible_server_backup_retention_period_35_days",
|
||||
"recovery_services_vault_uses_private_link",
|
||||
"recovery_services_vault_uses_private_link_for_backup",
|
||||
"sqlserver_database_long_term_geo_redundant_backup",
|
||||
"sqlserver_database_retention_policy_exceeds_90_days",
|
||||
"storage_default_storage_account_encrypted_with_cmk_not_stored_in_storage_account",
|
||||
"storage_geo_redundant_enabled",
|
||||
"storage_infrastructure_encryption_is_enabled",
|
||||
"storage_soft_delete_containers_enabled",
|
||||
"storage_soft_delete_enabled",
|
||||
"storage_ensure_soft_delete_is_enabled",
|
||||
"vm_backup_enabled",
|
||||
"vm_sufficient_daily_backup_retention_period"
|
||||
]
|
||||
@@ -266,26 +227,18 @@
|
||||
"keyvault_key_expiration_set_in_non_rbac",
|
||||
"keyvault_key_rotation_enabled",
|
||||
"keyvault_non_rbac_secret_expiration_set",
|
||||
"mysql_flexible_server_encrypted_at_rest_using_cmk",
|
||||
"mysql_flexible_server_encrypted_in_transit",
|
||||
"mysql_flexible_server_minimum_tls_version_tls12",
|
||||
"postgresql_flexible_server_encrypted_at_rest_using_cmk",
|
||||
"postgresql_flexible_server_encrypted_in_transit",
|
||||
"postgresql_flexible_server_minimum_tls_version_tls12",
|
||||
"sqlserver_advanced_data_security_enabled",
|
||||
"sqlserver_database_encryption_with_cmk",
|
||||
"sqlserver_database_tde_encryption_enabled",
|
||||
"sqlserver_minimum_tls_version_12",
|
||||
"storage_secure_transfer_required_enabled",
|
||||
"storage_default_storage_account_encrypted_with_cmk",
|
||||
"mysql_flexible_server_ssl_connection_enabled",
|
||||
"mysql_flexible_server_minimum_tls_version_12",
|
||||
"postgresql_flexible_server_enforce_ssl_enabled",
|
||||
"defender_ensure_defender_for_sql_servers_is_on",
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
"sqlserver_recommended_minimal_tls_version",
|
||||
"storage_secure_transfer_required_is_enabled",
|
||||
"storage_ensure_encryption_with_customer_managed_keys",
|
||||
"storage_infrastructure_encryption_is_enabled",
|
||||
"storage_storage_account_encrypted_with_cmk",
|
||||
"storage_storage_account_minimum_tls_version_tls12",
|
||||
"vm_encrypted_at_host",
|
||||
"vm_data_disks_encrypted_with_cmk",
|
||||
"vm_managed_disks_encrypted_with_cmk",
|
||||
"vm_os_disk_are_encrypted_with_cmk",
|
||||
"vm_temporary_disks_and_cache_encrypted"
|
||||
"storage_ensure_minimum_tls_version_12",
|
||||
"vm_ensure_attached_disks_encrypted_with_cmk"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -307,11 +260,7 @@
|
||||
"defender_container_images_resolved_vulnerabilities",
|
||||
"defender_container_images_scan_enabled",
|
||||
"defender_ensure_system_updates_are_applied",
|
||||
"vm_agent_installed",
|
||||
"vm_antimalware_solution_installed",
|
||||
"vm_endpoint_protection_installed",
|
||||
"vm_os_update_system_updates",
|
||||
"vm_security_patch_assessment"
|
||||
"defender_assessments_vm_endpoint_protection_installed"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -332,8 +281,7 @@
|
||||
"entra_user_with_vm_access_has_mfa",
|
||||
"iam_custom_role_has_permissions_to_administer_resource_locks",
|
||||
"iam_role_user_access_admin_restricted",
|
||||
"app_function_identity_is_configured",
|
||||
"vm_managed_identity_enabled"
|
||||
"app_function_identity_is_configured"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -348,10 +296,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"monitor_log_profile_all_categories",
|
||||
"monitor_log_profile_all_regions",
|
||||
"monitor_log_profile_captures_all_activities",
|
||||
"monitor_diagnostic_setting_deployed_for_all_resources",
|
||||
"monitor_diagnostic_setting_with_appropriate_categories",
|
||||
"monitor_diagnostic_settings_exists",
|
||||
"network_watcher_enabled"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1056,7 +1056,9 @@
|
||||
"entra_policy_guest_invite_only_for_admin_roles",
|
||||
"entra_policy_guest_users_access_restrictions",
|
||||
"entra_policy_restricts_user_consent_for_apps",
|
||||
"entra_policy_user_consent_for_verified_apps storage_blob_public_access_level_is_disabled storage_ensure_azure_services_are_trusted_to_access_is_enabled"
|
||||
"entra_policy_user_consent_for_verified_apps",
|
||||
"storage_blob_public_access_level_is_disabled",
|
||||
"storage_ensure_azure_services_are_trusted_to_access_is_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -1106,8 +1108,9 @@
|
||||
],
|
||||
"Checks": [
|
||||
"entra_authentication_methods_policy_strong_auth_enforced",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_app",
|
||||
"entra_non_privileged_user_has_mfa entra_privileged_user_has_mfa",
|
||||
"entra_conditional_access_policy_require_mfa_for_management_api",
|
||||
"entra_non_privileged_user_has_mfa",
|
||||
"entra_privileged_user_has_mfa",
|
||||
"entra_user_with_vm_access_has_mfa",
|
||||
"app_minimum_tls_version_12",
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
|
||||
@@ -29,7 +29,6 @@
|
||||
"app_ensure_php_version_is_latest",
|
||||
"app_ensure_python_version_is_latest",
|
||||
"defender_assessments_vm_endpoint_protection_installed",
|
||||
"defender_assessments_vm_endpoint_protection_installed",
|
||||
"defender_auto_provisioning_log_analytics_agent_vms_on",
|
||||
"defender_auto_provisioning_vulnerabilty_assessments_machines_on",
|
||||
"defender_container_images_resolved_vulnerabilities",
|
||||
@@ -1601,8 +1600,6 @@
|
||||
"mysql_flexible_server_minimum_tls_version_12",
|
||||
"mysql_flexible_server_ssl_connection_enabled",
|
||||
"postgresql_flexible_server_enforce_ssl_enabled",
|
||||
"sqlserver_tde_encrypted_with_cmk",
|
||||
"sqlserver_tde_encryption_enabled",
|
||||
"storage_blob_public_access_level_is_disabled",
|
||||
"storage_ensure_azure_services_are_trusted_to_access_is_enabled",
|
||||
"storage_ensure_encryption_with_customer_managed_keys",
|
||||
|
||||
@@ -1565,7 +1565,6 @@
|
||||
"containerregistry_uses_private_link",
|
||||
"cosmosdb_account_use_private_endpoints",
|
||||
"keyvault_private_endpoints",
|
||||
"monitor_storage_account_with_activity_logs_is_private",
|
||||
"storage_ensure_private_endpoints_in_storage_accounts"
|
||||
],
|
||||
"Attributes": [
|
||||
|
||||
@@ -743,24 +743,6 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "3.2.1",
|
||||
"Description": "Ensure that 'Auditing' Retention is 'greater than 90 days'",
|
||||
"Checks": [
|
||||
"sqlserver_auditing_retention_90_days"
|
||||
],
|
||||
"Attributes": [
|
||||
{
|
||||
"Title": "Auditing' Retention is 'greater than 90 days'",
|
||||
"Section": "3. Logging and Monitoring",
|
||||
"SubSection": "3.2 Retention",
|
||||
"AttributeDescription": "Configure SQL Server Audit Retention to retain logs for more than 90 days to ensure long-term visibility into database activity and security events.",
|
||||
"AdditionalInformation": "Maintaining audit logs for over 90 days helps detect anomalies, security breaches, and unauthorized access. Longer retention periods allow organizations to analyze historical data, support compliance requirements, and strengthen forensic investigations.",
|
||||
"LevelOfRisk": 3,
|
||||
"Weight": 10
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "3.2.1",
|
||||
"Description": "Ensure that Network Watcher flow log retention period is '0 or at least 90 days'",
|
||||
@@ -815,6 +797,24 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "3.2.4",
|
||||
"Description": "Ensure that 'Auditing' Retention is 'greater than 90 days'",
|
||||
"Checks": [
|
||||
"sqlserver_auditing_retention_90_days"
|
||||
],
|
||||
"Attributes": [
|
||||
{
|
||||
"Title": "Auditing' Retention is 'greater than 90 days'",
|
||||
"Section": "3. Logging and Monitoring",
|
||||
"SubSection": "3.2 Retention",
|
||||
"AttributeDescription": "Configure SQL Server Audit Retention to retain logs for more than 90 days to ensure long-term visibility into database activity and security events.",
|
||||
"AdditionalInformation": "Maintaining audit logs for over 90 days helps detect anomalies, security breaches, and unauthorized access. Longer retention periods allow organizations to analyze historical data, support compliance requirements, and strengthen forensic investigations.",
|
||||
"LevelOfRisk": 3,
|
||||
"Weight": 10
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "3.3.1",
|
||||
"Description": "Ensure that 'Auditing' is set to 'On' ",
|
||||
|
||||
@@ -1692,7 +1692,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "mp.com.4.gcp.vpc.1",
|
||||
"Id": "mp.com.4.gcp.vpc.2",
|
||||
"Description": "Separación de flujos de información en la red",
|
||||
"Attributes": [
|
||||
{
|
||||
|
||||
@@ -18,8 +18,7 @@
|
||||
],
|
||||
"Checks": [
|
||||
"iam_cloud_asset_inventory_enabled",
|
||||
"securitycenter_security_health_analytics_enabled",
|
||||
"essentialcontacts_security_contacts_configured"
|
||||
"iam_organization_essential_contacts_configured"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -34,23 +33,20 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_encryption",
|
||||
"cloudstorage_bucket_public_access",
|
||||
"cloudstorage_bucket_uniform_access",
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"cloudsql_instance_encryption_enabled",
|
||||
"cloudstorage_bucket_uniform_bucket_level_access",
|
||||
"cloudsql_instance_automated_backups",
|
||||
"cloudsql_instance_cmek_encryption_enabled",
|
||||
"cloudsql_instance_public_access",
|
||||
"compute_instance_public_ip",
|
||||
"compute_disk_encryption_enabled",
|
||||
"compute_firewall_rdp_access_from_internet_restricted",
|
||||
"compute_firewall_ssh_access_from_internet_restricted",
|
||||
"compute_network_legacy_network_not_used",
|
||||
"gke_cluster_master_authorized_networks_enabled",
|
||||
"gke_cluster_private_cluster_enabled",
|
||||
"compute_instance_encryption_with_csek_enabled",
|
||||
"compute_firewall_rdp_access_from_the_internet_allowed",
|
||||
"compute_firewall_ssh_access_from_the_internet_allowed",
|
||||
"compute_network_not_legacy",
|
||||
"iam_sa_no_administrative_privileges",
|
||||
"iam_no_service_roles_at_project_level",
|
||||
"bigquery_dataset_public_access",
|
||||
"bigquery_dataset_cmek_encryption",
|
||||
"bigquery_dataset_cmk_encryption",
|
||||
"kms_key_rotation_enabled",
|
||||
"gemini_api_disabled"
|
||||
]
|
||||
@@ -148,8 +144,7 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"securitycenter_security_health_analytics_enabled",
|
||||
"essentialcontacts_security_contacts_configured",
|
||||
"iam_organization_essential_contacts_configured",
|
||||
"logging_sink_created"
|
||||
]
|
||||
},
|
||||
@@ -165,9 +160,7 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"compute_disk_snapshot_encryption_enabled",
|
||||
"gke_cluster_stackdriver_logging_enabled"
|
||||
"cloudsql_instance_automated_backups"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -182,9 +175,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"cloudstorage_bucket_object_versioning",
|
||||
"compute_disk_snapshot_encryption_enabled"
|
||||
"cloudsql_instance_automated_backups",
|
||||
"cloudstorage_bucket_versioning_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -199,9 +191,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"cloudsql_instance_point_in_time_recovery_enabled",
|
||||
"cloudstorage_bucket_object_versioning"
|
||||
"cloudsql_instance_automated_backups",
|
||||
"cloudstorage_bucket_versioning_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -247,9 +238,8 @@
|
||||
],
|
||||
"Checks": [
|
||||
"compute_instance_public_ip",
|
||||
"compute_firewall_rdp_access_from_internet_restricted",
|
||||
"compute_firewall_ssh_access_from_internet_restricted",
|
||||
"gke_cluster_private_cluster_enabled"
|
||||
"compute_firewall_rdp_access_from_the_internet_allowed",
|
||||
"compute_firewall_ssh_access_from_the_internet_allowed"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -264,9 +254,7 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"compute_disk_encryption_enabled",
|
||||
"compute_disk_snapshot_encryption_enabled",
|
||||
"cloudstorage_bucket_encryption"
|
||||
"compute_instance_encryption_with_csek_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -285,11 +273,10 @@
|
||||
"iam_no_service_roles_at_project_level",
|
||||
"iam_account_access_approval_enabled",
|
||||
"cloudstorage_bucket_public_access",
|
||||
"cloudstorage_bucket_uniform_access",
|
||||
"cloudstorage_bucket_uniform_bucket_level_access",
|
||||
"cloudsql_instance_public_access",
|
||||
"bigquery_dataset_public_access",
|
||||
"compute_instance_public_ip",
|
||||
"gke_cluster_private_cluster_enabled"
|
||||
"compute_instance_public_ip"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -320,11 +307,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_encryption",
|
||||
"cloudsql_instance_encryption_enabled",
|
||||
"compute_disk_encryption_enabled",
|
||||
"compute_disk_snapshot_encryption_enabled",
|
||||
"bigquery_dataset_cmek_encryption",
|
||||
"cloudsql_instance_cmek_encryption_enabled",
|
||||
"compute_instance_encryption_with_csek_enabled",
|
||||
"bigquery_dataset_cmk_encryption",
|
||||
"kms_key_rotation_enabled"
|
||||
]
|
||||
},
|
||||
@@ -348,8 +333,7 @@
|
||||
"logging_log_metric_filter_and_alert_for_vpc_network_route_changes_enabled",
|
||||
"logging_log_metric_filter_and_alert_for_vpc_firewall_rule_changes_enabled",
|
||||
"logging_log_metric_filter_and_alert_for_bucket_permission_changes_enabled",
|
||||
"logging_log_metric_filter_and_alert_for_sql_instance_configuration_changes_enabled",
|
||||
"gke_cluster_stackdriver_logging_enabled"
|
||||
"logging_log_metric_filter_and_alert_for_sql_instance_configuration_changes_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -364,9 +348,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_object_versioning",
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"cloudsql_instance_point_in_time_recovery_enabled",
|
||||
"cloudstorage_bucket_versioning_enabled",
|
||||
"cloudsql_instance_automated_backups",
|
||||
"kms_key_rotation_enabled"
|
||||
]
|
||||
},
|
||||
@@ -398,11 +381,9 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_encryption",
|
||||
"compute_firewall_rdp_access_from_internet_restricted",
|
||||
"compute_firewall_ssh_access_from_internet_restricted",
|
||||
"cloudsql_instance_ssl_required",
|
||||
"gke_cluster_master_authorized_networks_enabled"
|
||||
"compute_firewall_rdp_access_from_the_internet_allowed",
|
||||
"compute_firewall_ssh_access_from_the_internet_allowed",
|
||||
"cloudsql_instance_ssl_connections"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -417,8 +398,8 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_object_versioning",
|
||||
"cloudsql_instance_automatic_backups_enabled",
|
||||
"cloudstorage_bucket_versioning_enabled",
|
||||
"cloudsql_instance_automated_backups",
|
||||
"logging_sink_created"
|
||||
]
|
||||
},
|
||||
@@ -434,12 +415,11 @@
|
||||
}
|
||||
],
|
||||
"Checks": [
|
||||
"cloudstorage_bucket_encryption",
|
||||
"cloudsql_instance_encryption_enabled",
|
||||
"compute_disk_encryption_enabled",
|
||||
"bigquery_dataset_cmek_encryption",
|
||||
"cloudsql_instance_cmek_encryption_enabled",
|
||||
"compute_instance_encryption_with_csek_enabled",
|
||||
"bigquery_dataset_cmk_encryption",
|
||||
"kms_key_rotation_enabled",
|
||||
"cloudsql_instance_ssl_required"
|
||||
"cloudsql_instance_ssl_connections"
|
||||
]
|
||||
}
|
||||
]
|
||||
|
||||
@@ -247,8 +247,7 @@
|
||||
"Checks": [
|
||||
"iam_sa_user_managed_key_rotate_90_days",
|
||||
"kms_key_rotation_enabled",
|
||||
"apikeys_key_rotated_in_90_days",
|
||||
"kms_key_rotation_enabled"
|
||||
"apikeys_key_rotated_in_90_days"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -889,7 +889,6 @@
|
||||
"dns_dnssec_disabled",
|
||||
"dns_rsasha1_in_use_to_key_sign_in_dnssec",
|
||||
"dns_rsasha1_in_use_to_zone_sign_in_dnssec",
|
||||
"bigquery_dataset_cmk_encryption",
|
||||
"bigquery_table_cmk_encryption",
|
||||
"compute_instance_encryption_with_csek_enabled",
|
||||
"dataproc_encrypted_with_cmks_disabled"
|
||||
|
||||
@@ -63,7 +63,7 @@
|
||||
"Id": "1.2.1",
|
||||
"Description": "Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account",
|
||||
"Checks": [
|
||||
"iam_sa_no_user_managed_keysiam_sa_no_user_managed_keys"
|
||||
"iam_sa_no_user_managed_keys"
|
||||
],
|
||||
"Attributes": [
|
||||
{
|
||||
|
||||
@@ -568,8 +568,7 @@
|
||||
"cloudstorage_bucket_uniform_bucket_level_access",
|
||||
"bigquery_dataset_cmk_encryption",
|
||||
"bigquery_table_cmk_encryption",
|
||||
"compute_instance_confidential_computing_enabled",
|
||||
"pubsub_topic_encryption_with_cmk"
|
||||
"compute_instance_confidential_computing_enabled"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -1688,27 +1688,6 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "2.4.1",
|
||||
"Description": "Sign all artifacts in all releases with user or organization keys.",
|
||||
"Checks": [],
|
||||
"Attributes": [
|
||||
{
|
||||
"Section": "2 Build Pipelines",
|
||||
"Subsection": "2.4 Pipeline Integrity",
|
||||
"Profile": "Level 2",
|
||||
"AssessmentStatus": "Manual",
|
||||
"Description": "Sign all artifacts in all releases with user or organization keys.",
|
||||
"RationaleStatement": "Signing artifacts is used to validate both their integrity and security. Organizations signal that artifacts may be trusted and they themselves produced them by ensuring that every artifact is properly signed. The presence of this signature also makes potentially malicious activity far more difficult.",
|
||||
"ImpactStatement": "",
|
||||
"RemediationProcedure": "For every artifact in every release, verify that all are properly signed.",
|
||||
"AuditProcedure": "Ensure every artifact in every release is signed.",
|
||||
"AdditionalInformation": "",
|
||||
"References": "",
|
||||
"DefaultValue": ""
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"Id": "2.4.2",
|
||||
"Description": "External dependencies may be public packages needed in the pipeline, or perhaps the public image being used for the build worker. Lock these external dependencies in every build pipeline.",
|
||||
|
||||
@@ -1132,7 +1132,6 @@
|
||||
"etcd_no_auto_tls",
|
||||
"etcd_no_peer_auto_tls",
|
||||
"etcd_peer_tls_config",
|
||||
"etcd_tls_encryption",
|
||||
"kubelet_tls_cert_and_key"
|
||||
]
|
||||
},
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
"Id": "1.1.1",
|
||||
"Description": "Administrative accounts are special privileged accounts that could have varying levels of access to data, users, and settings. Regular user accounts should never be utilized for administrative tasks and care should be taken, in the case of a hybrid environment, to keep Administrative accounts separated from on-prem accounts. Administrative accounts should not have applications assigned so that they have no access to potentially vulnerable services (EX. email, Teams, SharePoint, etc.) and only access to perform tasks as needed for administrative purposes.Ensure administrative accounts are not `On-premises sync enabled`.",
|
||||
"Checks": [
|
||||
"entra_admin_account_cloud_only"
|
||||
"entra_admin_users_cloud_only"
|
||||
],
|
||||
"Attributes": [
|
||||
{
|
||||
@@ -1357,7 +1357,7 @@
|
||||
"Id": "5.2.2.8",
|
||||
"Description": "When a Conditional Access policy targets the Microsoft Admin Portals cloud app, the policy is enforced for tokens issued to application IDs of the following Microsoft administrative portals:- Azure portal- Exchange admin center- Microsoft 365 admin center- Microsoft 365 Defender portal- Microsoft Entra admin center- Microsoft Intune admin center- Microsoft Purview compliance portal- Power Platform admin center- SharePoint admin center- Microsoft Teams admin center`Microsoft Admin Portals` should be restricted to specific pre-determined administrative roles.",
|
||||
"Checks": [
|
||||
"entra_admin_portals_role_limited_access"
|
||||
"entra_admin_portals_access_restriction"
|
||||
],
|
||||
"Attributes": [
|
||||
{
|
||||
|
||||
@@ -51,13 +51,10 @@
|
||||
"admincenter_users_between_two_and_four_global_admins",
|
||||
"defender_antispam_outbound_policy_configured",
|
||||
"entra_admin_consent_workflow_enabled",
|
||||
"entra_admin_portals_access_restriction",
|
||||
"entra_admin_users_cloud_only",
|
||||
"entra_admin_users_mfa_enabled",
|
||||
"entra_admin_users_phishing_resistant_mfa_enabled",
|
||||
"entra_admin_users_sign_in_frequency_enabled",
|
||||
"entra_policy_ensure_default_user_cannot_create_tenants",
|
||||
"entra_policy_guest_invite_only_for_admin_roles"
|
||||
"entra_policy_ensure_default_user_cannot_create_tenants"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -119,7 +116,7 @@
|
||||
"defender_safelinks_policy_enabled",
|
||||
"defender_zap_for_teams_enabled",
|
||||
"defenderxdr_endpoint_privileged_user_exposed_credentials",
|
||||
"defender_identity_health_issues_no_open",
|
||||
"defenderidentity_health_issues_no_open",
|
||||
"entra_admin_users_phishing_resistant_mfa_enabled",
|
||||
"entra_conditional_access_policy_block_elevated_insider_risk",
|
||||
"entra_conditional_access_policy_block_o365_elevated_insider_risk",
|
||||
@@ -186,7 +183,6 @@
|
||||
"sharepoint_guest_sharing_restricted",
|
||||
"sharepoint_modern_authentication_required",
|
||||
"sharepoint_onedrive_sync_restricted_unmanaged_devices",
|
||||
"teams_external_file_sharing_restricted",
|
||||
"teams_external_file_sharing_restricted"
|
||||
]
|
||||
},
|
||||
@@ -780,7 +776,7 @@
|
||||
"defender_malware_policy_comprehensive_attachments_filter_applied",
|
||||
"defender_malware_policy_notifications_internal_users_malware_enabled",
|
||||
"defenderxdr_endpoint_privileged_user_exposed_credentials",
|
||||
"defender_identity_health_issues_no_open"
|
||||
"defenderidentity_health_issues_no_open"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -52,7 +52,7 @@ class _MutableTimestamp:
|
||||
|
||||
timestamp = _MutableTimestamp(datetime.today())
|
||||
timestamp_utc = _MutableTimestamp(datetime.now(timezone.utc))
|
||||
prowler_version = "5.41.0"
|
||||
prowler_version = "5.41.1"
|
||||
html_logo_url = "https://github.com/prowler-cloud/prowler/"
|
||||
square_logo_img = "https://raw.githubusercontent.com/prowler-cloud/prowler/dc7d2d5aeb92fdf12e8604f42ef6472cd3e8e889/docs/img/prowler-logo-black.png"
|
||||
aws_logo = "https://user-images.githubusercontent.com/38561120/235953920-3e3fba08-0795-41dc-b480-9bea57db9f2e.png"
|
||||
|
||||
@@ -3,8 +3,10 @@ import hashlib
|
||||
import os
|
||||
import re
|
||||
from collections.abc import Mapping
|
||||
from concurrent.futures import ThreadPoolExecutor, as_completed
|
||||
from dataclasses import dataclass
|
||||
from datetime import datetime, timedelta
|
||||
from threading import Lock
|
||||
from typing import Dict, List, Optional
|
||||
|
||||
import requests
|
||||
@@ -416,6 +418,7 @@ class Jira:
|
||||
api_token: str = None,
|
||||
domain: str = None,
|
||||
):
|
||||
self._token_lock = Lock()
|
||||
self._redirect_uri = redirect_uri
|
||||
self._client_id = client_id
|
||||
self._client_secret = client_secret
|
||||
@@ -1017,11 +1020,15 @@ class Jira:
|
||||
if self._using_basic_auth:
|
||||
return self._access_token
|
||||
|
||||
if self.auth_expiration and datetime.now() < datetime.fromisoformat(
|
||||
self.auth_expiration
|
||||
):
|
||||
if self._access_token_is_valid():
|
||||
return self._access_token
|
||||
else:
|
||||
|
||||
# Atlassian rotates refresh tokens, so two concurrent refreshes with
|
||||
# the same one would invalidate each other. Re-check under the lock
|
||||
# in case another thread refreshed while we waited for it.
|
||||
with self._token_lock:
|
||||
if self._access_token_is_valid():
|
||||
return self._access_token
|
||||
return self.refresh_access_token()
|
||||
except JiraRefreshTokenError as refresh_error:
|
||||
raise refresh_error
|
||||
@@ -1034,6 +1041,12 @@ class Jira:
|
||||
file=os.path.basename(__file__),
|
||||
)
|
||||
|
||||
def _access_token_is_valid(self) -> bool:
|
||||
"""Return whether the current OAuth access token has not expired."""
|
||||
return bool(self.auth_expiration) and datetime.now() < datetime.fromisoformat(
|
||||
self.auth_expiration
|
||||
)
|
||||
|
||||
def refresh_access_token(self) -> str:
|
||||
"""Refresh the access token
|
||||
|
||||
@@ -1128,15 +1141,21 @@ class Jira:
|
||||
projects = jira.get_projects()
|
||||
|
||||
issue_types = {}
|
||||
for project_key in projects:
|
||||
try:
|
||||
issue_types[project_key] = jira.get_available_issue_types(
|
||||
project_key
|
||||
)
|
||||
except Exception as e:
|
||||
logger.warning(
|
||||
f"Failed to get issue types for project {project_key}: {e}"
|
||||
)
|
||||
with ThreadPoolExecutor(max_workers=10) as executor:
|
||||
future_to_project = {
|
||||
executor.submit(
|
||||
jira.get_available_issue_types, project_key
|
||||
): project_key
|
||||
for project_key in projects
|
||||
}
|
||||
for future in as_completed(future_to_project):
|
||||
project_key = future_to_project[future]
|
||||
try:
|
||||
issue_types[project_key] = future.result()
|
||||
except Exception as e:
|
||||
logger.warning(
|
||||
f"Failed to get issue types for project {project_key}: {e}"
|
||||
)
|
||||
|
||||
return JiraConnection(
|
||||
is_connected=True, projects=projects, issue_types=issue_types
|
||||
@@ -1296,7 +1315,10 @@ class Jira:
|
||||
|
||||
if response.status_code == 200:
|
||||
if len(response.json()["projects"]) == 0:
|
||||
logger.error("No projects found")
|
||||
# Expected per-project condition (e.g. the integration user lacks
|
||||
# "create issue" rights on this specific project) — the caller in
|
||||
# test_connection() already treats this as non-fatal, so this isn't
|
||||
# an error worth alerting on.
|
||||
raise JiraNoProjectsError(
|
||||
message="No projects found in Jira",
|
||||
file=os.path.basename(__file__),
|
||||
@@ -1316,6 +1338,13 @@ class Jira:
|
||||
raise refresh_error
|
||||
except JiraRefreshTokenResponseError as response_error:
|
||||
raise response_error
|
||||
except JiraNoProjectsError as no_projects_error:
|
||||
# Expected per-project condition; the caller decides whether to log it.
|
||||
raise JiraGetAvailableIssueTypesError(
|
||||
message="Failed to get available issue types",
|
||||
file=os.path.basename(__file__),
|
||||
original_exception=no_projects_error,
|
||||
)
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to get available issue types: {e}")
|
||||
raise JiraGetAvailableIssueTypesError(
|
||||
|
||||
+1
-1
@@ -143,7 +143,7 @@ maintainers = [{name = "Prowler Engineering", email = "engineering@prowler.com"}
|
||||
name = "prowler"
|
||||
readme = "README.md"
|
||||
requires-python = ">=3.10,<3.14"
|
||||
version = "5.41.0"
|
||||
version = "5.41.1"
|
||||
|
||||
[project.scripts]
|
||||
prowler = "prowler.__main__:prowler"
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
from unittest import mock
|
||||
|
||||
import pytest
|
||||
|
||||
_MOCK_CLASSES = (
|
||||
mock.Mock,
|
||||
mock.MagicMock,
|
||||
mock.AsyncMock,
|
||||
mock.NonCallableMock,
|
||||
mock.NonCallableMagicMock,
|
||||
)
|
||||
_MOCK_CLASS_BASELINE = {cls: frozenset(vars(cls)) for cls in _MOCK_CLASSES}
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _reset_mock_class_attributes():
|
||||
"""Drop attributes a test sets on the mock classes themselves (`c = mock.MagicMock; c.provider = ...`), so they cannot leak into other tests' instances."""
|
||||
yield
|
||||
for cls, baseline in _MOCK_CLASS_BASELINE.items():
|
||||
for name in set(vars(cls)) - baseline:
|
||||
delattr(cls, name)
|
||||
@@ -0,0 +1,64 @@
|
||||
import os
|
||||
from functools import lru_cache
|
||||
|
||||
import pytest
|
||||
|
||||
from prowler.lib.check.compliance_models import load_compliance_framework_universal
|
||||
from prowler.lib.check.utils import recover_checks_from_provider
|
||||
|
||||
COMPLIANCE_DIR = os.path.normpath(
|
||||
os.path.join(os.path.dirname(__file__), "..", "..", "..", "prowler", "compliance")
|
||||
)
|
||||
|
||||
|
||||
def _compliance_jsons() -> list[str]:
|
||||
paths = []
|
||||
for root, _, files in os.walk(COMPLIANCE_DIR):
|
||||
paths.extend(os.path.join(root, f) for f in files if f.endswith(".json"))
|
||||
return sorted(paths)
|
||||
|
||||
|
||||
@lru_cache
|
||||
def _check_ids(provider: str) -> frozenset[str]:
|
||||
return frozenset(name for name, _ in recover_checks_from_provider(provider))
|
||||
|
||||
|
||||
@pytest.mark.parametrize("json_path", _compliance_jsons(), ids=os.path.basename)
|
||||
class TestComplianceCatalogIntegrity:
|
||||
def test_requirement_ids_are_unique(self, json_path):
|
||||
framework = load_compliance_framework_universal(json_path)
|
||||
assert framework is not None, f"Failed to load {json_path}"
|
||||
|
||||
ids = [requirement.id for requirement in framework.requirements]
|
||||
duplicated = sorted({rid for rid in ids if ids.count(rid) > 1})
|
||||
assert not duplicated, f"Duplicated requirement ids: {duplicated}"
|
||||
|
||||
def test_requirements_do_not_repeat_checks(self, json_path):
|
||||
framework = load_compliance_framework_universal(json_path)
|
||||
assert framework is not None, f"Failed to load {json_path}"
|
||||
|
||||
repeated = sorted(
|
||||
{
|
||||
(requirement.id, provider, check)
|
||||
for requirement in framework.requirements
|
||||
for provider, checks in requirement.checks.items()
|
||||
for check in checks
|
||||
if checks.count(check) > 1
|
||||
}
|
||||
)
|
||||
assert not repeated, f"Checks listed twice in a requirement: {repeated}"
|
||||
|
||||
def test_referenced_checks_exist_for_provider(self, json_path):
|
||||
framework = load_compliance_framework_universal(json_path)
|
||||
assert framework is not None, f"Failed to load {json_path}"
|
||||
|
||||
unknown = sorted(
|
||||
{
|
||||
(provider, check)
|
||||
for requirement in framework.requirements
|
||||
for provider, checks in requirement.checks.items()
|
||||
for check in checks
|
||||
if check not in _check_ids(provider)
|
||||
}
|
||||
)
|
||||
assert not unknown, f"Checks that do not exist for their provider: {unknown}"
|
||||
@@ -1,7 +1,11 @@
|
||||
import base64
|
||||
import hashlib
|
||||
from concurrent.futures import ThreadPoolExecutor
|
||||
from dataclasses import FrozenInstanceError
|
||||
from datetime import datetime, timedelta
|
||||
from logging import ERROR, WARNING
|
||||
from threading import Barrier
|
||||
from time import sleep
|
||||
from types import SimpleNamespace
|
||||
from typing import List, Optional
|
||||
from unittest.mock import MagicMock, PropertyMock, patch
|
||||
@@ -453,6 +457,36 @@ class TestJiraIntegration:
|
||||
assert access_token == "new_access_token"
|
||||
mock_refresh_access_token.assert_called_once()
|
||||
|
||||
def test_get_access_token_concurrent_refresh_happens_once(self):
|
||||
self.jira_integration.auth_expiration = (
|
||||
datetime.now() - timedelta(seconds=1)
|
||||
).isoformat()
|
||||
refresh_calls = []
|
||||
# All 5 pass the expiry check together, so without a lock every one of
|
||||
# them would refresh.
|
||||
barrier = Barrier(5, timeout=5)
|
||||
|
||||
def fake_refresh():
|
||||
refresh_calls.append(1)
|
||||
# Keep the token expired while the other threads check it.
|
||||
sleep(0.2)
|
||||
self.jira_integration._access_token = "refreshed_token"
|
||||
self.jira_integration.auth_expiration = (
|
||||
datetime.now() + timedelta(hours=1)
|
||||
).isoformat()
|
||||
return "refreshed_token"
|
||||
|
||||
def get_token(_):
|
||||
barrier.wait()
|
||||
return self.jira_integration.get_access_token()
|
||||
|
||||
with patch.object(Jira, "refresh_access_token", side_effect=fake_refresh):
|
||||
with ThreadPoolExecutor(max_workers=5) as executor:
|
||||
tokens = list(executor.map(get_token, range(5)))
|
||||
|
||||
assert tokens == ["refreshed_token"] * 5
|
||||
assert len(refresh_calls) == 1
|
||||
|
||||
@freeze_time(TEST_DATETIME)
|
||||
@patch("prowler.lib.outputs.jira.jira.requests.post")
|
||||
@patch.object(Jira, "get_cloud_id", return_value="test_cloud_id")
|
||||
@@ -749,6 +783,77 @@ class TestJiraIntegration:
|
||||
domain=self.domain,
|
||||
)
|
||||
|
||||
@patch.object(Jira, "get_auth", return_value=None)
|
||||
@patch.object(
|
||||
Jira,
|
||||
"get_projects",
|
||||
return_value={"PROJ1": "Project One", "PROJ2": "Project Two"},
|
||||
)
|
||||
def test_test_connection_partial_issue_types_failure(
|
||||
self, mock_get_projects, mock_get_auth, caplog
|
||||
):
|
||||
# To disable vulture
|
||||
mock_get_projects = mock_get_projects
|
||||
mock_get_auth = mock_get_auth
|
||||
caplog.set_level(WARNING)
|
||||
|
||||
def fake_issue_types(project_key):
|
||||
if project_key == "PROJ2":
|
||||
raise JiraGetAvailableIssueTypesError("no create permission")
|
||||
return ["Task"]
|
||||
|
||||
with patch.object(
|
||||
Jira, "get_available_issue_types", side_effect=fake_issue_types
|
||||
):
|
||||
connection = Jira.test_connection(
|
||||
redirect_uri=self.redirect_uri,
|
||||
client_id=self.client_id,
|
||||
client_secret=self.client_secret,
|
||||
)
|
||||
|
||||
assert connection.is_connected
|
||||
assert connection.error is None
|
||||
assert connection.issue_types == {"PROJ1": ["Task"]}
|
||||
assert any(
|
||||
record.levelno == WARNING
|
||||
and "Failed to get issue types for project PROJ2" in record.message
|
||||
for record in caplog.records
|
||||
)
|
||||
assert not any(record.levelno >= ERROR for record in caplog.records)
|
||||
|
||||
@patch.object(Jira, "get_auth", return_value=None)
|
||||
@patch.object(
|
||||
Jira,
|
||||
"get_projects",
|
||||
return_value={f"PROJ{i}": f"Project {i}" for i in range(5)},
|
||||
)
|
||||
def test_test_connection_fetches_issue_types_concurrently(
|
||||
self, mock_get_projects, mock_get_auth
|
||||
):
|
||||
# To disable vulture
|
||||
mock_get_projects = mock_get_projects
|
||||
mock_get_auth = mock_get_auth
|
||||
|
||||
# Every call blocks until all 5 arrive; a sequential fetch would time out
|
||||
# at the barrier and surface as a per-project failure instead of a result.
|
||||
barrier = Barrier(5, timeout=5)
|
||||
|
||||
def fake_issue_types(project_key):
|
||||
barrier.wait()
|
||||
return [project_key]
|
||||
|
||||
with patch.object(
|
||||
Jira, "get_available_issue_types", side_effect=fake_issue_types
|
||||
):
|
||||
connection = Jira.test_connection(
|
||||
redirect_uri=self.redirect_uri,
|
||||
client_id=self.client_id,
|
||||
client_secret=self.client_secret,
|
||||
)
|
||||
|
||||
assert connection.is_connected
|
||||
assert connection.issue_types == {f"PROJ{i}": [f"PROJ{i}"] for i in range(5)}
|
||||
|
||||
@patch.object(Jira, "get_auth", return_value=None)
|
||||
@patch.object(
|
||||
Jira, "get_projects", side_effect=JiraNoProjectsError("No projects found")
|
||||
@@ -998,6 +1103,76 @@ class TestJiraIntegration:
|
||||
with pytest.raises(JiraGetAvailableIssueTypesError):
|
||||
self.jira_integration.get_available_issue_types(project_key="TEST")
|
||||
|
||||
@patch.object(Jira, "get_access_token", return_value="valid_access_token")
|
||||
@patch.object(
|
||||
Jira, "cloud_id", new_callable=PropertyMock, return_value="test_cloud_id"
|
||||
)
|
||||
@patch("prowler.lib.outputs.jira.jira.requests.get")
|
||||
def test_get_available_issue_types_no_projects_does_not_log(
|
||||
self, mock_get, mock_cloud_id, mock_get_access_token, caplog
|
||||
):
|
||||
# To disable vulture
|
||||
mock_cloud_id = mock_cloud_id
|
||||
mock_get_access_token = mock_get_access_token
|
||||
caplog.set_level(WARNING)
|
||||
|
||||
mock_response = MagicMock()
|
||||
mock_response.status_code = 200
|
||||
mock_response.json.return_value = {"projects": []}
|
||||
mock_get.return_value = mock_response
|
||||
|
||||
with pytest.raises(JiraGetAvailableIssueTypesError):
|
||||
self.jira_integration.get_available_issue_types(project_key="TEST")
|
||||
|
||||
assert not any(record.levelno >= WARNING for record in caplog.records)
|
||||
|
||||
@patch.object(Jira, "get_auth", return_value=None)
|
||||
@patch.object(
|
||||
Jira,
|
||||
"get_projects",
|
||||
return_value={"TEST": "Test Project"},
|
||||
)
|
||||
@patch.object(Jira, "get_access_token", return_value="valid_access_token")
|
||||
@patch.object(
|
||||
Jira, "cloud_id", new_callable=PropertyMock, return_value="test_cloud_id"
|
||||
)
|
||||
@patch("prowler.lib.outputs.jira.jira.requests.get")
|
||||
def test_test_connection_empty_issue_types_logs_one_warning(
|
||||
self,
|
||||
mock_get,
|
||||
mock_cloud_id,
|
||||
mock_get_access_token,
|
||||
mock_get_projects,
|
||||
mock_get_auth,
|
||||
caplog,
|
||||
):
|
||||
# To disable vulture
|
||||
mock_cloud_id = mock_cloud_id
|
||||
mock_get_access_token = mock_get_access_token
|
||||
mock_get_projects = mock_get_projects
|
||||
mock_get_auth = mock_get_auth
|
||||
caplog.set_level(WARNING)
|
||||
|
||||
mock_response = MagicMock()
|
||||
mock_response.status_code = 200
|
||||
mock_response.json.return_value = {"projects": []}
|
||||
mock_get.return_value = mock_response
|
||||
|
||||
connection = Jira.test_connection(
|
||||
redirect_uri=self.redirect_uri,
|
||||
client_id=self.client_id,
|
||||
client_secret=self.client_secret,
|
||||
)
|
||||
|
||||
warnings = [
|
||||
record
|
||||
for record in caplog.records
|
||||
if record.levelno == WARNING and "project TEST" in record.message
|
||||
]
|
||||
assert connection.is_connected
|
||||
assert len(warnings) == 1
|
||||
assert not any(record.levelno >= ERROR for record in caplog.records)
|
||||
|
||||
@patch.object(Jira, "get_access_token", return_value="valid_access_token")
|
||||
@patch.object(
|
||||
Jira, "cloud_id", new_callable=PropertyMock, return_value="test_cloud_id"
|
||||
|
||||
+1
-1
@@ -48,7 +48,7 @@ def _run(policies: list, scan_unused_services: bool = True):
|
||||
iam_client = mock.MagicMock()
|
||||
iam_client.policies = {policy.arn: policy for policy in policies}
|
||||
iam_client.region = AWS_REGION_US_EAST_1
|
||||
iam_client.provider.scan_unused_services = scan_unused_services
|
||||
iam_client.provider = mock.MagicMock(scan_unused_services=scan_unused_services)
|
||||
|
||||
aws_provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
|
||||
|
||||
+2
-1
@@ -105,7 +105,8 @@ def _run(policies: list, scan_unused_services: bool = True):
|
||||
iam_client = mock.MagicMock()
|
||||
iam_client.policies = {policy.arn: policy for policy in policies}
|
||||
iam_client.region = AWS_REGION_US_EAST_1
|
||||
iam_client.provider.scan_unused_services = scan_unused_services
|
||||
# Own mock: other test files set MagicMock.provider at class level to a real AwsProvider.
|
||||
iam_client.provider = mock.MagicMock(scan_unused_services=scan_unused_services)
|
||||
|
||||
aws_provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
|
||||
|
||||
+9
-9
@@ -15,7 +15,7 @@ FINDING_ARN = (
|
||||
class Test_inspector2_active_findings_exist:
|
||||
def test_enabled_no_finding(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
@@ -69,7 +69,7 @@ class Test_inspector2_active_findings_exist:
|
||||
|
||||
def test_enabled_with_no_active_finding(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
@@ -123,7 +123,7 @@ class Test_inspector2_active_findings_exist:
|
||||
|
||||
def test_enabled_with_active_finding(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
@@ -176,7 +176,7 @@ class Test_inspector2_active_findings_exist:
|
||||
|
||||
def test_enabled_with_none_finding(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
@@ -219,14 +219,14 @@ class Test_inspector2_active_findings_exist:
|
||||
|
||||
def test_inspector2_disabled_ignoring(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
awslambda_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
awslambda_client = mock.MagicMock()
|
||||
awslambda_client.functions = {}
|
||||
ecr_client = mock.MagicMock
|
||||
ecr_client = mock.MagicMock()
|
||||
ecr_client.registries = {}
|
||||
ecr_client.registries[AWS_REGION_EU_WEST_1] = mock.MagicMock
|
||||
ecr_client.registries[AWS_REGION_EU_WEST_1] = mock.MagicMock()
|
||||
ecr_client.registries[AWS_REGION_EU_WEST_1].repositories = []
|
||||
ec2_client = mock.MagicMock
|
||||
ec2_client = mock.MagicMock()
|
||||
ec2_client.instances = []
|
||||
ec2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
ecr_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
|
||||
+19
-19
@@ -75,10 +75,10 @@ class Test_inspector2_is_enabled:
|
||||
|
||||
def test_inspector2_disabled(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
awslambda_client = mock.MagicMock
|
||||
ecr_client = mock.MagicMock
|
||||
ec2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
awslambda_client = mock.MagicMock()
|
||||
ecr_client = mock.MagicMock()
|
||||
ec2_client = mock.MagicMock()
|
||||
ec2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
ecr_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
awslambda_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
@@ -133,7 +133,7 @@ class Test_inspector2_is_enabled:
|
||||
|
||||
def test_all_enabled(self):
|
||||
# Mock the inspector2 client
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -235,7 +235,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -286,7 +286,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ecr_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -337,7 +337,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_lambda_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -388,7 +388,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -439,7 +439,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_ecr_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -490,7 +490,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_lambda_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -541,7 +541,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -592,7 +592,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ecr_lambda_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -643,7 +643,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ecr_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -694,7 +694,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_lambda_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -745,7 +745,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_ecr_lambda_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -796,7 +796,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_ecr_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -847,7 +847,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ec2_lambda_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
@@ -898,7 +898,7 @@ class Test_inspector2_is_enabled:
|
||||
assert result[0].region == AWS_REGION_EU_WEST_1
|
||||
|
||||
def test_ecr_lambda_lambda_code_disabled(self):
|
||||
inspector2_client = mock.MagicMock
|
||||
inspector2_client = mock.MagicMock()
|
||||
inspector2_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
inspector2_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
inspector2_client.audited_account_arn = (
|
||||
|
||||
+3
-3
@@ -13,7 +13,7 @@ from tests.providers.aws.utils import (
|
||||
class Test_macie_automated_sensitive_data_discovery_enabled:
|
||||
@mock_aws
|
||||
def test_macie_disabled(self):
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
macie_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
macie_client.audited_account_arn = f"arn:aws:iam::{AWS_ACCOUNT_NUMBER}:root"
|
||||
@@ -56,7 +56,7 @@ class Test_macie_automated_sensitive_data_discovery_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_enabled_automated_discovery_disabled(self):
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
macie_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
macie_client.audited_account_arn = f"arn:aws:iam::{AWS_ACCOUNT_NUMBER}:root"
|
||||
@@ -109,7 +109,7 @@ class Test_macie_automated_sensitive_data_discovery_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_enabled_automated_discovery_enabled(self):
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
macie_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
macie_client.audited_account_arn = f"arn:aws:iam::{AWS_ACCOUNT_NUMBER}:root"
|
||||
|
||||
@@ -14,12 +14,12 @@ from tests.providers.aws.utils import (
|
||||
class Test_macie_is_enabled:
|
||||
@mock_aws
|
||||
def test_macie_disabled(self):
|
||||
s3_client = mock.MagicMock
|
||||
s3_client = mock.MagicMock()
|
||||
s3_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
s3_client.buckets = {}
|
||||
s3_client.regions_with_buckets = []
|
||||
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_EU_WEST_1], create_default_organization=False
|
||||
)
|
||||
@@ -74,12 +74,12 @@ class Test_macie_is_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_enabled(self):
|
||||
s3_client = mock.MagicMock
|
||||
s3_client = mock.MagicMock()
|
||||
s3_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
s3_client.buckets = {}
|
||||
s3_client.regions_with_buckets = []
|
||||
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_EU_WEST_1], create_default_organization=False
|
||||
)
|
||||
@@ -134,12 +134,12 @@ class Test_macie_is_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_suspended_ignored(self):
|
||||
s3_client = mock.MagicMock
|
||||
s3_client = mock.MagicMock()
|
||||
s3_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
s3_client.buckets = {}
|
||||
s3_client.regions_with_buckets = []
|
||||
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_EU_WEST_1], create_default_organization=False
|
||||
)
|
||||
@@ -189,7 +189,7 @@ class Test_macie_is_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_suspended_ignored_with_buckets(self):
|
||||
s3_client = mock.MagicMock
|
||||
s3_client = mock.MagicMock()
|
||||
s3_client.regions_with_buckets = [AWS_REGION_EU_WEST_1]
|
||||
s3_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
s3_client.buckets = [
|
||||
@@ -200,7 +200,7 @@ class Test_macie_is_enabled:
|
||||
)
|
||||
]
|
||||
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_EU_WEST_1], create_default_organization=False
|
||||
)
|
||||
@@ -258,10 +258,10 @@ class Test_macie_is_enabled:
|
||||
|
||||
@mock_aws
|
||||
def test_macie_suspended(self):
|
||||
s3_client = mock.MagicMock
|
||||
s3_client = mock.MagicMock()
|
||||
s3_client.provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
|
||||
macie_client = mock.MagicMock
|
||||
macie_client = mock.MagicMock()
|
||||
macie_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_EU_WEST_1], create_default_organization=False
|
||||
)
|
||||
|
||||
+3
-3
@@ -14,7 +14,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_deletion_protection:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -42,7 +42,7 @@ class Test_networkfirewall_deletion_protection:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_deletion_protection_disabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -89,7 +89,7 @@ class Test_networkfirewall_deletion_protection:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_deletion_protection_enabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
+14
-14
@@ -15,13 +15,13 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_in_all_vpc:
|
||||
def test_no_vpcs(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
networkfirewall_client.region = AWS_REGION_US_EAST_1
|
||||
networkfirewall_client.network_firewalls = {}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {}
|
||||
@@ -51,7 +51,7 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_vpcs_with_firewall_all(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -68,7 +68,7 @@ class Test_networkfirewall_in_all_vpc:
|
||||
deletion_protection=True,
|
||||
)
|
||||
}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
@@ -134,13 +134,13 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert result[0].resource_arn == "arn_test"
|
||||
|
||||
def test_vpcs_without_firewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
networkfirewall_client.region = AWS_REGION_US_EAST_1
|
||||
networkfirewall_client.network_firewalls = {}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
@@ -206,14 +206,14 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert result[0].resource_arn == "arn_test"
|
||||
|
||||
def test_vpcs_with_name_without_firewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
networkfirewall_client.region = AWS_REGION_US_EAST_1
|
||||
networkfirewall_client.network_firewalls = {}
|
||||
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
@@ -279,7 +279,7 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert result[0].resource_arn == "arn_test"
|
||||
|
||||
def test_vpcs_with_and_without_firewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -296,7 +296,7 @@ class Test_networkfirewall_in_all_vpc:
|
||||
deletion_protection=True,
|
||||
)
|
||||
}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
@@ -400,13 +400,13 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert r.resource_arn == "arn_test"
|
||||
|
||||
def test_vpcs_without_firewall_ignoring(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
networkfirewall_client.region = AWS_REGION_US_EAST_1
|
||||
networkfirewall_client.network_firewalls = {}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
@@ -464,13 +464,13 @@ class Test_networkfirewall_in_all_vpc:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_vpcs_without_firewall_ignoring_vpc_in_use(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
networkfirewall_client.region = AWS_REGION_US_EAST_1
|
||||
networkfirewall_client.network_firewalls = {}
|
||||
vpc_client = mock.MagicMock
|
||||
vpc_client = mock.MagicMock()
|
||||
vpc_client.provider = set_mocked_aws_provider([AWS_REGION_US_EAST_1])
|
||||
vpc_client.region = AWS_REGION_US_EAST_1
|
||||
vpc_client.vpcs = {
|
||||
|
||||
+3
-3
@@ -17,7 +17,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_logging_enabled:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -45,7 +45,7 @@ class Test_networkfirewall_logging_enabled:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_logging_disabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -93,7 +93,7 @@ class Test_networkfirewall_logging_enabled:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_logging_enabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
+3
-3
@@ -16,7 +16,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_multi_az:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -44,7 +44,7 @@ class Test_networkfirewall_multi_az:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_multi_az_disabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -97,7 +97,7 @@ class Test_networkfirewall_multi_az:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_multi_az_enabled(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
+4
-4
@@ -14,7 +14,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_policy_default_action_fragmented_packets:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -42,7 +42,7 @@ class Test_networkfirewall_policy_default_action_fragmented_packets:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_default_stateless_action_drop(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -90,7 +90,7 @@ class Test_networkfirewall_policy_default_action_fragmented_packets:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_default_stateless_action_forward(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -139,7 +139,7 @@ class Test_networkfirewall_policy_default_action_fragmented_packets:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_default_stateless_action_pass(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
+4
-4
@@ -14,7 +14,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_policy_default_action_full_packets:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -42,7 +42,7 @@ class Test_networkfirewall_policy_default_action_full_packets:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_policy_default_action_drop(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -90,7 +90,7 @@ class Test_networkfirewall_policy_default_action_full_packets:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_policy_default_action_forward(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -139,7 +139,7 @@ class Test_networkfirewall_policy_default_action_full_packets:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_policy_default_action_pass(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
+5
-5
@@ -14,7 +14,7 @@ POLICY_ARN = "arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/my
|
||||
|
||||
class Test_networkfirewall_policy_rule_group_associated:
|
||||
def test_no_networkfirewall(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -42,7 +42,7 @@ class Test_networkfirewall_policy_rule_group_associated:
|
||||
assert len(result) == 0
|
||||
|
||||
def test_networkfirewall_policy_stateless_rule_group_associated(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -92,7 +92,7 @@ class Test_networkfirewall_policy_rule_group_associated:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_policy_stateful_rule_group_associated(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -142,7 +142,7 @@ class Test_networkfirewall_policy_rule_group_associated:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_policy_both_rule_groups_associated(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -196,7 +196,7 @@ class Test_networkfirewall_policy_rule_group_associated:
|
||||
assert result[0].resource_arn == FIREWALL_ARN
|
||||
|
||||
def test_networkfirewall_policy_no_rule_groups_associated(self):
|
||||
networkfirewall_client = mock.MagicMock
|
||||
networkfirewall_client = mock.MagicMock()
|
||||
networkfirewall_client.provider = set_mocked_aws_provider(
|
||||
[AWS_REGION_US_EAST_1]
|
||||
)
|
||||
|
||||
@@ -2,7 +2,7 @@ export {
|
||||
createIntegration,
|
||||
deleteIntegration,
|
||||
getIntegrations,
|
||||
pollConnectionTestStatus,
|
||||
revalidateIntegrationConnectionPages,
|
||||
testIntegrationConnection,
|
||||
updateIntegration,
|
||||
} from "./integrations";
|
||||
|
||||
@@ -0,0 +1,64 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const { fetchMock, revalidatePathMock } = vi.hoisted(() => ({
|
||||
fetchMock: vi.fn(),
|
||||
revalidatePathMock: vi.fn(),
|
||||
}));
|
||||
|
||||
vi.mock("next/cache", () => ({
|
||||
revalidatePath: revalidatePathMock,
|
||||
}));
|
||||
|
||||
vi.mock("@/lib", () => ({
|
||||
apiBaseUrl: "https://api.example.com/api/v1",
|
||||
getAuthHeaders: vi.fn().mockResolvedValue({ Authorization: "Bearer token" }),
|
||||
parseStringify: (value: unknown) => JSON.parse(JSON.stringify(value)),
|
||||
}));
|
||||
|
||||
vi.mock("@/lib/server-actions-helper", () => ({
|
||||
handleApiError: () => ({ error: "An error occurred" }),
|
||||
handleApiResponse: vi.fn(),
|
||||
}));
|
||||
|
||||
import {
|
||||
revalidateIntegrationConnectionPages,
|
||||
testIntegrationConnection,
|
||||
} from "./integrations";
|
||||
|
||||
describe("testIntegrationConnection", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
vi.stubGlobal("fetch", fetchMock);
|
||||
fetchMock.mockResolvedValue(
|
||||
new Response(JSON.stringify({ data: { id: "task-1", type: "tasks" } }), {
|
||||
status: 202,
|
||||
}),
|
||||
);
|
||||
});
|
||||
|
||||
it("returns the task immediately for shared background tracking", async () => {
|
||||
// When
|
||||
const response = await testIntegrationConnection("jira-1");
|
||||
|
||||
// Then
|
||||
expect(response).toEqual({
|
||||
success: true,
|
||||
message: "Connection test started. It may take some time to complete.",
|
||||
taskId: "task-1",
|
||||
data: { data: { id: "task-1", type: "tasks" } },
|
||||
});
|
||||
});
|
||||
|
||||
it("revalidates every integration page through one shared action", async () => {
|
||||
// When
|
||||
await revalidateIntegrationConnectionPages();
|
||||
|
||||
// Then
|
||||
expect(revalidatePathMock.mock.calls).toEqual([
|
||||
["/integrations/amazon-s3"],
|
||||
["/integrations/aws-security-hub"],
|
||||
["/integrations/jira"],
|
||||
["/integrations/slack"],
|
||||
]);
|
||||
});
|
||||
});
|
||||
@@ -2,25 +2,19 @@
|
||||
|
||||
import { revalidatePath } from "next/cache";
|
||||
|
||||
import { pollTaskUntilSettled } from "@/actions/task/poll";
|
||||
import { apiBaseUrl, getAuthHeaders, parseStringify } from "@/lib";
|
||||
import { handleApiError, handleApiResponse } from "@/lib/server-actions-helper";
|
||||
import { IntegrationType } from "@/types/integrations";
|
||||
import type { TaskState } from "@/types/tasks";
|
||||
import type {
|
||||
IntegrationConnectionTestResponse,
|
||||
IntegrationType,
|
||||
} from "@/types/integrations";
|
||||
|
||||
type TaskStartResponse = {
|
||||
data: { id: string; type: "tasks" };
|
||||
};
|
||||
|
||||
type TestConnectionResponse = {
|
||||
success: boolean;
|
||||
message?: string;
|
||||
taskId?: string;
|
||||
data?: TaskStartResponse;
|
||||
error?: string;
|
||||
/** The id of the channel a channel-level failure named, when it named one. */
|
||||
failedChannelId?: string | null;
|
||||
};
|
||||
const INTEGRATION_CONNECTION_PATHS = [
|
||||
"/integrations/amazon-s3",
|
||||
"/integrations/aws-security-hub",
|
||||
"/integrations/jira",
|
||||
"/integrations/slack",
|
||||
] as const;
|
||||
|
||||
export const getIntegrations = async (searchParams?: URLSearchParams) => {
|
||||
const headers = await getAuthHeaders({ contentType: false });
|
||||
@@ -266,59 +260,9 @@ export const deleteIntegration = async (
|
||||
}
|
||||
};
|
||||
|
||||
type ConnectionTaskResult = {
|
||||
connected?: boolean;
|
||||
error?: string | null;
|
||||
// The failing channel's id, or null when the failure names no channel.
|
||||
channel?: string | null;
|
||||
};
|
||||
|
||||
type PollConnectionResult =
|
||||
| {
|
||||
success: true;
|
||||
message: string;
|
||||
taskState: TaskState;
|
||||
result: ConnectionTaskResult | undefined;
|
||||
}
|
||||
| {
|
||||
success: false;
|
||||
message: string;
|
||||
taskState?: TaskState;
|
||||
result?: ConnectionTaskResult;
|
||||
}
|
||||
| { error: string };
|
||||
|
||||
const pollTaskUntilComplete = async (
|
||||
taskId: string,
|
||||
): Promise<PollConnectionResult> => {
|
||||
const settled = await pollTaskUntilSettled<ConnectionTaskResult>(taskId, {
|
||||
maxAttempts: 20,
|
||||
delayMs: 3000,
|
||||
});
|
||||
|
||||
if (!settled.ok) {
|
||||
return { error: settled.error };
|
||||
}
|
||||
|
||||
const taskState = settled.state;
|
||||
const result = settled.result;
|
||||
|
||||
const isSuccessful =
|
||||
taskState === "completed" &&
|
||||
result?.connected === true &&
|
||||
result?.error === null;
|
||||
|
||||
const message = isSuccessful
|
||||
? "Connection test completed successfully."
|
||||
: result?.error || "Connection test failed.";
|
||||
|
||||
return { success: isSuccessful, message, taskState, result };
|
||||
};
|
||||
|
||||
export const testIntegrationConnection = async (
|
||||
id: string,
|
||||
waitForCompletion = true,
|
||||
): Promise<TestConnectionResponse> => {
|
||||
): Promise<IntegrationConnectionTestResponse> => {
|
||||
const headers = await getAuthHeaders({ contentType: true });
|
||||
const url = new URL(`${apiBaseUrl}/integrations/${id}/connection`);
|
||||
|
||||
@@ -330,43 +274,13 @@ export const testIntegrationConnection = async (
|
||||
const taskId = data?.data?.id;
|
||||
|
||||
if (taskId) {
|
||||
// If waitForCompletion is false, return immediately with task started status
|
||||
if (!waitForCompletion) {
|
||||
return {
|
||||
success: true,
|
||||
message:
|
||||
"Connection test started. It may take some time to complete.",
|
||||
taskId,
|
||||
data: parseStringify(data),
|
||||
};
|
||||
}
|
||||
|
||||
// Poll the task until completion
|
||||
const pollResult = await pollTaskUntilComplete(taskId);
|
||||
|
||||
revalidatePath("/integrations/amazon-s3");
|
||||
revalidatePath("/integrations/aws-security-hub");
|
||||
revalidatePath("/integrations/jira");
|
||||
revalidatePath("/integrations/slack");
|
||||
|
||||
if ("error" in pollResult) {
|
||||
return { success: false, error: pollResult.error };
|
||||
}
|
||||
|
||||
if (pollResult.success) {
|
||||
return {
|
||||
success: true,
|
||||
message:
|
||||
pollResult.message || "Connection test completed successfully!",
|
||||
data: parseStringify(data),
|
||||
};
|
||||
} else {
|
||||
return {
|
||||
success: false,
|
||||
error: pollResult.message || "Connection test failed.",
|
||||
failedChannelId: pollResult.result?.channel ?? null,
|
||||
};
|
||||
}
|
||||
return {
|
||||
success: true,
|
||||
message:
|
||||
"Connection test started. It may take some time to complete.",
|
||||
taskId,
|
||||
data: parseStringify(data),
|
||||
};
|
||||
} else {
|
||||
return {
|
||||
success: false,
|
||||
@@ -386,35 +300,8 @@ export const testIntegrationConnection = async (
|
||||
}
|
||||
};
|
||||
|
||||
export const pollConnectionTestStatus = async (
|
||||
taskId: string,
|
||||
): Promise<TestConnectionResponse> => {
|
||||
try {
|
||||
const pollResult = await pollTaskUntilComplete(taskId);
|
||||
|
||||
revalidatePath("/integrations/amazon-s3");
|
||||
revalidatePath("/integrations/aws-security-hub");
|
||||
revalidatePath("/integrations/jira");
|
||||
revalidatePath("/integrations/slack");
|
||||
|
||||
if ("error" in pollResult) {
|
||||
return { success: false, error: pollResult.error };
|
||||
}
|
||||
|
||||
if (pollResult.success) {
|
||||
return {
|
||||
success: true,
|
||||
message:
|
||||
pollResult.message || "Connection test completed successfully!",
|
||||
};
|
||||
} else {
|
||||
return {
|
||||
success: false,
|
||||
error: pollResult.message || "Connection test failed.",
|
||||
failedChannelId: pollResult.result?.channel ?? null,
|
||||
};
|
||||
}
|
||||
} catch (_error) {
|
||||
return { success: false, error: "Failed to check connection test status." };
|
||||
export const revalidateIntegrationConnectionPages = async (): Promise<void> => {
|
||||
for (const path of INTEGRATION_CONNECTION_PATHS) {
|
||||
revalidatePath(path);
|
||||
}
|
||||
};
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
`nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low)
|
||||
@@ -0,0 +1 @@
|
||||
Integration connection test polling now waits up to ~3 minutes instead of ~57 seconds before giving up, so it no longer reports a false failure on slower checks (e.g. Jira accounts with many projects) that were still going to succeed
|
||||
@@ -0,0 +1 @@
|
||||
`next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4)
|
||||
@@ -0,0 +1 @@
|
||||
`sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c)
|
||||
@@ -0,0 +1,64 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const { revalidateIntegrationConnectionPagesMock, toastMock } = vi.hoisted(
|
||||
() => ({
|
||||
revalidateIntegrationConnectionPagesMock: vi.fn(),
|
||||
toastMock: vi.fn(),
|
||||
}),
|
||||
);
|
||||
|
||||
vi.mock("@/actions/integrations", () => ({
|
||||
revalidateIntegrationConnectionPages:
|
||||
revalidateIntegrationConnectionPagesMock,
|
||||
}));
|
||||
|
||||
vi.mock("@/components/shadcn/toast", () => ({
|
||||
toast: toastMock,
|
||||
}));
|
||||
|
||||
import { integrationConnectionTaskHandler } from "./integration-connection-task-handler";
|
||||
|
||||
const task = {
|
||||
taskId: "task-1",
|
||||
kind: "integration-connection-test",
|
||||
status: "ready" as const,
|
||||
meta: { integrationId: "jira-1" },
|
||||
startedAt: 1,
|
||||
};
|
||||
|
||||
describe("integration connection task handler", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
revalidateIntegrationConnectionPagesMock.mockResolvedValue(undefined);
|
||||
});
|
||||
|
||||
it("revalidates integrations and reports a resumed success", () => {
|
||||
// When
|
||||
integrationConnectionTaskHandler.onReady({
|
||||
...task,
|
||||
result: { connected: true, error: null },
|
||||
});
|
||||
|
||||
// Then
|
||||
expect(revalidateIntegrationConnectionPagesMock).toHaveBeenCalledOnce();
|
||||
expect(toastMock).toHaveBeenCalledWith({
|
||||
title: "Connection test successful!",
|
||||
description: "Connection test completed successfully.",
|
||||
});
|
||||
});
|
||||
|
||||
it("reports a resumed backend failure", () => {
|
||||
// When
|
||||
integrationConnectionTaskHandler.onReady({
|
||||
...task,
|
||||
result: { connected: false, error: "Missing permission" },
|
||||
});
|
||||
|
||||
// Then
|
||||
expect(toastMock).toHaveBeenCalledWith({
|
||||
variant: "destructive",
|
||||
title: "Connection test failed",
|
||||
description: "Missing permission",
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,42 @@
|
||||
"use client";
|
||||
|
||||
import { revalidateIntegrationConnectionPages } from "@/actions/integrations";
|
||||
import { toast } from "@/components/shadcn/toast";
|
||||
import { evaluateIntegrationConnectionTask } from "@/lib/integrations/test-connection-result";
|
||||
import type { TaskKindHandler } from "@/store/task-watcher/store";
|
||||
import type { IntegrationConnectionTaskResult } from "@/types/integrations";
|
||||
|
||||
const refreshIntegrationPages = (): void => {
|
||||
void revalidateIntegrationConnectionPages().catch(() => undefined);
|
||||
};
|
||||
|
||||
export const integrationConnectionTaskHandler: TaskKindHandler = {
|
||||
onReady: (task) => {
|
||||
refreshIntegrationPages();
|
||||
const result = evaluateIntegrationConnectionTask(
|
||||
task.result as IntegrationConnectionTaskResult | undefined,
|
||||
);
|
||||
|
||||
if (result.success) {
|
||||
toast({
|
||||
title: "Connection test successful!",
|
||||
description: result.message,
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
toast({
|
||||
variant: "destructive",
|
||||
title: "Connection test failed",
|
||||
description: result.error,
|
||||
});
|
||||
},
|
||||
onError: (task) => {
|
||||
refreshIntegrationPages();
|
||||
toast({
|
||||
variant: "destructive",
|
||||
title: "Connection test failed",
|
||||
description: task.error || "The connection test failed unexpectedly.",
|
||||
});
|
||||
},
|
||||
};
|
||||
@@ -4,11 +4,7 @@ import { format } from "date-fns";
|
||||
import { PlusIcon, Trash2Icon } from "lucide-react";
|
||||
import { useState } from "react";
|
||||
|
||||
import {
|
||||
deleteIntegration,
|
||||
testIntegrationConnection,
|
||||
updateIntegration,
|
||||
} from "@/actions/integrations";
|
||||
import { deleteIntegration, updateIntegration } from "@/actions/integrations";
|
||||
import { JiraIcon } from "@/components/icons/services/IconServices";
|
||||
import {
|
||||
IntegrationActionButtons,
|
||||
@@ -24,7 +20,10 @@ import {
|
||||
} from "@/components/shadcn";
|
||||
import { Modal } from "@/components/shadcn/modal";
|
||||
import { DataTablePagination } from "@/components/shadcn/table/data-table-pagination";
|
||||
import { triggerTestConnectionWithDelay } from "@/lib/integrations/test-connection-helper";
|
||||
import {
|
||||
executeIntegrationConnectionTest,
|
||||
triggerTestConnectionWithDelay,
|
||||
} from "@/lib/integrations/test-connection-helper";
|
||||
import { MetaDataProps } from "@/types";
|
||||
import { IntegrationProps } from "@/types/integrations";
|
||||
|
||||
@@ -98,7 +97,7 @@ export const JiraIntegrationsManager = ({
|
||||
const handleTestConnection = async (id: string) => {
|
||||
setIsTesting(id);
|
||||
try {
|
||||
const result = await testIntegrationConnection(id);
|
||||
const result = await executeIntegrationConnectionTest(id);
|
||||
|
||||
if (result.success) {
|
||||
toast({
|
||||
|
||||
@@ -4,11 +4,7 @@ import { format } from "date-fns";
|
||||
import { PlusIcon, Trash2Icon } from "lucide-react";
|
||||
import { useState } from "react";
|
||||
|
||||
import {
|
||||
deleteIntegration,
|
||||
testIntegrationConnection,
|
||||
updateIntegration,
|
||||
} from "@/actions/integrations";
|
||||
import { deleteIntegration, updateIntegration } from "@/actions/integrations";
|
||||
import { AmazonS3Icon } from "@/components/icons/services/IconServices";
|
||||
import {
|
||||
IntegrationActionButtons,
|
||||
@@ -24,7 +20,10 @@ import {
|
||||
} from "@/components/shadcn";
|
||||
import { Modal } from "@/components/shadcn/modal";
|
||||
import { DataTablePagination } from "@/components/shadcn/table/data-table-pagination";
|
||||
import { triggerTestConnectionWithDelay } from "@/lib/integrations/test-connection-helper";
|
||||
import {
|
||||
executeIntegrationConnectionTest,
|
||||
triggerTestConnectionWithDelay,
|
||||
} from "@/lib/integrations/test-connection-helper";
|
||||
import { MetaDataProps } from "@/types";
|
||||
import { IntegrationProps } from "@/types/integrations";
|
||||
import { ProviderProps } from "@/types/providers";
|
||||
@@ -112,7 +111,7 @@ export const S3IntegrationsManager = ({
|
||||
const handleTestConnection = async (id: string) => {
|
||||
setIsTesting(id);
|
||||
try {
|
||||
const result = await testIntegrationConnection(id);
|
||||
const result = await executeIntegrationConnectionTest(id);
|
||||
|
||||
if (result.success) {
|
||||
toast({
|
||||
|
||||
@@ -4,11 +4,7 @@ import { format } from "date-fns";
|
||||
import { PlusIcon, Trash2Icon } from "lucide-react";
|
||||
import { useState } from "react";
|
||||
|
||||
import {
|
||||
deleteIntegration,
|
||||
testIntegrationConnection,
|
||||
updateIntegration,
|
||||
} from "@/actions/integrations";
|
||||
import { deleteIntegration, updateIntegration } from "@/actions/integrations";
|
||||
import { AWSSecurityHubIcon } from "@/components/icons/services/IconServices";
|
||||
import {
|
||||
IntegrationActionButtons,
|
||||
@@ -25,7 +21,10 @@ import {
|
||||
} from "@/components/shadcn";
|
||||
import { Modal } from "@/components/shadcn/modal";
|
||||
import { DataTablePagination } from "@/components/shadcn/table/data-table-pagination";
|
||||
import { triggerTestConnectionWithDelay } from "@/lib/integrations/test-connection-helper";
|
||||
import {
|
||||
executeIntegrationConnectionTest,
|
||||
triggerTestConnectionWithDelay,
|
||||
} from "@/lib/integrations/test-connection-helper";
|
||||
import { MetaDataProps } from "@/types";
|
||||
import { IntegrationProps } from "@/types/integrations";
|
||||
import { ProviderProps } from "@/types/providers";
|
||||
@@ -114,7 +113,7 @@ export const SecurityHubIntegrationsManager = ({
|
||||
const handleTestConnection = async (id: string) => {
|
||||
setIsTesting(id);
|
||||
try {
|
||||
const result = await testIntegrationConnection(id);
|
||||
const result = await executeIntegrationConnectionTest(id);
|
||||
|
||||
if (result.success) {
|
||||
toast({
|
||||
|
||||
@@ -17,8 +17,8 @@ vi.mock("@/actions/integrations/slack", () => ({
|
||||
setSlackAuthorizedChannels: vi.fn(),
|
||||
}));
|
||||
|
||||
vi.mock("@/actions/integrations/integrations", () => ({
|
||||
testIntegrationConnection: vi.fn(),
|
||||
vi.mock("@/lib/integrations/test-connection-helper", () => ({
|
||||
executeIntegrationConnectionTest: vi.fn(),
|
||||
}));
|
||||
|
||||
/**
|
||||
|
||||
@@ -4,7 +4,6 @@ import { format, isValid, parseISO } from "date-fns";
|
||||
import { TestTube, Unplug } from "lucide-react";
|
||||
import { type ReactNode, useEffect, useState } from "react";
|
||||
|
||||
import { testIntegrationConnection } from "@/actions/integrations/integrations";
|
||||
import {
|
||||
disconnectSlackIntegration,
|
||||
getSlackAuthorizeUrl,
|
||||
@@ -37,6 +36,7 @@ import {
|
||||
slackErrorMessage,
|
||||
} from "@/lib/integrations/slack-errors";
|
||||
import type { SlackTokenErrorCode } from "@/lib/integrations/slack-errors";
|
||||
import { executeIntegrationConnectionTest } from "@/lib/integrations/test-connection-helper";
|
||||
import type {
|
||||
IntegrationProps,
|
||||
SlackAuthorizedChannel,
|
||||
@@ -492,7 +492,7 @@ export const SlackIntegrationManager = ({
|
||||
|
||||
setIsTesting(true);
|
||||
try {
|
||||
const result = await testIntegrationConnection(id);
|
||||
const result = await executeIntegrationConnectionTest(id);
|
||||
|
||||
if (result.success) {
|
||||
provedCredentialAlive();
|
||||
|
||||
@@ -9,12 +9,16 @@ import {
|
||||
crossProviderPdfHandler,
|
||||
} from "@/app/(prowler)/compliance/_lib/cross-provider-pdf";
|
||||
import { jiraDispatchTaskHandler } from "@/components/findings/jira-dispatch-task-handler";
|
||||
import { integrationConnectionTaskHandler } from "@/components/integrations/integration-connection-task-handler";
|
||||
import { useMountEffect } from "@/hooks/use-mount-effect";
|
||||
import {
|
||||
registerTaskKindHandler,
|
||||
resumePendingTasks,
|
||||
} from "@/store/task-watcher/store";
|
||||
import { JIRA_DISPATCH_TASK_KIND } from "@/types/integrations";
|
||||
import {
|
||||
INTEGRATION_CONNECTION_TASK_KIND,
|
||||
JIRA_DISPATCH_TASK_KIND,
|
||||
} from "@/types/integrations";
|
||||
|
||||
// Kind registrations happen at module scope, before any task can settle in
|
||||
// this tab. Adding a new watched task kind (integration tests, scan exports,
|
||||
@@ -22,6 +26,10 @@ import { JIRA_DISPATCH_TASK_KIND } from "@/types/integrations";
|
||||
registerTaskKindHandler(CROSS_PROVIDER_PDF_TASK_KIND, crossProviderPdfHandler);
|
||||
registerTaskKindHandler(CROSS_ACCOUNT_PDF_TASK_KIND, crossAccountPdfHandler);
|
||||
registerTaskKindHandler(JIRA_DISPATCH_TASK_KIND, jiraDispatchTaskHandler);
|
||||
registerTaskKindHandler(
|
||||
INTEGRATION_CONNECTION_TASK_KIND,
|
||||
integrationConnectionTaskHandler,
|
||||
);
|
||||
|
||||
/**
|
||||
* Mounted once in the app layout (next to `Toaster`): resumes polling any
|
||||
|
||||
+14
-14
@@ -442,10 +442,10 @@
|
||||
{
|
||||
"section": "dependencies",
|
||||
"name": "js-yaml",
|
||||
"from": "4.1.1",
|
||||
"to": "4.3.0",
|
||||
"from": "4.3.0",
|
||||
"to": "4.3.1",
|
||||
"strategy": "installed",
|
||||
"generatedAt": "2026-07-16T15:29:57.887Z"
|
||||
"generatedAt": "2026-09-08T07:45:48.316Z"
|
||||
},
|
||||
{
|
||||
"section": "dependencies",
|
||||
@@ -491,17 +491,17 @@
|
||||
"section": "dependencies",
|
||||
"name": "nanoid",
|
||||
"from": "5.1.6",
|
||||
"to": "5.1.6",
|
||||
"to": "5.1.16",
|
||||
"strategy": "installed",
|
||||
"generatedAt": "2025-12-10T11:34:11.122Z"
|
||||
"generatedAt": "2026-09-08T07:45:48.316Z"
|
||||
},
|
||||
{
|
||||
"section": "dependencies",
|
||||
"name": "next",
|
||||
"from": "16.2.9",
|
||||
"to": "16.2.11",
|
||||
"from": "16.2.11",
|
||||
"to": "16.3.3",
|
||||
"strategy": "installed",
|
||||
"generatedAt": "2026-07-24T08:32:45.227Z"
|
||||
"generatedAt": "2026-09-09T12:23:05.642Z"
|
||||
},
|
||||
{
|
||||
"section": "dependencies",
|
||||
@@ -594,10 +594,10 @@
|
||||
{
|
||||
"section": "dependencies",
|
||||
"name": "sharp",
|
||||
"from": "0.33.5",
|
||||
"to": "0.35.3",
|
||||
"from": "0.35.3",
|
||||
"to": "0.35.4",
|
||||
"strategy": "installed",
|
||||
"generatedAt": "2026-08-11T11:35:35.609Z"
|
||||
"generatedAt": "2026-09-09T12:39:08.649Z"
|
||||
},
|
||||
{
|
||||
"section": "dependencies",
|
||||
@@ -930,10 +930,10 @@
|
||||
{
|
||||
"section": "devDependencies",
|
||||
"name": "postcss",
|
||||
"from": "8.4.38",
|
||||
"to": "8.5.14",
|
||||
"from": "8.5.14",
|
||||
"to": "8.5.23",
|
||||
"strategy": "installed",
|
||||
"generatedAt": "2026-05-14T10:09:04.901Z"
|
||||
"generatedAt": "2026-09-08T07:45:48.316Z"
|
||||
},
|
||||
{
|
||||
"section": "devDependencies",
|
||||
|
||||
@@ -0,0 +1,125 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const {
|
||||
revalidateIntegrationConnectionPagesMock,
|
||||
testIntegrationConnectionMock,
|
||||
trackAndPollTaskMock,
|
||||
} = vi.hoisted(() => ({
|
||||
revalidateIntegrationConnectionPagesMock: vi.fn(),
|
||||
testIntegrationConnectionMock: vi.fn(),
|
||||
trackAndPollTaskMock: vi.fn(),
|
||||
}));
|
||||
|
||||
vi.mock("@/actions/integrations", () => ({
|
||||
revalidateIntegrationConnectionPages:
|
||||
revalidateIntegrationConnectionPagesMock,
|
||||
testIntegrationConnection: testIntegrationConnectionMock,
|
||||
}));
|
||||
|
||||
vi.mock("@/store/task-watcher/store", () => ({
|
||||
TASK_WATCHER_STATUS: { READY: "ready", ERROR: "error" },
|
||||
trackAndPollTask: trackAndPollTaskMock,
|
||||
}));
|
||||
|
||||
import {
|
||||
executeIntegrationConnectionTest,
|
||||
runTestConnection,
|
||||
} from "./test-connection-helper";
|
||||
|
||||
describe("integration connection test helper", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
revalidateIntegrationConnectionPagesMock.mockResolvedValue(undefined);
|
||||
testIntegrationConnectionMock.mockResolvedValue({
|
||||
success: true,
|
||||
taskId: "task-1",
|
||||
});
|
||||
trackAndPollTaskMock.mockResolvedValue({
|
||||
status: "ready",
|
||||
result: { connected: true, error: null },
|
||||
});
|
||||
});
|
||||
|
||||
it("tracks a started test through the shared task watcher", async () => {
|
||||
// Given
|
||||
const onStarted = vi.fn();
|
||||
|
||||
// When
|
||||
const result = await executeIntegrationConnectionTest("jira-1", onStarted);
|
||||
|
||||
// Then
|
||||
expect(onStarted).toHaveBeenCalledOnce();
|
||||
expect(trackAndPollTaskMock).toHaveBeenCalledWith({
|
||||
taskId: "task-1",
|
||||
kind: "integration-connection-test",
|
||||
meta: { integrationId: "jira-1" },
|
||||
notifyHandler: false,
|
||||
});
|
||||
expect(revalidateIntegrationConnectionPagesMock).toHaveBeenCalledOnce();
|
||||
expect(result).toEqual({
|
||||
success: true,
|
||||
message: "Connection test completed successfully.",
|
||||
});
|
||||
});
|
||||
|
||||
it("preserves the backend connection failure details", async () => {
|
||||
// Given
|
||||
trackAndPollTaskMock.mockResolvedValue({
|
||||
status: "ready",
|
||||
result: {
|
||||
connected: false,
|
||||
error: "Channel unavailable",
|
||||
channel: "C123",
|
||||
},
|
||||
});
|
||||
|
||||
// When
|
||||
const result = await executeIntegrationConnectionTest("slack-1");
|
||||
|
||||
// Then
|
||||
expect(result).toEqual({
|
||||
success: false,
|
||||
error: "Channel unavailable",
|
||||
failedChannelId: "C123",
|
||||
});
|
||||
});
|
||||
|
||||
it("surfaces task watcher failures", async () => {
|
||||
// Given
|
||||
trackAndPollTaskMock.mockResolvedValue({
|
||||
status: "error",
|
||||
error: "The task is taking too long. Try again later.",
|
||||
});
|
||||
|
||||
// When
|
||||
const result = await executeIntegrationConnectionTest("jira-1");
|
||||
|
||||
// Then
|
||||
expect(result).toEqual({
|
||||
success: false,
|
||||
error: "The task is taking too long. Try again later.",
|
||||
});
|
||||
});
|
||||
|
||||
it("completes once when the task cannot be started", async () => {
|
||||
// Given
|
||||
const onComplete = vi.fn();
|
||||
const onError = vi.fn();
|
||||
testIntegrationConnectionMock.mockResolvedValue({
|
||||
success: false,
|
||||
error: "Could not start",
|
||||
});
|
||||
|
||||
// When
|
||||
await runTestConnection({
|
||||
integrationId: "jira-1",
|
||||
integrationType: "jira",
|
||||
onComplete,
|
||||
onError,
|
||||
});
|
||||
|
||||
// Then
|
||||
expect(onError).toHaveBeenCalledWith("Could not start");
|
||||
expect(onComplete).toHaveBeenCalledOnce();
|
||||
});
|
||||
});
|
||||
@@ -1,7 +1,18 @@
|
||||
import {
|
||||
pollConnectionTestStatus,
|
||||
revalidateIntegrationConnectionPages,
|
||||
testIntegrationConnection,
|
||||
} from "@/actions/integrations";
|
||||
import type { useToast } from "@/components/shadcn/toast/use-toast";
|
||||
import { evaluateIntegrationConnectionTask } from "@/lib/integrations/test-connection-result";
|
||||
import {
|
||||
TASK_WATCHER_STATUS,
|
||||
trackAndPollTask,
|
||||
} from "@/store/task-watcher/store";
|
||||
import {
|
||||
INTEGRATION_CONNECTION_TASK_KIND,
|
||||
type IntegrationConnectionTaskResult,
|
||||
type IntegrationConnectionTestResponse,
|
||||
} from "@/types/integrations";
|
||||
|
||||
// Integration configuration type
|
||||
export interface IntegrationMessages {
|
||||
@@ -58,6 +69,47 @@ interface TestConnectionOptions {
|
||||
onComplete?: () => void;
|
||||
}
|
||||
|
||||
export const executeIntegrationConnectionTest = async (
|
||||
integrationId: string,
|
||||
onStarted?: () => void,
|
||||
): Promise<IntegrationConnectionTestResponse> => {
|
||||
const started = await testIntegrationConnection(integrationId);
|
||||
|
||||
if (!started.success) {
|
||||
return {
|
||||
success: false,
|
||||
error: started.error || "Connection test could not be started.",
|
||||
};
|
||||
}
|
||||
|
||||
if (!started.taskId) {
|
||||
return {
|
||||
success: false,
|
||||
error: "Failed to start connection test. No task ID received.",
|
||||
};
|
||||
}
|
||||
|
||||
onStarted?.();
|
||||
|
||||
const tracked = await trackAndPollTask<IntegrationConnectionTaskResult>({
|
||||
taskId: started.taskId,
|
||||
kind: INTEGRATION_CONNECTION_TASK_KIND,
|
||||
meta: { integrationId },
|
||||
notifyHandler: false,
|
||||
});
|
||||
|
||||
await revalidateIntegrationConnectionPages();
|
||||
|
||||
if (tracked.status !== TASK_WATCHER_STATUS.READY) {
|
||||
return {
|
||||
success: false,
|
||||
error: tracked.error || "Failed to track the connection test.",
|
||||
};
|
||||
}
|
||||
|
||||
return evaluateIntegrationConnectionTask(tracked.result);
|
||||
};
|
||||
|
||||
export const runTestConnection = async ({
|
||||
integrationId,
|
||||
integrationType,
|
||||
@@ -67,44 +119,22 @@ export const runTestConnection = async ({
|
||||
onComplete,
|
||||
}: TestConnectionOptions) => {
|
||||
try {
|
||||
// Start the test without waiting for completion
|
||||
const result = await testIntegrationConnection(integrationId, false);
|
||||
const result = await executeIntegrationConnectionTest(
|
||||
integrationId,
|
||||
onStart,
|
||||
);
|
||||
|
||||
if (!result || (!result.success && !result.error)) {
|
||||
onError?.("Connection test could not be started. Please try again.");
|
||||
onComplete?.();
|
||||
return;
|
||||
}
|
||||
|
||||
if (result.error) {
|
||||
onError?.(result.error);
|
||||
onComplete?.();
|
||||
return;
|
||||
}
|
||||
|
||||
if (!result.taskId) {
|
||||
onError?.("Failed to start connection test. No task ID received.");
|
||||
onComplete?.();
|
||||
return;
|
||||
}
|
||||
|
||||
// Notify that test has started
|
||||
onStart?.();
|
||||
|
||||
// Poll for the test completion
|
||||
const pollResult = await pollConnectionTestStatus(result.taskId);
|
||||
|
||||
if (pollResult.success) {
|
||||
if (result.success) {
|
||||
const config = INTEGRATION_CONFIG[integrationType];
|
||||
const defaultMessage =
|
||||
config?.successMessage ||
|
||||
`Successfully connected to ${integrationType}.`;
|
||||
onSuccess?.(pollResult.message || defaultMessage);
|
||||
onSuccess?.(result.message || defaultMessage);
|
||||
} else {
|
||||
const config = INTEGRATION_CONFIG[integrationType];
|
||||
const defaultError =
|
||||
config?.errorMessage || `Failed to connect to ${integrationType}.`;
|
||||
onError?.(pollResult.error || defaultError);
|
||||
onError?.(result.error || defaultError);
|
||||
}
|
||||
} catch (_error) {
|
||||
onError?.(
|
||||
@@ -119,7 +149,7 @@ export const triggerTestConnectionWithDelay = (
|
||||
integrationId: string | undefined,
|
||||
shouldTestConnection: boolean | undefined,
|
||||
integrationType: string,
|
||||
toast: any,
|
||||
toast: ReturnType<typeof useToast>["toast"],
|
||||
delay = 200,
|
||||
onComplete?: () => void,
|
||||
) => {
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
import type {
|
||||
IntegrationConnectionTaskResult,
|
||||
IntegrationConnectionTestResponse,
|
||||
} from "@/types/integrations";
|
||||
|
||||
export const evaluateIntegrationConnectionTask = (
|
||||
result: IntegrationConnectionTaskResult | undefined,
|
||||
): IntegrationConnectionTestResponse => {
|
||||
const isSuccessful = result?.connected === true && result.error === null;
|
||||
|
||||
if (isSuccessful) {
|
||||
return {
|
||||
success: true,
|
||||
message: "Connection test completed successfully.",
|
||||
};
|
||||
}
|
||||
|
||||
return {
|
||||
success: false,
|
||||
error: result?.error || "Connection test failed.",
|
||||
failedChannelId: result?.channel ?? null,
|
||||
};
|
||||
};
|
||||
+5
-5
@@ -90,14 +90,14 @@
|
||||
"driver.js": "1.4.0",
|
||||
"framer-motion": "11.18.2",
|
||||
"import-in-the-middle": "3.3.1",
|
||||
"js-yaml": "4.3.0",
|
||||
"js-yaml": "4.3.1",
|
||||
"jwt-decode": "4.0.0",
|
||||
"langchain": "1.4.0",
|
||||
"lucide-react": "0.543.0",
|
||||
"marked": "15.0.12",
|
||||
"modern-screenshot": "4.7.0",
|
||||
"nanoid": "5.1.6",
|
||||
"next": "16.2.11",
|
||||
"nanoid": "5.1.16",
|
||||
"next": "16.3.3",
|
||||
"next-auth": "5.0.0-beta.32",
|
||||
"next-themes": "0.2.1",
|
||||
"posthog-js": "1.407.2",
|
||||
@@ -109,7 +109,7 @@
|
||||
"recharts": "2.15.4",
|
||||
"require-in-the-middle": "8.0.1",
|
||||
"server-only": "0.0.1",
|
||||
"sharp": "0.35.3",
|
||||
"sharp": "0.35.4",
|
||||
"streamdown": "1.6.10",
|
||||
"tailwind-merge": "3.3.1",
|
||||
"tailwindcss-animate": "1.0.7",
|
||||
@@ -153,7 +153,7 @@
|
||||
"jsdom": "27.4.0",
|
||||
"knip": "6.3.1",
|
||||
"msw": "2.13.4",
|
||||
"postcss": "8.5.14",
|
||||
"postcss": "8.5.23",
|
||||
"prettier": "3.6.2",
|
||||
"prettier-plugin-packagejson": "2.5.22",
|
||||
"prettier-plugin-tailwindcss": "0.6.14",
|
||||
|
||||
Generated
+456
-381
File diff suppressed because it is too large
Load Diff
+55
-19
@@ -18,21 +18,25 @@ overrides:
|
||||
"@react-aria/visually-hidden>react": "19.2.7"
|
||||
"@react-aria/interactions>react": "19.2.7"
|
||||
"lodash": "4.18.1"
|
||||
# sharp 0.33.x/0.34.x carry GHSA-f88m-g3jw-g9cj; next pulls 0.34.5 transitively.
|
||||
"sharp": "0.35.3"
|
||||
# Next.js 16.3.3 requests sharp ^0.35.3; resolve 0.35.4 to fix
|
||||
# GHSA-rgj7-g3m4-5g8c (libheif). This override controls resolution;
|
||||
# keep it aligned with the direct dependency in package.json.
|
||||
"sharp": "0.35.4"
|
||||
"lodash-es": "4.18.1"
|
||||
# GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials) + 4 moderate
|
||||
# advisories (serve-static path traversal, Lambda Set-Cookie merge, body-limit
|
||||
# bypass, Lambda@Edge repeated-header loss), all fixed in 4.12.25, plus
|
||||
# CVE-2026-59896 (hono/jsx SSR context leak across concurrent requests; in NVD
|
||||
# but not yet in the npm audit feed), fixed in 4.12.27. Not 4.12.29: it is
|
||||
# still inside StepSecurity's 7-day npm cooldown gate.
|
||||
"hono": "4.12.28"
|
||||
"@hono/node-server": "1.19.14"
|
||||
# GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials), CVE-2026-59896
|
||||
# (hono/jsx SSR context leak) and the 4.12.34 batch: CORS ReDoS via
|
||||
# Access-Control-Request-Headers, `memo()` SSR output retained across requests,
|
||||
# Language middleware algorithmic DoS, Proxy Helper keeping `Connection` headers.
|
||||
# Node adapter 1.19.17 fixes serve-static path traversal via `%5C` on Windows
|
||||
# (1.19.15 was published without provenance and trips `trustPolicy: no-downgrade`).
|
||||
"hono": "4.12.34"
|
||||
"@hono/node-server": "1.19.17"
|
||||
"@isaacs/brace-expansion": "5.0.1"
|
||||
"fast-xml-parser": "5.8.0"
|
||||
"serialize-javascript": "7.0.5"
|
||||
"postcss": "8.5.14"
|
||||
# GHSA-6g55-p6wh-862q (sourceMappingURL path traversal reads arbitrary .map files)
|
||||
# and its incomplete-fix follow-up when `from` is unset, both closed in 8.5.23.
|
||||
"postcss": "8.5.23"
|
||||
"esbuild": "0.28.1"
|
||||
"rollup@>=4": "4.59.0"
|
||||
# GHSA-fx2h-pf6j-xcff (server.fs.deny bypass on Windows alternate paths, high) +
|
||||
@@ -52,10 +56,11 @@ overrides:
|
||||
# fixed in 7.29.1. An override instead of `pnpm update` so the rest of the
|
||||
# babel/browserslist subtree keeps its existing lockfile resolutions.
|
||||
"@babel/core": "7.29.7"
|
||||
# Ephemeral cooldown pins: the @babel/helper-compilation-targets refresh pulls
|
||||
# browserslist-ecosystem releases newer than StepSecurity's 7-day npm cooldown.
|
||||
# Safe to drop after 2026-07-20.
|
||||
"browserslist": "4.28.2"
|
||||
# browserslist 4.28.7 fixes unbounded query-result cache growth (OOM) and an
|
||||
# uncaught crash / prototype write from untrusted browserslist-stats.json.
|
||||
# caniuse-lite and baseline-browser-mapping stay pinned so the babel subtree
|
||||
# does not float past StepSecurity's 7-day npm cooldown gate.
|
||||
"browserslist": "4.28.7"
|
||||
"caniuse-lite": "1.0.30001792"
|
||||
"baseline-browser-mapping": "2.10.29"
|
||||
"minimatch@<4": "3.1.4"
|
||||
@@ -63,7 +68,9 @@ overrides:
|
||||
"minimatch@>=10": "10.2.3"
|
||||
"ajv@<7": "6.14.0"
|
||||
"ajv@>=8": "8.18.0"
|
||||
"qs": "6.15.2"
|
||||
# 6.16.0 fixes the bracket-key comma array-limit bypass and DoS via an
|
||||
# attacker-controlled isBuffer.
|
||||
"qs": "6.16.0"
|
||||
# 8.2.2 dropped provenance attestation; 8.3.1+ restored it. Pinned to skip 8.2.2
|
||||
# under `trustPolicy: no-downgrade`.
|
||||
"express-rate-limit": "8.5.1"
|
||||
@@ -73,9 +80,38 @@ overrides:
|
||||
# but the override unifies the tree on a patched version.
|
||||
"uuid": "11.1.1"
|
||||
# GHSA-vxr8-fq34-vvx9 (+ several related XSS sanitization bypasses): DOMPurify < 3.4.9,
|
||||
# pulled in transitively via streamdown > mermaid (which wants ^3.3.1). Bumped to 3.4.11
|
||||
# for GHSA-cmwh-pvxp-8882 (permanent ALLOWED_ATTR pollution via setConfig()).
|
||||
"dompurify": "3.4.11"
|
||||
# pulled in transitively via streamdown > mermaid and posthog-js. 3.4.11 closed
|
||||
# GHSA-cmwh-pvxp-8882 (permanent ALLOWED_ATTR pollution via setConfig()); 3.4.13
|
||||
# also closes the CUSTOM_ELEMENT_HANDLING afterSanitizeElements bypass and the
|
||||
# IN_PLACE hook removal that left a detached subtree executable.
|
||||
"dompurify": "3.4.13"
|
||||
|
||||
# Advisories flagged by `pnpm audit` on 2026-09-08. Every pin below is the
|
||||
# oldest patched release and was published more than 7 days before that date,
|
||||
# so it clears StepSecurity's npm cooldown gate.
|
||||
# brace-expansion: three DoS advisories (exponential `{}` expansion, unbounded
|
||||
# expansion length OOM, unbounded intermediate arrays bypassing the
|
||||
# CVE-2026-14257 mitigation). 1.x via eslint > minimatch, 5.x via @sentry > glob.
|
||||
"brace-expansion@<2": "1.1.18"
|
||||
"brace-expansion@>=5": "5.0.9"
|
||||
# fast-uri (via ajv): host confusion through backslash authority delimiters,
|
||||
# failed IDN canonicalization and percent-encoded scheme normalization, plus SSRF
|
||||
# via malformed IPv6 normalization and repeated hostname percent-decoding.
|
||||
"fast-uri": "3.1.6"
|
||||
# ip-address (via express-rate-limit): SSRF / trust-boundary bypasses from
|
||||
# leading-zero octets, CIDR suffixes and IPv4-mapped / NAT64 misclassification.
|
||||
"ip-address": "10.3.1"
|
||||
# mermaid (via streamdown): prototype pollution in config APIs and Architecture
|
||||
# diagrams, CSS injection into sibling elements, XY Chart infinite loop and
|
||||
# radar diagram DoS.
|
||||
"mermaid": "11.16.1"
|
||||
# body-parser (via express): invalid `limit` silently disabled size enforcement.
|
||||
"body-parser": "2.3.0"
|
||||
# @humanfs/node (via eslint): recursive copy followed symlinks outside the tree.
|
||||
"@humanfs/node": "0.16.8"
|
||||
# js-yaml: quadratic CPU in `!!omap` resolution (CVE-2026-59870 not backported
|
||||
# to 4.3.0). Direct dep is already 4.3.1; the override lifts eslint's copy too.
|
||||
"js-yaml": "4.3.1"
|
||||
|
||||
# --- Level 1: Minimum Release Age ---
|
||||
# Packages must be published for at least 1 day before they can be installed.
|
||||
|
||||
@@ -12,6 +12,34 @@ export const INTEGRATION_TYPE = {
|
||||
export type IntegrationType =
|
||||
(typeof INTEGRATION_TYPE)[keyof typeof INTEGRATION_TYPE];
|
||||
|
||||
export const INTEGRATION_CONNECTION_TASK_KIND = "integration-connection-test";
|
||||
|
||||
export interface IntegrationConnectionTaskResource {
|
||||
id: string;
|
||||
type: "tasks";
|
||||
}
|
||||
|
||||
export interface IntegrationConnectionTaskDocument {
|
||||
data: IntegrationConnectionTaskResource;
|
||||
}
|
||||
|
||||
export interface IntegrationConnectionTaskResult {
|
||||
connected?: boolean;
|
||||
error?: string | null;
|
||||
/** The failing channel id, or null when the failure names no channel. */
|
||||
channel?: string | null;
|
||||
}
|
||||
|
||||
export interface IntegrationConnectionTestResponse {
|
||||
success: boolean;
|
||||
message?: string;
|
||||
taskId?: string;
|
||||
data?: IntegrationConnectionTaskDocument;
|
||||
error?: string;
|
||||
/** The failing channel id, or null when the failure names no channel. */
|
||||
failedChannelId?: string | null;
|
||||
}
|
||||
|
||||
export const JIRA_DISPATCH_MODE = {
|
||||
INDIVIDUAL: "individual",
|
||||
GROUPED: "grouped",
|
||||
|
||||
Reference in New Issue
Block a user