AWS Compliance Mod for Powerpipe

repository·main·Indexed 19 days ago

https://github.com/turbot/steampipe-mod-aws-compliance

A collection of over 540 security checks for AWS environments, covering industry benchmarks such as CIS, PCI DSS, HIPAA, NIST, and the ACSC Essential Eight. The mod integrates with Powerpipe and Steampipe to provide compliance auditing via web-based dashboards or the command line, including detailed remediation steps for non-compliant AWS resource configurations.

Tokens
328K
Snippets
452
Records
1.4K
Agent score
60%

What's inside steampipe-mod-aws-compliance

  1. Overview of CIS Compute Service Benchmarks

    main

    This module provides prescriptive guidance for configuring security options for AWS services within the Compute category. These benchmarks focus on technical configuration settings to maintain or increase security.

    Note that these benchmarks are intended to be used in conjunction with the CIS Amazon Web Services Foundations Benchmark. For the most up-to-date official guidance, visit the CIS official website.

  2. Overview of AWS Control Tower in AWS Compliance Mod

    main

    AWS Control Tower provides a managed way to set up and govern multi-account AWS environments using best practices. It orchestrates AWS Organizations, AWS Service Catalog, and AWS Single Sign-On to build a landing zone.

    In the context of compliance and auditing, Control Tower applies preventive and detective controls (guardrails) to prevent or detect 'drift' (divergence from best practices). These guardrails can ensure that critical resources, such as security logs and cross-account access permissions, are correctly configured and remain unaltered.

  3. Overview of ACSC Essential Eight compliance checks

    main

    The ACSC Essential Eight is a prioritized set of baseline security strategies designed to mitigate cybersecurity incidents, based on the Australian Signals Directorate (ASD) experience. This module provides checks to assess compliance against these strategies.

    The framework is divided into two primary components:

    1. Essential Eight Maturity Model: A set of maturity levels used to assess an organization's cybersecurity posture.
    2. Essential Eight Strategies: A set of specific mitigation strategies implemented to protect systems against adversaries.

    These checks are designed to complement other frameworks like the NIST Cybersecurity Framework and ISO 27001.

  4. NIST SP 800-171 Rev 2 Overview

    main

    NIST SP 800-171 is a security standard designed to protect the confidentiality of Controlled Unclassified Information (CUI) within nonfederal systems and organizations. It outlines specific security requirements and practices that non-federal organizations must implement when handling CUI on their networks.

    For the most current and official version of the NIST SP 800-171 Rev 2 guide, refer to the official NIST website.

  5. Scope of the CIS AWS Foundations Benchmark

    main

    The CIS AWS Foundations Benchmark provides prescriptive guidance for foundational, testable, and architecture-agnostic security settings across several AWS services, including:

    • AWS Identity and Access Management (IAM)
    • IAM Access Analyzer
    • AWS Config
    • AWS CloudTrail
    • AWS CloudWatch
    • AWS Simple Notification Service (SNS)
    • AWS Simple Storage Service (S3)
    • Elastic Compute Cloud (EC2)
    • Relational Database Service (RDS)
    • AWS VPC (Default)
  6. Scope of CIS AWS Foundations Benchmark

    main

    The CIS AWS Foundations Benchmark provides prescriptive guidance for configuring security options across several core AWS services. The services in scope include:

    • AWS Identity and Access Management (IAM)
    • IAM Access Analyzer
    • AWS Config
    • AWS CloudTrail
    • AWS CloudWatch
    • AWS Simple Notification Service (SNS)
    • AWS Simple Storage Service (S3)
    • Elastic Compute Cloud (EC2)
    • Elastic File System (EFS)
    • Relational Database Service (RDS)
    • AWS VPC (Default)
  7. Overview of the FFIEC Cybersecurity Assessment Tool

    main

    The FFIEC Cybersecurity Assessment Tool is a measurable and repeatable process designed to help financial institutions identify cyber risks and determine cybersecurity maturity. The assessment is divided into two primary parts:

    1. Inherent Risk Profile: Identifies an institution's inherent risk based on five categories:

      • Technologies and Connection Types
      • Delivery Channels
      • Online/Mobile Products and Technology Services
      • Organizational Characteristics
      • External Threats
    2. Cybersecurity Maturity: Determines the current state of preparedness across five domains:

      • Cyber Risk Management and Oversight: Focuses on board oversight and the implementation of enterprise-wide cybersecurity programs, policies, and procedures.
      • Threat Intelligence and Collaboration: Focuses on discovering, analyzing, and understanding cyber threats and sharing information internally and with third parties.
      • Cybersecurity Controls: Focuses on defensive practices, automated protection, and continuous monitoring of assets and infrastructure.
      • External Dependency Management: Focuses on managing external connections and third-party relationships that have access to technology assets and information.
      • Cyber Incident Management and Resilience: Focuses on identifying, analyzing, and mitigating cyber events, as well as planning and testing for operational recovery during and after an incident.