AWS New Checks

Ensure a log metric filter and alarm are in place for the disabling or scheduled deletion of customer-created KMS CMKs
Profile Applicability: Level 1 Description: This control ensures that AWS CloudTrail log data is monitored for any event where customer-managed AWS ...
Thu, 9 Oct, 2025 at 4:03 AM
Ensure a log metric filter and alarm exist for Management Console sign-in without MFA
Profile Applicability: Level 1 Description: This control ensures that AWS CloudTrail log data is monitored for Management Console sign-in attempts m...
Thu, 9 Oct, 2025 at 4:19 AM
Ensure a log metric filter and alarm exist for S3 bucket policy changes
Profile Applicability: Level 1 Description: This control ensures that AWS CloudTrail log data is monitored for any changes made to Amazon S3 bucke...
Thu, 9 Oct, 2025 at 4:34 AM
Ensure a log metric filter and alarm exist for changes to network gateways
Profile Applicability: Level 1 Description: This control ensures that AWS CloudTrail log data is monitored for any configuration changes to network ...
Thu, 9 Oct, 2025 at 4:44 AM
Ensure Amazon Elasticsearch/Opensearch Service domains have logging enabled
Profile Applicability: Level 1 Description: This control ensures that all Amazon Elasticsearch Service (now Amazon OpenSearch Service) domains have au...
Thu, 9 Oct, 2025 at 5:10 AM
Ensure Amazon Elasticsearch/Opensearch Service domains have logging enabled
Profile Applicability: Level 1 Description: This control ensures that all Amazon Elasticsearch Service (now Amazon OpenSearch Service) domains have ...
Thu, 9 Oct, 2025 at 5:14 AM
Ensure Amazon Opensearch/Elasticsearch domains are not set as Public or have open policy access
Profile Applicability: Level 1 Description: This control ensures that Amazon OpenSearch (formerly Elasticsearch) Service domains are not publicly ac...
Thu, 9 Oct, 2025 at 5:22 AM
Ensure Route53 public hosted zones are logging queries to CloudWatch Logs
Profile Applicability: Level 1 Description: This control ensures that Amazon Route 53 public hosted zones have DNS query logging enabled and that th...
Thu, 9 Oct, 2025 at 5:51 AM
Ensure checking for internet facing Elastic Load Balancers
Profile Applicability: Level 1 Description: This control ensures that all Elastic Load Balancers (ELBs) — including Classic, Application (ALB),...
Thu, 9 Oct, 2025 at 6:05 AM
Ensure checking for internet facing Elastic Load Balancers
Ensure checking for internet facing Elastic Load Balancers
Tue, 7 Oct, 2025 at 9:19 AM