|
| 1 | +rule,nistid |
| 2 | +acm-certificate-with-close-expiration-date,SC-12 |
| 3 | +acm-certificate-with-transparency-logging-disabled,SC-12 |
| 4 | +cloudformation-stack-with-role,AC-6 |
| 5 | +cloudtrail-duplicated-global-services-logging,AU-6 |
| 6 | +cloudtrail-no-cloudwatch-integration,AU-12|SI-4(2) |
| 7 | +cloudtrail-no-data-logging,AU-12 |
| 8 | +cloudtrail-no-encryption-with-kms,AU-6 |
| 9 | +cloudtrail-no-global-services-logging,AU-12 |
| 10 | +cloudtrail-no-log-file-validation,AU-6 |
| 11 | +cloudtrail-no-logging,AU-12 |
| 12 | +cloudtrail-not-configured,AU-12 |
| 13 | +cloudwatch-alarm-without-actions,AU-12 |
| 14 | +config-recorder-not-configured,CM-8|CM-8(2)|CM-8(6) |
| 15 | +ec2-ami-public,AC-3 |
| 16 | +ec2-default-security-group-in-use,AC-3(3) |
| 17 | +ec2-default-security-group-with-rules,AC-3(3) |
| 18 | +ec2-ebs-snapshot-not-encrypted,SC-28 |
| 19 | +ec2-ebs-snapshot-public,AC-3 |
| 20 | +ec2-ebs-volume-not-encrypted,SC-28 |
| 21 | +ec2-instance-in-security-group,CM-7(1) |
| 22 | +ec2-instance-type,CM-2 |
| 23 | +ec2-instance-types,CM-2 |
| 24 | +ec2-instance-with-public-ip,AC-3 |
| 25 | +ec2-instance-with-user-data-secrets,AC-3 |
| 26 | +ec2-security-group-opens-all-ports,CM-7(1) |
| 27 | +ec2-security-group-opens-all-ports-to-all,CM-7(1) |
| 28 | +ec2-security-group-opens-all-ports-to-self,CM-7(1) |
| 29 | +ec2-security-group-opens-icmp-to-all,CM-7(1) |
| 30 | +ec2-security-group-opens-known-port-to-all,CM-7(1) |
| 31 | +ec2-security-group-opens-plaintext-port,CM-7(1) |
| 32 | +ec2-security-group-opens-port-range,CM-7(1) |
| 33 | +ec2-security-group-opens-port-to-all,CM-7(1) |
| 34 | +ec2-security-group-whitelists-aws,CM-7(1) |
| 35 | +ec2-security-group-whitelists-aws-ip-from-banned-region,CM-7(1) |
| 36 | +ec2-security-group-whitelists-non-elastic-ips,CM-7(1) |
| 37 | +ec2-security-group-whitelists-unknown-aws,CM-7(1) |
| 38 | +ec2-security-group-whitelists-unknown-cidrs,CM-7(1) |
| 39 | +ec2-unused-security-group,CM-7(1) |
| 40 | +elb-listener-allowing-cleartext,SC-8 |
| 41 | +elb-no-access-logs,AU-12 |
| 42 | +elb-older-ssl-policy,SC-8 |
| 43 | +elbv2-http-request-smuggling,SC-8 |
| 44 | +elbv2-listener-allowing-cleartext,SC-8 |
| 45 | +elbv2-no-access-logs,AU-12 |
| 46 | +elbv2-no-deletion-protection,SI-7 |
| 47 | +elbv2-older-ssl-policy,SC-8 |
| 48 | +iam-assume-role-lacks-external-id-and-mfa,AC-17 |
| 49 | +iam-assume-role-no-mfa,AC-6 |
| 50 | +iam-assume-role-policy-allows-all,AC-6 |
| 51 | +iam-ec2-role-without-instances,AC-6 |
| 52 | +iam-group-with-inline-policies,AC-6 |
| 53 | +iam-group-with-no-users,AC-6 |
| 54 | +iam-human-user-with-policies,AC-6 |
| 55 | +iam-inline-policy-allows-non-sts-action,AC-6 |
| 56 | +iam-inline-policy-allows-NotActions,AC-6 |
| 57 | +iam-inline-policy-for-role,AC-6 |
| 58 | +iam-managed-policy-allows-full-privileges,AC-6 |
| 59 | +iam-managed-policy-allows-non-sts-action,AC-6 |
| 60 | +iam-managed-policy-allows-NotActions,AC-6 |
| 61 | +iam-managed-policy-for-role,AC-6 |
| 62 | +iam-managed-policy-no-attachments,AC-6 |
| 63 | +iam-no-support-role,IR-7 |
| 64 | +iam-password-policy-expiration-threshold,AC-2 |
| 65 | +iam-password-policy-minimum-length,AC-2 |
| 66 | +iam-password-policy-no-expiration,AC-2 |
| 67 | +iam-password-policy-no-lowercase-required,AC-2 |
| 68 | +iam-password-policy-no-number-required,AC-2 |
| 69 | +iam-password-policy-no-symbol-required,AC-2 |
| 70 | +iam-password-policy-no-uppercase-required,AC-2 |
| 71 | +iam-password-policy-reuse-enabled,IA-5(1) |
| 72 | +iam-role-with-inline-policies,AC-6 |
| 73 | +iam-root-account-no-hardware-mfa,IA-2(1) |
| 74 | +iam-root-account-no-mfa,IA-2(1) |
| 75 | +iam-root-account-used-recently,AC-6(9) |
| 76 | +iam-root-account-with-active-certs,AC-6(9) |
| 77 | +iam-root-account-with-active-keys,AC-6(9) |
| 78 | +iam-service-user-with-password,AC-2 |
| 79 | +iam-unused-credentials-not-disabled,AC-2 |
| 80 | +iam-user-no-key-rotation,AC-2 |
| 81 | +iam-user-not-in-category-group,AC-2 |
| 82 | +iam-user-not-in-common-group,AC-2 |
| 83 | +iam-user-unused-access-key-initial-setup,AC-2 |
| 84 | +iam-user-with-multiple-access-keys,IA-2 |
| 85 | +iam-user-without-mfa,IA-2(1) |
| 86 | +iam-user-with-password-and-key,IA-2 |
| 87 | +iam-user-with-policies,AC-2 |
| 88 | +kms-cmk-rotation-disabled,SC-12 |
| 89 | +logs-no-alarm-aws-configuration-changes,CM-8|CM-8(2)|CM-8(6) |
| 90 | +logs-no-alarm-cloudtrail-configuration-changes,AU-6 |
| 91 | +logs-no-alarm-cmk-deletion,AC-2 |
| 92 | +logs-no-alarm-console-authentication-failures,AC-2 |
| 93 | +logs-no-alarm-iam-policy-changes,AC-2 |
| 94 | +logs-no-alarm-nacl-changes,CM-6(2) |
| 95 | +logs-no-alarm-network-gateways-changes,AU-12|CM-6(2) |
| 96 | +logs-no-alarm-root-usage,AU-2 |
| 97 | +logs-no-alarm-route-table-changes,AU-12|CM-6(2) |
| 98 | +logs-no-alarm-s3-policy-changes,AC-6|AU-12 |
| 99 | +logs-no-alarm-security-group-changes,AC-2(4) |
| 100 | +logs-no-alarm-signin-without-mfa,AC-2 |
| 101 | +logs-no-alarm-unauthorized-api-calls,AU-6|SI-4(2) |
| 102 | +logs-no-alarm-vpc-changes,CM-6(1) |
| 103 | +rds-instance-backup-disabled,CP-9 |
| 104 | +rds-instance-ca-certificate-deprecated,SC-12 |
| 105 | +rds-instance-no-minor-upgrade,SI-2 |
| 106 | +rds-instance-short-backup-retention-period,CP-9 |
| 107 | +rds-instance-single-az,CP-7 |
| 108 | +rds-instance-storage-not-encrypted,SC-28 |
| 109 | +rds-postgres-instance-with-invalid-certificate,SC-12 |
| 110 | +rds-security-group-allows-all,CM-7(1) |
| 111 | +rds-snapshot-public,SC-28 |
| 112 | +redshift-cluster-database-not-encrypted,SC-28 |
| 113 | +redshift-cluster-no-version-upgrade,SI-2 |
| 114 | +redshift-cluster-publicly-accessible,AC-3 |
| 115 | +redshift-parameter-group-logging-disabled,AU-12 |
| 116 | +redshift-parameter-group-ssl-not-required,SC-8 |
| 117 | +redshift-security-group-whitelists-all,CM-7(1) |
| 118 | +route53-domain-no-autorenew,SC-2 |
| 119 | +route53-domain-no-transferlock,SC-2 |
| 120 | +route53-domain-transferlock-not-authorized,SC-2 |
| 121 | +s3-bucket-allowing-cleartext,SC-28 |
| 122 | +s3-bucket-no-default-encryption,SC-28 |
| 123 | +s3-bucket-no-logging,AU-2|AU-12 |
| 124 | +s3-bucket-no-mfa-delete,SI-7 |
| 125 | +s3-bucket-no-versioning,SI-7 |
| 126 | +s3-bucket-world-acl,AC-3(3) |
| 127 | +s3-bucket-world-policy-arg,AC-3(3) |
| 128 | +s3-bucket-world-policy-star,AC-3(3) |
| 129 | +ses-identity-dkim-not-enabled,SC-23 |
| 130 | +ses-identity-dkim-not-verified,SC-23 |
| 131 | +ses-identity-world-policy,AC-6 |
| 132 | +sns-topic-world-policy,AC-6 |
| 133 | +sqs-queue-world-policy,AC-6 |
| 134 | +vpc-custom-network-acls-allow-all,SC-7 |
| 135 | +vpc-default-network-acls-allow-all,SC-7 |
| 136 | +vpc-network-acl-not-used,SC-7 |
| 137 | +vpc-routing-tables-with-peering,AC-3(3) |
| 138 | +vpc-subnet-with-bad-acls,SC-7 |
| 139 | +vpc-subnet-with-default-acls,SC-7 |
| 140 | +vpc-subnet-without-flow-log,AU-12 |
0 commit comments