Skip to content

Does manual check of AWS security best practices need require AWS Support?

0

I am looking for a manual review AWS best practice and CIS benchmarking of services ACM, S3, VPC, ECR and KMS. Does it require permissions from AWS support?

asked a year ago267 views
2 Answers
3

Hi,

Re CIS benchmark applied to various AWS services, you want to start by checking out this page: https://docs.aws.amazon.com/securityhub/latest/userguide/cis-aws-foundations-benchmark.html

Then, you will be interested by all official compliance reports in AWS Artifact: https://aws.amazon.com/artifact/

Finally, check out the following page to see the compliance with various standards of the service that you are interested in: https://aws.amazon.com/compliance/programs/

Best,

Didier

EXPERT
answered a year ago
EXPERT
reviewed a year ago
2
Accepted Answer

Hi lakshmy G

don't need permissions from AWS Support to perform a manual review of AWS best practices and CIS benchmarking for ACM, S3, VPC, ECR, and KMS.

AWS Best Practices:

  • Each AWS service has its own documentation section dedicated to best practices. You can find them directly within the service documentation on the AWS website.

CIS Benchmarking:

https://medium.com/ofofo-io/cis-benchmark-for-cis-amazon-web-services-foundations-benchmark-what-it-is-and-how-to-use-it-2a9425f5dcf0

AWS Config: This service allows you to automate some aspects of configuration review by setting up rules that check your resources against best practices https://docs.aws.amazon.com/config/

AWS Well-Architected Framework: This framework provides a holistic approach to building secure, high-performing, and cost-optimized infrastructure on AWS https://docs.aws.amazon.com/wellarchitected/latest/userguide/waf.html

EXPERT
answered a year ago
EXPERT
reviewed a year ago
EXPERT
reviewed a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.