Cloud Security Controls Library - Guardrails & Compliance Reference

View details
aws

Implement Regular Access Reviews for Landing Zone Accounts

Compliancehigh
View details
aws

Enable AWS Artifact for Compliance Reports

Compliancelow
View details
aws

Maintain Landing Zone Compliance Documentation

Compliancemedium
View details
aws

Implement Cost Allocation Tagging Strategy

Cost Managementhigh
View details
aws

Implement S3 Lifecycle Policies for Log Data

Cost Managementmedium
View details
aws

Implement Budget Alerts for Central Accounts

Cost Managementmedium
View details
aws

Enforce S3 Block Public Access at Organization Level

Data Protectioncritical
View details
aws

Enforce KMS Key Policies for Central Landing Zone Accounts

Data Protectionhigh
View details
aws

Centralize AWS Backup for Landing Zone Core Accounts

Data Protectionhigh
View details
aws

Secure S3 Audit Trails and CloudTrail Loop Prevention

Data Protectionmedium
View details
aws

Prohibit Public EBS and RDS Snapshots

Data Protectioncritical
View details
aws

Mandate Encryption for Data at Rest (EBS & S3)

Data Protectionhigh
View details
aws

Ensure Only Approved Cross-Account IAM Role Trusts

Identity & Accesshigh
View details
aws

Enforce IAM Account Password Policy for Central Accounts

Identity & Accessmedium
View details
aws

Centralized Identity Management with IAM Identity Center

Identity & Accesscritical
View details
aws

Enforce Break Glass Access Procedures

Identity & Accesscritical
View details
aws

Restrict IAM User Creation in Central Landing Zone Accounts

Identity & Accesshigh
View details
aws

Enforce OIDC for VCS CI/CD Connections to AWS

Identity & Accesscritical
View details
aws

Implement Foundational Service Control Policies (SCPs)

Identity & Accesshigh
View details
aws

Enable IAM Access Analyzer at Organization Level

Identity & Accesshigh
View details
aws

Define and Apply Resource Control Policies (RCPs)

Identity & Accesshigh
View details
aws

Ensure No Root User Account Access Key Exists

Identity & Accesscritical
View details
aws

Centralized and Immutable CloudTrail Logging

Loggingcritical
View details
aws

Selective CloudWatch Logs Aggregation with Cost Guardrails

Loggingmedium
View details
aws

Log Archive Account Isolation and Immutability Guardrails

Loggingcritical
View details
aws

Centralized VPC Flow Logging with Partitioning and Compression

Loggingmedium
View details
aws

Enforce Customer Managed KMS Keys and Key Rotation for Audit Logs

Logginghigh
View details
aws

Selective CloudTrail Data Events Logging with Cost Guardrails

Logginghigh
View details
gcp

Enforce Foundational IAM Organization Policy Constraints

Identity & Accesshigh
View details
gcp

Enforce Just-In-Time Privileged Access with Privileged Access Manager

Identity & Accesshigh
View details
gcp

Enable Policy Analyzer and IAM Recommender

Identity & Accessmedium
View details
gcp

Enforce Workload Identity Federation for VCS CI/CD Connections to GCP

Identity & Accesscritical
Showing 132 of 32
1/1

We value your privacy

We use analytics cookies to understand how visitors interact with our site and to improve the user experience. You can choose to accept or decline these cookies.