Cloud Security Controls Library - Guardrails & Compliance Reference
/
View details
Implement Regular Access Reviews for Landing Zone Accounts
Compliancehigh
View details
Enable AWS Artifact for Compliance Reports
Compliancelow
View details
Maintain Landing Zone Compliance Documentation
Compliancemedium
View details
Implement Cost Allocation Tagging Strategy
Cost Managementhigh
View details
Implement S3 Lifecycle Policies for Log Data
Cost Managementmedium
View details
Implement Budget Alerts for Central Accounts
Cost Managementmedium
View details
Enforce S3 Block Public Access at Organization Level
Data Protectioncritical
View details
Enforce KMS Key Policies for Central Landing Zone Accounts
Data Protectionhigh
View details
Centralize AWS Backup for Landing Zone Core Accounts
Data Protectionhigh
View details
Secure S3 Audit Trails and CloudTrail Loop Prevention
Data Protectionmedium
View details
Prohibit Public EBS and RDS Snapshots
Data Protectioncritical
View details
Mandate Encryption for Data at Rest (EBS & S3)
Data Protectionhigh
View details
Ensure Only Approved Cross-Account IAM Role Trusts
Identity & Accesshigh
View details
Enforce IAM Account Password Policy for Central Accounts
Identity & Accessmedium
View details
Centralized Identity Management with IAM Identity Center
Identity & Accesscritical
View details
Enforce Break Glass Access Procedures
Identity & Accesscritical
View details
Restrict IAM User Creation in Central Landing Zone Accounts
Identity & Accesshigh
View details
Enforce OIDC for VCS CI/CD Connections to AWS
Identity & Accesscritical
View details
Implement Foundational Service Control Policies (SCPs)
Identity & Accesshigh
View details
Enable IAM Access Analyzer at Organization Level
Identity & Accesshigh
View details
Define and Apply Resource Control Policies (RCPs)
Identity & Accesshigh
View details
Ensure No Root User Account Access Key Exists
Identity & Accesscritical
View details
Centralized and Immutable CloudTrail Logging
Loggingcritical
View details
Selective CloudWatch Logs Aggregation with Cost Guardrails
Loggingmedium
View details
Log Archive Account Isolation and Immutability Guardrails
Loggingcritical
View details
Centralized VPC Flow Logging with Partitioning and Compression
Loggingmedium
View details
Enforce Customer Managed KMS Keys and Key Rotation for Audit Logs
Logginghigh
View details
Selective CloudTrail Data Events Logging with Cost Guardrails
Logginghigh
View details
Enforce Foundational IAM Organization Policy Constraints
Identity & Accesshigh
View details
Enforce Just-In-Time Privileged Access with Privileged Access Manager
Identity & Accesshigh
View details
Enable Policy Analyzer and IAM Recommender
Identity & Accessmedium
View details
Enforce Workload Identity Federation for VCS CI/CD Connections to GCP
Identity & Accesscritical
Showing 1–32 of 32
1/1