{ "source": "fsbp", "fetched_at": "2026-05-12T17:17:42.705929+00:00", "controls": [ { "control_id": "FSBP Account.1", "title": "Security contact information should be provided for an AWS account", "severity": "medium", "resource_types": [ "aws_account_alternate_contact" ], "requirement": "Security contact information should be provided for an AWS account", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/account-controls.html#account-1" }, { "control_id": "FSBP ACM.1", "title": "Imported and ACM-issued certificates should be renewed after a specified time period", "severity": "medium", "resource_types": [ "aws_acm_certificate" ], "requirement": "Imported and ACM-issued certificates should be renewed after a specified time period", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/acm-controls.html#acm-1" }, { "control_id": "FSBP ACM.2", "title": "RSA certificates managed by ACM should use a key length of at least 2,048 bits", "severity": "medium", "resource_types": [ "aws_acm_certificate" ], "requirement": "RSA certificates managed by ACM should use a key length of at least 2,048 bits", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/acm-controls.html#acm-2" }, { "control_id": "FSBP APIGateway.1", "title": "API Gateway REST and WebSocket API execution logging should be enabled", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway REST and WebSocket API execution logging should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-1" }, { "control_id": "FSBP APIGateway.2", "title": "API Gateway REST API stages should be configured to use SSL certificates for backend authentication", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway REST API stages should be configured to use SSL certificates for backend authentication", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-2" }, { "control_id": "FSBP APIGateway.3", "title": "API Gateway REST API stages should have AWS X-Ray tracing enabled", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway REST API stages should have AWS X-Ray tracing enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-3" }, { "control_id": "FSBP APIGateway.4", "title": "API Gateway should be associated with a WAF Web ACL", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway should be associated with a WAF Web ACL", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-4" }, { "control_id": "FSBP APIGateway.5", "title": "API Gateway REST API cache data should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway REST API cache data should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-5" }, { "control_id": "FSBP APIGateway.8", "title": "API Gateway routes should specify an authorization type", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway routes should specify an authorization type", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-8" }, { "control_id": "FSBP APIGateway.9", "title": "Access logging should be configured for API Gateway V2 Stages", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "Access logging should be configured for API Gateway V2 Stages", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-9" }, { "control_id": "FSBP APIGateway.10", "title": "API Gateway V2 integrations should use HTTPS for private connections", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway V2 integrations should use HTTPS for private connections", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-10" }, { "control_id": "FSBP APIGateway.11", "title": "API Gateway domain names should use recommended security policies", "severity": "medium", "resource_types": [ "aws_api_gateway_rest_api", "aws_apigatewayv2_api", "aws_api_gateway_stage", "aws_api_gateway_method" ], "requirement": "API Gateway domain names should use recommended security policies", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/apigateway-controls.html#apigateway-11" }, { "control_id": "FSBP AppSync.1", "title": "AWS AppSync API caches should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_appsync_graphql_api" ], "requirement": "AWS AppSync API caches should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/appsync-controls.html#appsync-1" }, { "control_id": "FSBP AppSync.2", "title": "AWS AppSync should have field-level logging enabled", "severity": "medium", "resource_types": [ "aws_appsync_graphql_api" ], "requirement": "AWS AppSync should have field-level logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/appsync-controls.html#appsync-2" }, { "control_id": "FSBP AppSync.5", "title": "AWS AppSync GraphQL APIs should not be authenticated with API keys", "severity": "medium", "resource_types": [ "aws_appsync_graphql_api" ], "requirement": "AWS AppSync GraphQL APIs should not be authenticated with API keys", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/appsync-controls.html#appsync-5" }, { "control_id": "FSBP AppSync.6", "title": "AWS AppSync API caches should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_appsync_graphql_api" ], "requirement": "AWS AppSync API caches should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/appsync-controls.html#appsync-6" }, { "control_id": "FSBP Athena.4", "title": "Athena workgroups should have logging enabled", "severity": "medium", "resource_types": [ "aws_athena_workgroup" ], "requirement": "Athena workgroups should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/athena-controls.html#athena-4" }, { "control_id": "FSBP AutoScaling.1", "title": "Auto Scaling groups associated with a load balancer should use ELB health checks", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Auto Scaling groups associated with a load balancer should use ELB health checks", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-1" }, { "control_id": "FSBP AutoScaling.2", "title": "Amazon EC2 Auto Scaling group should cover multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Amazon EC2 Auto Scaling group should cover multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-2" }, { "control_id": "FSBP AutoScaling.3", "title": "Auto Scaling group launch configurations should configure EC2 instances to require Instance Metadata Service Version 2 (IMDSv2)", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Auto Scaling group launch configurations should configure EC2 instances to require Instance Metadata Service Version 2 (IMDSv2)", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-3" }, { "control_id": "FSBP Autoscaling.5", "title": "Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-5" }, { "control_id": "FSBP AutoScaling.6", "title": "Auto Scaling groups should use multiple instance types in multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Auto Scaling groups should use multiple instance types in multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-6" }, { "control_id": "FSBP AutoScaling.9", "title": "Amazon EC2 Auto Scaling groups should use Amazon EC2 launch templates", "severity": "medium", "resource_types": [ "aws_autoscaling_group", "aws_launch_template", "aws_launch_configuration" ], "requirement": "Amazon EC2 Auto Scaling groups should use Amazon EC2 launch templates", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-9" }, { "control_id": "FSBP Backup.1", "title": "AWS Backup recovery points should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_backup_plan", "aws_backup_vault" ], "requirement": "AWS Backup recovery points should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/backup-controls.html#backup-1" }, { "control_id": "FSBP BedrockAgentCore.1", "title": "Bedrock AgentCore runtimes should be configured with VPC network mode", "severity": "medium", "resource_types": [], "requirement": "Bedrock AgentCore runtimes should be configured with VPC network mode", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/bedrockagentcore-controls.html#bedrockagentcore-1" }, { "control_id": "FSBP BedrockAgentCore.2", "title": "Bedrock AgentCore Gateways should require authorization for inbound requests", "severity": "medium", "resource_types": [], "requirement": "Bedrock AgentCore Gateways should require authorization for inbound requests", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/bedrockagentcore-controls.html#bedrockagentcore-2" }, { "control_id": "FSBP CloudFormation.3", "title": "CloudFormation stacks should have termination protection enabled", "severity": "medium", "resource_types": [ "aws_cloudformation_stack", "aws_cloudformation_stack_set" ], "requirement": "CloudFormation stacks should have termination protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudformation-controls.html#cloudformation-3" }, { "control_id": "FSBP CloudFormation.4", "title": "CloudFormation stacks should have associated service roles", "severity": "medium", "resource_types": [ "aws_cloudformation_stack", "aws_cloudformation_stack_set" ], "requirement": "CloudFormation stacks should have associated service roles", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudformation-controls.html#cloudformation-4" }, { "control_id": "FSBP CloudFront.1", "title": "CloudFront distributions should have a default root object configured", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should have a default root object configured", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-1" }, { "control_id": "FSBP CloudFront.3", "title": "CloudFront distributions should require encryption in transit", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should require encryption in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-3" }, { "control_id": "FSBP CloudFront.4", "title": "CloudFront distributions should have origin failover configured", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should have origin failover configured", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-4" }, { "control_id": "FSBP CloudFront.5", "title": "CloudFront distributions should have logging enabled", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-5" }, { "control_id": "FSBP CloudFront.6", "title": "CloudFront distributions should have WAF enabled", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should have WAF enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-6" }, { "control_id": "FSBP CloudFront.7", "title": "CloudFront distributions should use custom SSL/TLS certificates", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use custom SSL/TLS certificates", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-7" }, { "control_id": "FSBP CloudFront.8", "title": "CloudFront distributions should use SNI to serve HTTPS requests", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use SNI to serve HTTPS requests", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-8" }, { "control_id": "FSBP CloudFront.9", "title": "CloudFront distributions should encrypt traffic to custom origins", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should encrypt traffic to custom origins", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-9" }, { "control_id": "FSBP CloudFront.10", "title": "CloudFront distributions should not use deprecated SSL protocols between edge locations and custom origins", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should not use deprecated SSL protocols between edge locations and custom origins", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-10" }, { "control_id": "FSBP CloudFront.12", "title": "CloudFront distributions should not point to non-existent S3 origins", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should not point to non-existent S3 origins", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-12" }, { "control_id": "FSBP CloudFront.13", "title": "CloudFront distributions should use origin access control", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use origin access control", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-13" }, { "control_id": "FSBP CloudFront.15", "title": "CloudFront distributions should use the recommended TLS security policy", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use the recommended TLS security policy", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-15" }, { "control_id": "FSBP CloudFront.16", "title": "CloudFront distributions should use origin access control for Lambda function URL origins", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use origin access control for Lambda function URL origins", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-16" }, { "control_id": "FSBP CloudFront.17", "title": "CloudFront distributions should use trusted key groups for signed URLs and cookies", "severity": "medium", "resource_types": [ "aws_cloudfront_distribution" ], "requirement": "CloudFront distributions should use trusted key groups for signed URLs and cookies", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-17" }, { "control_id": "FSBP CloudTrail.1", "title": "CloudTrail should be enabled and configured with at least one multi-Region trail that includes read and write management events", "severity": "medium", "resource_types": [ "aws_cloudtrail" ], "requirement": "CloudTrail should be enabled and configured with at least one multi-Region trail that includes read and write management events", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-1" }, { "control_id": "FSBP CloudTrail.2", "title": "CloudTrail should have encryption at-rest enabled", "severity": "medium", "resource_types": [ "aws_cloudtrail" ], "requirement": "CloudTrail should have encryption at-rest enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-2" }, { "control_id": "FSBP CloudTrail.4", "title": "CloudTrail log file validation should be enabled", "severity": "medium", "resource_types": [ "aws_cloudtrail" ], "requirement": "CloudTrail log file validation should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-4" }, { "control_id": "FSBP CloudTrail.5", "title": "CloudTrail trails should be integrated with Amazon CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_cloudtrail" ], "requirement": "CloudTrail trails should be integrated with Amazon CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-5" }, { "control_id": "FSBP CodeBuild.1", "title": "CodeBuild Bitbucket source repository URLs should not contain sensitive credentials", "severity": "medium", "resource_types": [ "aws_codebuild_project" ], "requirement": "CodeBuild Bitbucket source repository URLs should not contain sensitive credentials", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/codebuild-controls.html#codebuild-1" }, { "control_id": "FSBP CodeBuild.2", "title": "CodeBuild project environment variables should not contain clear text credentials", "severity": "medium", "resource_types": [ "aws_codebuild_project" ], "requirement": "CodeBuild project environment variables should not contain clear text credentials", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/codebuild-controls.html#codebuild-2" }, { "control_id": "FSBP CodeBuild.3", "title": "CodeBuild S3 logs should be encrypted", "severity": "medium", "resource_types": [ "aws_codebuild_project" ], "requirement": "CodeBuild S3 logs should be encrypted", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/codebuild-controls.html#codebuild-3" }, { "control_id": "FSBP CodeBuild.4", "title": "CodeBuild project environments should have a logging AWS Configuration", "severity": "medium", "resource_types": [ "aws_codebuild_project" ], "requirement": "CodeBuild project environments should have a logging AWS Configuration", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/codebuild-controls.html#codebuild-4" }, { "control_id": "FSBP CodeBuild.7", "title": "CodeBuild report group exports should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_codebuild_project" ], "requirement": "CodeBuild report group exports should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/codebuild-controls.html#codebuild-7" }, { "control_id": "FSBP Cognito.2", "title": "Cognito identity pools should not allow unauthenticated identities", "severity": "medium", "resource_types": [ "aws_cognito_user_pool", "aws_cognito_identity_pool" ], "requirement": "Cognito identity pools should not allow unauthenticated identities", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cognito-controls.html#cognito-2" }, { "control_id": "FSBP Cognito.3", "title": "Password policies for Cognito user pools should have strong configurations", "severity": "medium", "resource_types": [ "aws_cognito_user_pool", "aws_cognito_identity_pool" ], "requirement": "Password policies for Cognito user pools should have strong configurations", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cognito-controls.html#cognito-3" }, { "control_id": "FSBP Cognito.4", "title": "Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication", "severity": "medium", "resource_types": [ "aws_cognito_user_pool", "aws_cognito_identity_pool" ], "requirement": "Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cognito-controls.html#cognito-4" }, { "control_id": "FSBP Cognito.5", "title": "MFA should be enabled for Cognito user pools", "severity": "medium", "resource_types": [ "aws_cognito_user_pool", "aws_cognito_identity_pool" ], "requirement": "MFA should be enabled for Cognito user pools", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cognito-controls.html#cognito-5" }, { "control_id": "FSBP Cognito.6", "title": "Cognito user pools should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_cognito_user_pool", "aws_cognito_identity_pool" ], "requirement": "Cognito user pools should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/cognito-controls.html#cognito-6" }, { "control_id": "FSBP Config.1", "title": "AWS Config should be enabled and use the service-linked role for resource recording", "severity": "medium", "resource_types": [ "aws_config_configuration_recorder", "aws_config_delivery_channel", "aws_config_config_rule" ], "requirement": "AWS Config should be enabled and use the service-linked role for resource recording", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1" }, { "control_id": "FSBP Connect.2", "title": "Connect Customer instances should have CloudWatch logging enabled", "severity": "medium", "resource_types": [ "aws_connect_instance" ], "requirement": "Connect Customer instances should have CloudWatch logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/connect-controls.html#connect-2" }, { "control_id": "FSBP DataFirehose.1", "title": "Firehose delivery streams should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_kinesis_firehose_delivery_stream" ], "requirement": "Firehose delivery streams should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/datafirehose-controls.html#datafirehose-1" }, { "control_id": "FSBP DataSync.1", "title": "DataSync tasks should have logging enabled", "severity": "medium", "resource_types": [ "aws_datasync_task" ], "requirement": "DataSync tasks should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/datasync-controls.html#datasync-1" }, { "control_id": "FSBP DMS.1", "title": "Database Migration Service replication instances should not be public", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "Database Migration Service replication instances should not be public", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-1" }, { "control_id": "FSBP DMS.6", "title": "DMS replication instances should have automatic minor version upgrade enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS replication instances should have automatic minor version upgrade enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-6" }, { "control_id": "FSBP DMS.7", "title": "DMS replication tasks for the target database should have logging enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS replication tasks for the target database should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-7" }, { "control_id": "FSBP DMS.8", "title": "DMS replication tasks for the source database should have logging enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS replication tasks for the source database should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-8" }, { "control_id": "FSBP DMS.9", "title": "DMS endpoints should use SSL", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS endpoints should use SSL", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-9" }, { "control_id": "FSBP DMS.10", "title": "DMS endpoints for Neptune databases should have IAM authorization enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS endpoints for Neptune databases should have IAM authorization enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-10" }, { "control_id": "FSBP DMS.11", "title": "DMS endpoints for MongoDB should have an authentication mechanism enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS endpoints for MongoDB should have an authentication mechanism enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-11" }, { "control_id": "FSBP DMS.12", "title": "DMS endpoints for Redis OSS should have TLS enabled", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS endpoints for Redis OSS should have TLS enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-12" }, { "control_id": "FSBP DMS.13", "title": "DMS replication instances should be configured to use multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_dms_endpoint", "aws_dms_replication_instance" ], "requirement": "DMS replication instances should be configured to use multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dms-controls.html#dms-13" }, { "control_id": "FSBP DocumentDB.1", "title": "Amazon DocumentDB clusters should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB clusters should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-1" }, { "control_id": "FSBP DocumentDB.2", "title": "Amazon DocumentDB clusters should have an adequate backup retention period", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB clusters should have an adequate backup retention period", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-2" }, { "control_id": "FSBP DocumentDB.3", "title": "Amazon DocumentDB manual cluster snapshots should not be public", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB manual cluster snapshots should not be public", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-3" }, { "control_id": "FSBP DocumentDB.4", "title": "Amazon DocumentDB clusters should publish audit logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB clusters should publish audit logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-4" }, { "control_id": "FSBP DocumentDB.5", "title": "Amazon DocumentDB clusters should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB clusters should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-5" }, { "control_id": "FSBP DocumentDB.6", "title": "Amazon DocumentDB clusters should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_docdb_cluster", "aws_docdb_cluster_instance" ], "requirement": "Amazon DocumentDB clusters should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-6" }, { "control_id": "FSBP DynamoDB.1", "title": "DynamoDB tables should automatically scale capacity with demand", "severity": "medium", "resource_types": [ "aws_dynamodb_table" ], "requirement": "DynamoDB tables should automatically scale capacity with demand", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dynamodb-controls.html#dynamodb-1" }, { "control_id": "FSBP DynamoDB.2", "title": "DynamoDB tables should have point-in-time recovery enabled", "severity": "medium", "resource_types": [ "aws_dynamodb_table" ], "requirement": "DynamoDB tables should have point-in-time recovery enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dynamodb-controls.html#dynamodb-2" }, { "control_id": "FSBP DynamoDB.3", "title": "DynamoDB Accelerator (DAX) clusters should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_dynamodb_table" ], "requirement": "DynamoDB Accelerator (DAX) clusters should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dynamodb-controls.html#dynamodb-3" }, { "control_id": "FSBP DynamoDB.6", "title": "DynamoDB tables should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_dynamodb_table" ], "requirement": "DynamoDB tables should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dynamodb-controls.html#dynamodb-6" }, { "control_id": "FSBP DynamoDB.7", "title": "DynamoDB Accelerator clusters should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_dynamodb_table" ], "requirement": "DynamoDB Accelerator clusters should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/dynamodb-controls.html#dynamodb-7" }, { "control_id": "FSBP EC2.1", "title": "Amazon EBS snapshots should not be configured to be publicly restorable", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EBS snapshots should not be configured to be publicly restorable", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-1" }, { "control_id": "FSBP EC2.2", "title": "VPC default security groups should not allow inbound or outbound traffic", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPC default security groups should not allow inbound or outbound traffic", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-2" }, { "control_id": "FSBP EC2.3", "title": "Attached Amazon EBS volumes should be encrypted at-rest", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Attached Amazon EBS volumes should be encrypted at-rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-3" }, { "control_id": "FSBP EC2.4", "title": "Stopped EC2 instances should be removed after a specified time period", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Stopped EC2 instances should be removed after a specified time period", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-4" }, { "control_id": "FSBP EC2.6", "title": "VPC flow logging should be enabled in all VPCs", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPC flow logging should be enabled in all VPCs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-6" }, { "control_id": "FSBP EC2.7", "title": "EBS default encryption should be enabled", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EBS default encryption should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-7" }, { "control_id": "FSBP EC2.8", "title": "EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-8" }, { "control_id": "FSBP EC2.9", "title": "Amazon EC2 instances should not have a public IPv4 address", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 instances should not have a public IPv4 address", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-9" }, { "control_id": "FSBP EC2.10", "title": "Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-10" }, { "control_id": "FSBP EC2.15", "title": "Amazon EC2 subnets should not automatically assign public IP addresses", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 subnets should not automatically assign public IP addresses", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-15" }, { "control_id": "FSBP EC2.16", "title": "Unused Network Access Control Lists should be removed", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Unused Network Access Control Lists should be removed", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-16" }, { "control_id": "FSBP EC2.17", "title": "Amazon EC2 instances should not use multiple ENIs", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 instances should not use multiple ENIs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-17" }, { "control_id": "FSBP EC2.18", "title": "Security groups should only allow unrestricted incoming traffic for authorized ports", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Security groups should only allow unrestricted incoming traffic for authorized ports", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-18" }, { "control_id": "FSBP EC2.19", "title": "Security groups should not allow unrestricted access to ports with high risk", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Security groups should not allow unrestricted access to ports with high risk", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-19" }, { "control_id": "FSBP EC2.20", "title": "Both VPN tunnels for an AWS Site-to-Site VPN connection should be up", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Both VPN tunnels for an AWS Site-to-Site VPN connection should be up", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-20" }, { "control_id": "FSBP EC2.21", "title": "Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 3389", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 3389", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-21" }, { "control_id": "FSBP EC2.23", "title": "Amazon EC2 Transit Gateways should not automatically accept VPC attachment requests", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 Transit Gateways should not automatically accept VPC attachment requests", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-23" }, { "control_id": "FSBP EC2.24", "title": "Amazon EC2 paravirtual instance types should not be used", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 paravirtual instance types should not be used", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-24" }, { "control_id": "FSBP EC2.25", "title": "Amazon EC2 launch templates should not assign public IPs to network interfaces", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Amazon EC2 launch templates should not assign public IPs to network interfaces", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-25" }, { "control_id": "FSBP EC2.51", "title": "EC2 Client VPN endpoints should have client connection logging enabled", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 Client VPN endpoints should have client connection logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-51" }, { "control_id": "FSBP EC2.55", "title": "VPCs should be configured with an interface endpoint for ECR API", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPCs should be configured with an interface endpoint for ECR API", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-55" }, { "control_id": "FSBP EC2.56", "title": "VPCs should be configured with an interface endpoint for Docker Registry", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPCs should be configured with an interface endpoint for Docker Registry", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-56" }, { "control_id": "FSBP EC2.57", "title": "VPCs should be configured with an interface endpoint for Systems Manager", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPCs should be configured with an interface endpoint for Systems Manager", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-57" }, { "control_id": "FSBP EC2.58", "title": "VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-58" }, { "control_id": "FSBP EC2.60", "title": "VPCs should be configured with an interface endpoint for Systems Manager Incident Manager", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "VPCs should be configured with an interface endpoint for Systems Manager Incident Manager", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-60" }, { "control_id": "FSBP EC2.170", "title": "EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-170" }, { "control_id": "FSBP EC2.171", "title": "EC2 VPN connections should have logging enabled", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 VPN connections should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-171" }, { "control_id": "FSBP EC2.172", "title": "EC2 VPC Block Public Access settings should block internet gateway traffic", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 VPC Block Public Access settings should block internet gateway traffic", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-172" }, { "control_id": "FSBP EC2.173", "title": "EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-173" }, { "control_id": "FSBP EC2.180", "title": "EC2 network interfaces should have source/destination checking enabled", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 network interfaces should have source/destination checking enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-180" }, { "control_id": "FSBP EC2.181", "title": "EC2 launch templates should enable encryption for attached EBS volumes", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 launch templates should enable encryption for attached EBS volumes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-181" }, { "control_id": "FSBP EC2.182", "title": "Block public access settings should be enabled for Amazon EBS snapshots", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "Block public access settings should be enabled for Amazon EBS snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-182" }, { "control_id": "FSBP EC2.183", "title": "EC2 VPN connections should use IKEv2 protocol", "severity": "medium", "resource_types": [ "aws_instance", "aws_security_group", "aws_security_group_rule", "aws_vpc", "aws_subnet", "aws_network_acl", "aws_ebs_volume", "aws_ebs_default_kms_key", "aws_eip", "aws_nat_gateway", "aws_internet_gateway", "aws_route_table", "aws_vpc_endpoint", "aws_flow_log", "aws_default_security_group" ], "requirement": "EC2 VPN connections should use IKEv2 protocol", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-183" }, { "control_id": "FSBP ECR.1", "title": "ECR private repositories should have image scanning configured", "severity": "medium", "resource_types": [ "aws_ecr_repository", "aws_ecr_repository_policy" ], "requirement": "ECR private repositories should have image scanning configured", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecr-controls.html#ecr-1" }, { "control_id": "FSBP ECR.2", "title": "ECR private repositories should have tag immutability configured", "severity": "medium", "resource_types": [ "aws_ecr_repository", "aws_ecr_repository_policy" ], "requirement": "ECR private repositories should have tag immutability configured", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecr-controls.html#ecr-2" }, { "control_id": "FSBP ECR.3", "title": "ECR repositories should have at least one lifecycle policy configured", "severity": "medium", "resource_types": [ "aws_ecr_repository", "aws_ecr_repository_policy" ], "requirement": "ECR repositories should have at least one lifecycle policy configured", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecr-controls.html#ecr-3" }, { "control_id": "FSBP ECS.1", "title": "Amazon ECS task definitions should have secure networking modes and user definitions", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "Amazon ECS task definitions should have secure networking modes and user definitions", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-1" }, { "control_id": "FSBP ECS.2", "title": "ECS services should not have public IP addresses assigned to them automatically", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS services should not have public IP addresses assigned to them automatically", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-2" }, { "control_id": "FSBP ECS.3", "title": "ECS task definitions should not share the host's process namespace", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS task definitions should not share the host's process namespace", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-3" }, { "control_id": "FSBP ECS.4", "title": "ECS containers should run as non-privileged", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS containers should run as non-privileged", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-4" }, { "control_id": "FSBP ECS.5", "title": "ECS task definitions should configure containers to be limited to read-only access to root filesystems", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS task definitions should configure containers to be limited to read-only access to root filesystems", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-5" }, { "control_id": "FSBP ECS.8", "title": "Secrets should not be passed as container environment variables", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "Secrets should not be passed as container environment variables", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-8" }, { "control_id": "FSBP ECS.9", "title": "ECS task definitions should have a logging configuration", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS task definitions should have a logging configuration", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-9" }, { "control_id": "FSBP ECS.10", "title": "ECS Fargate services should run on the latest Fargate platform version", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS Fargate services should run on the latest Fargate platform version", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-10" }, { "control_id": "FSBP ECS.12", "title": "ECS clusters should use Container Insights", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS clusters should use Container Insights", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-12" }, { "control_id": "FSBP ECS.16", "title": "ECS task sets should not automatically assign public IP addresses", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS task sets should not automatically assign public IP addresses", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-16" }, { "control_id": "FSBP ECS.18", "title": "ECS Task Definitions should use in-transit encryption for EFS volumes", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS Task Definitions should use in-transit encryption for EFS volumes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-18" }, { "control_id": "FSBP ECS.19", "title": "ECS capacity providers should have managed termination protection enabled", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS capacity providers should have managed termination protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-19" }, { "control_id": "FSBP ECS.20", "title": "ECS Task Definitions should configure non-root users in Linux container definitions", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS Task Definitions should configure non-root users in Linux container definitions", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-20" }, { "control_id": "FSBP ECS.21", "title": "ECS Task Definitions should configure non-administrator users in Windows container definitions", "severity": "medium", "resource_types": [ "aws_ecs_cluster", "aws_ecs_service", "aws_ecs_task_definition" ], "requirement": "ECS Task Definitions should configure non-administrator users in Windows container definitions", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ecs-controls.html#ecs-21" }, { "control_id": "FSBP EFS.1", "title": "Elastic File System should be configured to encrypt file data at-rest using AWS KMS", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "Elastic File System should be configured to encrypt file data at-rest using AWS KMS", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-1" }, { "control_id": "FSBP EFS.2", "title": "Amazon EFS volumes should be in backup plans", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "Amazon EFS volumes should be in backup plans", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-2" }, { "control_id": "FSBP EFS.3", "title": "EFS access points should enforce a root directory", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "EFS access points should enforce a root directory", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-3" }, { "control_id": "FSBP EFS.4", "title": "EFS access points should enforce a user identity", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "EFS access points should enforce a user identity", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-4" }, { "control_id": "FSBP EFS.6", "title": "EFS mount targets should not be associated with subnets that assign public IP addresses on launch", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "EFS mount targets should not be associated with subnets that assign public IP addresses on launch", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-6" }, { "control_id": "FSBP EFS.7", "title": "EFS file systems should have automatic backups enabled", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "EFS file systems should have automatic backups enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-7" }, { "control_id": "FSBP EFS.8", "title": "EFS file systems should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_efs_file_system", "aws_efs_file_system_policy", "aws_efs_access_point" ], "requirement": "EFS file systems should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/efs-controls.html#efs-8" }, { "control_id": "FSBP EKS.1", "title": "EKS cluster endpoints should not be publicly accessible", "severity": "medium", "resource_types": [ "aws_eks_cluster", "aws_eks_node_group" ], "requirement": "EKS cluster endpoints should not be publicly accessible", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eks-controls.html#eks-1" }, { "control_id": "FSBP EKS.2", "title": "EKS clusters should run on a supported Kubernetes version", "severity": "medium", "resource_types": [ "aws_eks_cluster", "aws_eks_node_group" ], "requirement": "EKS clusters should run on a supported Kubernetes version", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eks-controls.html#eks-2" }, { "control_id": "FSBP EKS.3", "title": "EKS clusters should use encrypted Kubernetes secrets", "severity": "medium", "resource_types": [ "aws_eks_cluster", "aws_eks_node_group" ], "requirement": "EKS clusters should use encrypted Kubernetes secrets", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eks-controls.html#eks-3" }, { "control_id": "FSBP EKS.8", "title": "EKS clusters should have audit logging enabled", "severity": "medium", "resource_types": [ "aws_eks_cluster", "aws_eks_node_group" ], "requirement": "EKS clusters should have audit logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eks-controls.html#eks-8" }, { "control_id": "FSBP EKS.9", "title": "EKS node groups should run on a supported Kubernetes version", "severity": "medium", "resource_types": [ "aws_eks_cluster", "aws_eks_node_group" ], "requirement": "EKS node groups should run on a supported Kubernetes version", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eks-controls.html#eks-9" }, { "control_id": "FSBP ElastiCache.1", "title": "ElastiCache (Redis OSS) clusters should have automatic backups enabled", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache (Redis OSS) clusters should have automatic backups enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-1" }, { "control_id": "FSBP ElastiCache.2", "title": "ElastiCache clusters should have automatic minor version upgrades enabled", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache clusters should have automatic minor version upgrades enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-2" }, { "control_id": "FSBP ElastiCache.3", "title": "ElastiCache replication groups should have automatic failover enabled", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache replication groups should have automatic failover enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-3" }, { "control_id": "FSBP ElastiCache.4", "title": "ElastiCache replication groups should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache replication groups should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-4" }, { "control_id": "FSBP ElastiCache.5", "title": "ElastiCache replication groups should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache replication groups should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-5" }, { "control_id": "FSBP ElastiCache.6", "title": "ElastiCache (Redis OSS) replication groups of earlier versions should have Redis OSS AUTH enabled", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache (Redis OSS) replication groups of earlier versions should have Redis OSS AUTH enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-6" }, { "control_id": "FSBP ElastiCache.7", "title": "ElastiCache clusters should not use the default subnet group", "severity": "medium", "resource_types": [ "aws_elasticache_cluster", "aws_elasticache_replication_group" ], "requirement": "ElastiCache clusters should not use the default subnet group", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-7" }, { "control_id": "FSBP ElasticBeanstalk.1", "title": "Elastic Beanstalk environments should have enhanced health reporting enabled", "severity": "medium", "resource_types": [ "aws_elastic_beanstalk_environment" ], "requirement": "Elastic Beanstalk environments should have enhanced health reporting enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticbeanstalk-controls.html#elasticbeanstalk-1" }, { "control_id": "FSBP ElasticBeanstalk.2", "title": "Elastic Beanstalk managed platform updates should be enabled", "severity": "medium", "resource_types": [ "aws_elastic_beanstalk_environment" ], "requirement": "Elastic Beanstalk managed platform updates should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticbeanstalk-controls.html#elasticbeanstalk-2" }, { "control_id": "FSBP ElasticBeanstalk.3", "title": "Elastic Beanstalk should stream logs to CloudWatch", "severity": "medium", "resource_types": [ "aws_elastic_beanstalk_environment" ], "requirement": "Elastic Beanstalk should stream logs to CloudWatch", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticbeanstalk-controls.html#elasticbeanstalk-3" }, { "control_id": "FSBP ELB.1", "title": "Application Load Balancer should be configured to redirect all HTTP requests to HTTPS", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application Load Balancer should be configured to redirect all HTTP requests to HTTPS", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-1" }, { "control_id": "FSBP ELB.2", "title": "Classic Load Balancers with SSL/HTTPS listeners should use a certificate provided by AWS Certificate Manager", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancers with SSL/HTTPS listeners should use a certificate provided by AWS Certificate Manager", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-2" }, { "control_id": "FSBP ELB.3", "title": "Classic Load Balancer listeners should be configured with HTTPS or TLS termination", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancer listeners should be configured with HTTPS or TLS termination", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-3" }, { "control_id": "FSBP ELB.4", "title": "Application Load Balancer should be configured to drop invalid http headers", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application Load Balancer should be configured to drop invalid http headers", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-4" }, { "control_id": "FSBP ELB.5", "title": "Application and Classic Load Balancers logging should be enabled", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application and Classic Load Balancers logging should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-5" }, { "control_id": "FSBP ELB.6", "title": "Application, Gateway, and Network Load Balancers should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application, Gateway, and Network Load Balancers should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-6" }, { "control_id": "FSBP ELB.7", "title": "Classic Load Balancers should have connection draining enabled", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancers should have connection draining enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-7" }, { "control_id": "FSBP ELB.8", "title": "Classic Load Balancers with SSL listeners should use a predefined security policy that has strong AWS Configuration", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancers with SSL listeners should use a predefined security policy that has strong AWS Configuration", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-8" }, { "control_id": "FSBP ELB.9", "title": "Classic Load Balancers should have cross-zone load balancing enabled", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancers should have cross-zone load balancing enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-9" }, { "control_id": "FSBP ELB.10", "title": "Classic Load Balancer should span multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancer should span multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-10" }, { "control_id": "FSBP ELB.12", "title": "Application Load Balancer should be configured with defensive or strictest desync mitigation mode", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application Load Balancer should be configured with defensive or strictest desync mitigation mode", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-12" }, { "control_id": "FSBP ELB.13", "title": "Application, Network and Gateway Load Balancers should span multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application, Network and Gateway Load Balancers should span multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-13" }, { "control_id": "FSBP ELB.14", "title": "Classic Load Balancer should be configured with defensive or strictest desync mitigation mode", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Classic Load Balancer should be configured with defensive or strictest desync mitigation mode", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-14" }, { "control_id": "FSBP ELB.17", "title": "Application and Network Load Balancers with listeners should use recommended security policies", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application and Network Load Balancers with listeners should use recommended security policies", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-17" }, { "control_id": "FSBP ELB.18", "title": "Application and Network Load Balancer listeners should use secure protocols to encrypt data in transit", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application and Network Load Balancer listeners should use secure protocols to encrypt data in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-18" }, { "control_id": "FSBP ELB.21", "title": "Application and Network Load Balancer target groups should use encrypted health check protocols", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "Application and Network Load Balancer target groups should use encrypted health check protocols", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-21" }, { "control_id": "FSBP ELB.22", "title": "ELB target groups should use encrypted transport protocols", "severity": "medium", "resource_types": [ "aws_lb", "aws_alb", "aws_elb", "aws_lb_listener", "aws_alb_listener", "aws_lb_target_group" ], "requirement": "ELB target groups should use encrypted transport protocols", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-22" }, { "control_id": "FSBP EMR.1", "title": "Amazon EMR cluster primary nodes should not have public IP addresses", "severity": "medium", "resource_types": [ "aws_emr_cluster" ], "requirement": "Amazon EMR cluster primary nodes should not have public IP addresses", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/emr-controls.html#emr-1" }, { "control_id": "FSBP EMR.2", "title": "Amazon EMR block public access setting should be enabled", "severity": "medium", "resource_types": [ "aws_emr_cluster" ], "requirement": "Amazon EMR block public access setting should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/emr-controls.html#emr-2" }, { "control_id": "FSBP EMR.3", "title": "Amazon EMR security configurations should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_emr_cluster" ], "requirement": "Amazon EMR security configurations should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/emr-controls.html#emr-3" }, { "control_id": "FSBP EMR.4", "title": "Amazon EMR security configurations should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_emr_cluster" ], "requirement": "Amazon EMR security configurations should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/emr-controls.html#emr-4" }, { "control_id": "FSBP ES.1", "title": "Elasticsearch domains should have encryption at-rest enabled", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should have encryption at-rest enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-1" }, { "control_id": "FSBP ES.2", "title": "Elasticsearch domains should not be publicly accessible", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should not be publicly accessible", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-2" }, { "control_id": "FSBP ES.3", "title": "Elasticsearch domains should encrypt data sent between nodes", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should encrypt data sent between nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-3" }, { "control_id": "FSBP ES.4", "title": "Elasticsearch domain error logging to CloudWatch Logs should be enabled", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domain error logging to CloudWatch Logs should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-4" }, { "control_id": "FSBP ES.5", "title": "Elasticsearch domains should have audit logging enabled", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should have audit logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-5" }, { "control_id": "FSBP ES.6", "title": "Elasticsearch domains should have at least three data nodes", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should have at least three data nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-6" }, { "control_id": "FSBP ES.7", "title": "Elasticsearch domains should be configured with at least three dedicated master nodes", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Elasticsearch domains should be configured with at least three dedicated master nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-7" }, { "control_id": "FSBP ES.8", "title": "Connections to Elasticsearch domains should be encrypted using the latest TLS security policy", "severity": "medium", "resource_types": [ "aws_elasticsearch_domain" ], "requirement": "Connections to Elasticsearch domains should be encrypted using the latest TLS security policy", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/es-controls.html#es-8" }, { "control_id": "FSBP EventBridge.3", "title": "EventBridge custom event buses should have a resource-based policy attached", "severity": "medium", "resource_types": [ "aws_cloudwatch_event_rule", "aws_cloudwatch_event_bus" ], "requirement": "EventBridge custom event buses should have a resource-based policy attached", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/eventbridge-controls.html#eventbridge-3" }, { "control_id": "FSBP FSx.1", "title": "FSx for OpenZFS file systems should be configured to copy tags to backups and volumes", "severity": "medium", "resource_types": [ "aws_fsx_lustre_file_system", "aws_fsx_windows_file_system", "aws_fsx_openzfs_file_system", "aws_fsx_ontap_file_system" ], "requirement": "FSx for OpenZFS file systems should be configured to copy tags to backups and volumes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/fsx-controls.html#fsx-1" }, { "control_id": "FSBP FSx.2", "title": "FSx for Lustre file systems should be configured to copy tags to backups", "severity": "medium", "resource_types": [ "aws_fsx_lustre_file_system", "aws_fsx_windows_file_system", "aws_fsx_openzfs_file_system", "aws_fsx_ontap_file_system" ], "requirement": "FSx for Lustre file systems should be configured to copy tags to backups", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/fsx-controls.html#fsx-2" }, { "control_id": "FSBP FSx.3", "title": "FSx for OpenZFS file systems should be configured for Multi-AZ deployment", "severity": "medium", "resource_types": [ "aws_fsx_lustre_file_system", "aws_fsx_windows_file_system", "aws_fsx_openzfs_file_system", "aws_fsx_ontap_file_system" ], "requirement": "FSx for OpenZFS file systems should be configured for Multi-AZ deployment", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/fsx-controls.html#fsx-3" }, { "control_id": "FSBP FSx.4", "title": "FSx for NetApp ONTAP file systems should be configured for Multi-AZ deployment", "severity": "medium", "resource_types": [ "aws_fsx_lustre_file_system", "aws_fsx_windows_file_system", "aws_fsx_openzfs_file_system", "aws_fsx_ontap_file_system" ], "requirement": "FSx for NetApp ONTAP file systems should be configured for Multi-AZ deployment", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/fsx-controls.html#fsx-4" }, { "control_id": "FSBP FSx.5", "title": "FSx for Windows File Server file systems should be configured for Multi-AZ deployment", "severity": "medium", "resource_types": [ "aws_fsx_lustre_file_system", "aws_fsx_windows_file_system", "aws_fsx_openzfs_file_system", "aws_fsx_ontap_file_system" ], "requirement": "FSx for Windows File Server file systems should be configured for Multi-AZ deployment", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/fsx-controls.html#fsx-5" }, { "control_id": "FSBP Glue.3", "title": "AWS Glue machine learning transforms should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_glue_catalog_database", "aws_glue_crawler", "aws_glue_job" ], "requirement": "AWS Glue machine learning transforms should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/glue-controls.html#glue-3" }, { "control_id": "FSBP Glue.4", "title": "AWS Glue Spark jobs should run on supported versions of AWS Glue", "severity": "medium", "resource_types": [ "aws_glue_catalog_database", "aws_glue_crawler", "aws_glue_job" ], "requirement": "AWS Glue Spark jobs should run on supported versions of AWS Glue", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/glue-controls.html#glue-4" }, { "control_id": "FSBP GuardDuty.1", "title": "GuardDuty should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-1" }, { "control_id": "FSBP GuardDuty.5", "title": "GuardDuty EKS Audit Log Monitoring should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty EKS Audit Log Monitoring should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-5" }, { "control_id": "FSBP GuardDuty.6", "title": "GuardDuty Lambda Protection should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty Lambda Protection should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-6" }, { "control_id": "FSBP GuardDuty.7", "title": "GuardDuty EKS Runtime Monitoring should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty EKS Runtime Monitoring should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-7" }, { "control_id": "FSBP GuardDuty.8", "title": "GuardDuty Malware Protection for EC2 should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty Malware Protection for EC2 should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-8" }, { "control_id": "FSBP GuardDuty.9", "title": "GuardDuty RDS Protection should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty RDS Protection should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-9" }, { "control_id": "FSBP GuardDuty.10", "title": "GuardDuty S3 Protection should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty S3 Protection should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-10" }, { "control_id": "FSBP GuardDuty.11", "title": "GuardDuty Runtime Monitoring should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty Runtime Monitoring should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-11" }, { "control_id": "FSBP GuardDuty.12", "title": "GuardDuty ECS Runtime Monitoring should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty ECS Runtime Monitoring should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-12" }, { "control_id": "FSBP GuardDuty.13", "title": "GuardDuty EC2 Runtime Monitoring should be enabled", "severity": "medium", "resource_types": [ "aws_guardduty_detector" ], "requirement": "GuardDuty EC2 Runtime Monitoring should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html#guardduty-13" }, { "control_id": "FSBP IAM.1", "title": "IAM policies should not allow full \"*\" administrative privileges", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "IAM policies should not allow full \"*\" administrative privileges", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-1" }, { "control_id": "FSBP IAM.2", "title": "IAM users should not have IAM policies attached", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "IAM users should not have IAM policies attached", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-2" }, { "control_id": "FSBP IAM.3", "title": "IAM users' access keys should be rotated every 90 days or less", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "IAM users' access keys should be rotated every 90 days or less", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-3" }, { "control_id": "FSBP IAM.4", "title": "IAM root user access key should not exist", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "IAM root user access key should not exist", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-4" }, { "control_id": "FSBP IAM.5", "title": "MFA should be enabled for all IAM users that have a console password", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "MFA should be enabled for all IAM users that have a console password", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-5" }, { "control_id": "FSBP IAM.6", "title": "Hardware MFA should be enabled for the root user", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "Hardware MFA should be enabled for the root user", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-6" }, { "control_id": "FSBP IAM.7", "title": "Password policies for IAM users should have strong configurations", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "Password policies for IAM users should have strong configurations", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-7" }, { "control_id": "FSBP IAM.8", "title": "Unused IAM user credentials should be removed", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "Unused IAM user credentials should be removed", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-8" }, { "control_id": "FSBP IAM.21", "title": "IAM customer managed policies that you create should not allow wildcard actions for services", "severity": "medium", "resource_types": [ "aws_iam_user", "aws_iam_role", "aws_iam_policy", "aws_iam_user_policy", "aws_iam_role_policy", "aws_iam_access_key", "aws_iam_account_password_policy", "aws_iam_group", "aws_iam_user_policy_attachment", "aws_iam_role_policy_attachment" ], "requirement": "IAM customer managed policies that you create should not allow wildcard actions for services", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-21" }, { "control_id": "FSBP Inspector.1", "title": "Amazon Inspector EC2 scanning should be enabled", "severity": "medium", "resource_types": [ "aws_inspector2_enabler" ], "requirement": "Amazon Inspector EC2 scanning should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/inspector-controls.html#inspector-1" }, { "control_id": "FSBP Inspector.2", "title": "Amazon Inspector ECR scanning should be enabled", "severity": "medium", "resource_types": [ "aws_inspector2_enabler" ], "requirement": "Amazon Inspector ECR scanning should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/inspector-controls.html#inspector-2" }, { "control_id": "FSBP Inspector.3", "title": "Amazon Inspector Lambda code scanning should be enabled", "severity": "medium", "resource_types": [ "aws_inspector2_enabler" ], "requirement": "Amazon Inspector Lambda code scanning should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/inspector-controls.html#inspector-3" }, { "control_id": "FSBP Inspector.4", "title": "Amazon Inspector Lambda standard scanning should be enabled", "severity": "medium", "resource_types": [ "aws_inspector2_enabler" ], "requirement": "Amazon Inspector Lambda standard scanning should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/inspector-controls.html#inspector-4" }, { "control_id": "FSBP Kinesis.1", "title": "Kinesis streams should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_kinesis_stream" ], "requirement": "Kinesis streams should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kinesis-controls.html#kinesis-1" }, { "control_id": "FSBP Kinesis.3", "title": "Kinesis streams should have an adequate data retention period", "severity": "medium", "resource_types": [ "aws_kinesis_stream" ], "requirement": "Kinesis streams should have an adequate data retention period", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kinesis-controls.html#kinesis-3" }, { "control_id": "FSBP KMS.1", "title": "IAM customer managed policies should not allow decryption actions on all KMS keys", "severity": "medium", "resource_types": [ "aws_kms_key", "aws_kms_alias" ], "requirement": "IAM customer managed policies should not allow decryption actions on all KMS keys", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-1" }, { "control_id": "FSBP KMS.2", "title": "IAM principals should not have IAM inline policies that allow decryption actions on all KMS keys", "severity": "medium", "resource_types": [ "aws_kms_key", "aws_kms_alias" ], "requirement": "IAM principals should not have IAM inline policies that allow decryption actions on all KMS keys", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-2" }, { "control_id": "FSBP KMS.3", "title": "AWS KMS keys should not be deleted unintentionally", "severity": "medium", "resource_types": [ "aws_kms_key", "aws_kms_alias" ], "requirement": "AWS KMS keys should not be deleted unintentionally", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-3" }, { "control_id": "FSBP KMS.5", "title": "KMS keys should not be publicly accessible", "severity": "medium", "resource_types": [ "aws_kms_key", "aws_kms_alias" ], "requirement": "KMS keys should not be publicly accessible", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-5" }, { "control_id": "FSBP Lambda.1", "title": "Lambda function policies should prohibit public access", "severity": "medium", "resource_types": [ "aws_lambda_function", "aws_lambda_permission", "aws_lambda_function_url" ], "requirement": "Lambda function policies should prohibit public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/lambda-controls.html#lambda-1" }, { "control_id": "FSBP Lambda.2", "title": "Lambda functions should use supported runtimes", "severity": "medium", "resource_types": [ "aws_lambda_function", "aws_lambda_permission", "aws_lambda_function_url" ], "requirement": "Lambda functions should use supported runtimes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/lambda-controls.html#lambda-2" }, { "control_id": "FSBP Lambda.5", "title": "VPC Lambda functions should operate in multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_lambda_function", "aws_lambda_permission", "aws_lambda_function_url" ], "requirement": "VPC Lambda functions should operate in multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/lambda-controls.html#lambda-5" }, { "control_id": "FSBP Macie.1", "title": "Amazon Macie should be enabled", "severity": "medium", "resource_types": [ "aws_macie2_account" ], "requirement": "Amazon Macie should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/macie-controls.html#macie-1" }, { "control_id": "FSBP Macie.2", "title": "Macie automated sensitive data discovery should be enabled", "severity": "medium", "resource_types": [ "aws_macie2_account" ], "requirement": "Macie automated sensitive data discovery should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/macie-controls.html#macie-2" }, { "control_id": "FSBP MQ.2", "title": "ActiveMQ brokers should stream audit logs to CloudWatch", "severity": "medium", "resource_types": [ "aws_mq_broker" ], "requirement": "ActiveMQ brokers should stream audit logs to CloudWatch", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/mq-controls.html#mq-2" }, { "control_id": "FSBP MQ.3", "title": "Amazon MQ brokers should have automatic minor version upgrade enabled", "severity": "medium", "resource_types": [ "aws_mq_broker" ], "requirement": "Amazon MQ brokers should have automatic minor version upgrade enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/mq-controls.html#mq-3" }, { "control_id": "FSBP MSK.1", "title": "MSK clusters should be encrypted in transit among broker nodes", "severity": "medium", "resource_types": [ "aws_msk_cluster" ], "requirement": "MSK clusters should be encrypted in transit among broker nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/msk-controls.html#msk-1" }, { "control_id": "FSBP MSK.3", "title": "MSK Connect connectors should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_msk_cluster" ], "requirement": "MSK Connect connectors should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/msk-controls.html#msk-3" }, { "control_id": "FSBP MSK.4", "title": "MSK clusters should have public access disabled", "severity": "medium", "resource_types": [ "aws_msk_cluster" ], "requirement": "MSK clusters should have public access disabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/msk-controls.html#msk-4" }, { "control_id": "FSBP MSK.5", "title": "MSK connectors should have logging enabled", "severity": "medium", "resource_types": [ "aws_msk_cluster" ], "requirement": "MSK connectors should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/msk-controls.html#msk-5" }, { "control_id": "FSBP MSK.6", "title": "MSK clusters should disable unauthenticated access", "severity": "medium", "resource_types": [ "aws_msk_cluster" ], "requirement": "MSK clusters should disable unauthenticated access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/msk-controls.html#msk-6" }, { "control_id": "FSBP Neptune.1", "title": "Neptune DB clusters should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-1" }, { "control_id": "FSBP Neptune.2", "title": "Neptune DB clusters should publish audit logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should publish audit logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-2" }, { "control_id": "FSBP Neptune.3", "title": "Neptune DB cluster snapshots should not be public", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB cluster snapshots should not be public", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-3" }, { "control_id": "FSBP Neptune.4", "title": "Neptune DB clusters should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-4" }, { "control_id": "FSBP Neptune.5", "title": "Neptune DB clusters should have automated backups enabled", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should have automated backups enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-5" }, { "control_id": "FSBP Neptune.6", "title": "Neptune DB cluster snapshots should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB cluster snapshots should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-6" }, { "control_id": "FSBP Neptune.7", "title": "Neptune DB clusters should have IAM database authentication enabled", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should have IAM database authentication enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-7" }, { "control_id": "FSBP Neptune.8", "title": "Neptune DB clusters should be configured to copy tags to snapshots", "severity": "medium", "resource_types": [ "aws_neptune_cluster", "aws_neptune_cluster_instance" ], "requirement": "Neptune DB clusters should be configured to copy tags to snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-8" }, { "control_id": "FSBP NetworkFirewall.2", "title": "Network Firewall logging should be enabled", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "Network Firewall logging should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-2" }, { "control_id": "FSBP NetworkFirewall.3", "title": "Network Firewall policies should have at least one rule group associated", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "Network Firewall policies should have at least one rule group associated", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-3" }, { "control_id": "FSBP NetworkFirewall.4", "title": "The default stateless action for Network Firewall policies should be drop or forward for full packets", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "The default stateless action for Network Firewall policies should be drop or forward for full packets", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-4" }, { "control_id": "FSBP NetworkFirewall.5", "title": "The default stateless action for Network Firewall policies should be drop or forward for fragmented packets", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "The default stateless action for Network Firewall policies should be drop or forward for fragmented packets", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-5" }, { "control_id": "FSBP NetworkFirewall.6", "title": "Stateless Network Firewall rule group should not be empty", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "Stateless Network Firewall rule group should not be empty", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-6" }, { "control_id": "FSBP NetworkFirewall.9", "title": "Network Firewall firewalls should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "Network Firewall firewalls should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-9" }, { "control_id": "FSBP NetworkFirewall.10", "title": "Network Firewall firewalls should have subnet change protection enabled", "severity": "medium", "resource_types": [ "aws_networkfirewall_firewall", "aws_networkfirewall_firewall_policy", "aws_networkfirewall_rule_group" ], "requirement": "Network Firewall firewalls should have subnet change protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-10" }, { "control_id": "FSBP Opensearch.1", "title": "OpenSearch domains should have encryption at rest enabled", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should have encryption at rest enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-1" }, { "control_id": "FSBP Opensearch.2", "title": "OpenSearch domains should not be publicly accessible", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should not be publicly accessible", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-2" }, { "control_id": "FSBP Opensearch.3", "title": "OpenSearch domains should encrypt data sent between nodes", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should encrypt data sent between nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-3" }, { "control_id": "FSBP Opensearch.4", "title": "OpenSearch domain error logging to CloudWatch Logs should be enabled", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domain error logging to CloudWatch Logs should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-4" }, { "control_id": "FSBP Opensearch.5", "title": "OpenSearch domains should have audit logging enabled", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should have audit logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-5" }, { "control_id": "FSBP Opensearch.6", "title": "OpenSearch domains should have at least three data nodes", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should have at least three data nodes", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-6" }, { "control_id": "FSBP Opensearch.7", "title": "OpenSearch domains should have fine-grained access control enabled", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should have fine-grained access control enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-7" }, { "control_id": "FSBP Opensearch.8", "title": "Connections to OpenSearch domains should be encrypted using the latest TLS security policy", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "Connections to OpenSearch domains should be encrypted using the latest TLS security policy", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-8" }, { "control_id": "FSBP Opensearch.10", "title": "OpenSearch domains should have the latest software update installed", "severity": "medium", "resource_types": [ "aws_opensearch_domain" ], "requirement": "OpenSearch domains should have the latest software update installed", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/opensearch-controls.html#opensearch-10" }, { "control_id": "FSBP PCA.1", "title": "AWS Private CA root certificate authority should be disabled", "severity": "medium", "resource_types": [ "aws_acmpca_certificate_authority" ], "requirement": "AWS Private CA root certificate authority should be disabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/pca-controls.html#pca-1" }, { "control_id": "FSBP Route53.2", "title": "Route\u00c2\u00a053 public hosted zones should log DNS queries", "severity": "medium", "resource_types": [ "aws_route53_zone" ], "requirement": "Route\u00c2\u00a053 public hosted zones should log DNS queries", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/route53-controls.html#route53-2" }, { "control_id": "FSBP RDS.1", "title": "RDS snapshot should be private", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS snapshot should be private", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-1" }, { "control_id": "FSBP RDS.2", "title": "RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-2" }, { "control_id": "FSBP RDS.3", "title": "RDS DB instances should have encryption at-rest enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should have encryption at-rest enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-3" }, { "control_id": "FSBP RDS.4", "title": "RDS cluster snapshots and database snapshots should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS cluster snapshots and database snapshots should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-4" }, { "control_id": "FSBP RDS.5", "title": "RDS DB instances should be configured with multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should be configured with multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-5" }, { "control_id": "FSBP RDS.6", "title": "Enhanced monitoring should be configured for RDS DB instances", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Enhanced monitoring should be configured for RDS DB instances", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-6" }, { "control_id": "FSBP RDS.7", "title": "RDS clusters should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS clusters should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-7" }, { "control_id": "FSBP RDS.8", "title": "RDS DB instances should have deletion protection enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should have deletion protection enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-8" }, { "control_id": "FSBP RDS.9", "title": "RDS DB instances should publish logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should publish logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-9" }, { "control_id": "FSBP RDS.10", "title": "IAM authentication should be configured for RDS instances", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "IAM authentication should be configured for RDS instances", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-10" }, { "control_id": "FSBP RDS.11", "title": "RDS instances should have automatic backups enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS instances should have automatic backups enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-11" }, { "control_id": "FSBP RDS.12", "title": "IAM authentication should be configured for RDS clusters", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "IAM authentication should be configured for RDS clusters", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-12" }, { "control_id": "FSBP RDS.13", "title": "RDS automatic minor version upgrades should be enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS automatic minor version upgrades should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-13" }, { "control_id": "FSBP RDS.14", "title": "Amazon Aurora clusters should have backtracking enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Amazon Aurora clusters should have backtracking enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-14" }, { "control_id": "FSBP RDS.15", "title": "RDS DB clusters should be configured for multiple Availability Zones", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB clusters should be configured for multiple Availability Zones", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-15" }, { "control_id": "FSBP RDS.16", "title": "Aurora DB clusters should be configured to copy tags to DB snapshots", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Aurora DB clusters should be configured to copy tags to DB snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-16" }, { "control_id": "FSBP RDS.17", "title": "RDS DB instances should be configured to copy tags to snapshots", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should be configured to copy tags to snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-17" }, { "control_id": "FSBP RDS.19", "title": "Existing RDS event notification subscriptions should be configured for critical cluster events", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Existing RDS event notification subscriptions should be configured for critical cluster events", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-19" }, { "control_id": "FSBP RDS.20", "title": "Existing RDS event notification subscriptions should be configured for critical database instance events", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Existing RDS event notification subscriptions should be configured for critical database instance events", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-20" }, { "control_id": "FSBP RDS.21", "title": "An RDS event notifications subscription should be configured for critical database parameter group events", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "An RDS event notifications subscription should be configured for critical database parameter group events", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-21" }, { "control_id": "FSBP RDS.22", "title": "An RDS event notifications subscription should be configured for critical database security group events", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "An RDS event notifications subscription should be configured for critical database security group events", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-22" }, { "control_id": "FSBP RDS.23", "title": "RDS instances should not use a database engine default port", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS instances should not use a database engine default port", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-23" }, { "control_id": "FSBP RDS.24", "title": "RDS Database clusters should use a custom administrator username", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS Database clusters should use a custom administrator username", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-24" }, { "control_id": "FSBP RDS.25", "title": "RDS database instances should use a custom administrator username", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS database instances should use a custom administrator username", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-25" }, { "control_id": "FSBP RDS.27", "title": "RDS DB clusters should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB clusters should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-27" }, { "control_id": "FSBP RDS.34", "title": "Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-34" }, { "control_id": "FSBP RDS.35", "title": "RDS DB clusters should have automatic minor version upgrade enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB clusters should have automatic minor version upgrade enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-35" }, { "control_id": "FSBP RDS.36", "title": "RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-36" }, { "control_id": "FSBP RDS.37", "title": "Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-37" }, { "control_id": "FSBP RDS.40", "title": "RDS for SQL Server DB instances should publish logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for SQL Server DB instances should publish logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-40" }, { "control_id": "FSBP RDS.41", "title": "RDS for SQL Server DB instances should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for SQL Server DB instances should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-41" }, { "control_id": "FSBP RDS.42", "title": "RDS for MariaDB DB instances should publish logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for MariaDB DB instances should publish logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-42" }, { "control_id": "FSBP RDS.43", "title": "RDS DB proxies should require TLS encryption for connections", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB proxies should require TLS encryption for connections", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-43" }, { "control_id": "FSBP RDS.44", "title": "RDS for MariaDB DB instances should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for MariaDB DB instances should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-44" }, { "control_id": "FSBP RDS.45", "title": "Aurora MySQL DB clusters should have audit logging enabled", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "Aurora MySQL DB clusters should have audit logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-45" }, { "control_id": "FSBP RDS.46", "title": "RDS DB instances should not be deployed in public subnets with routes to internet gateways", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB instances should not be deployed in public subnets with routes to internet gateways", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-46" }, { "control_id": "FSBP RDS.47", "title": "RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-47" }, { "control_id": "FSBP RDS.48", "title": "RDS for MySQL DB clusters should be configured to copy tags to DB snapshots", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS for MySQL DB clusters should be configured to copy tags to DB snapshots", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-48" }, { "control_id": "FSBP RDS.50", "title": "RDS DB clusters should have enough backup retention period set", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS DB clusters should have enough backup retention period set", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-50" }, { "control_id": "FSBP RDS.51", "title": "RDS global clusters should run on a supported Aurora MySQL version", "severity": "medium", "resource_types": [ "aws_db_instance", "aws_rds_cluster", "aws_db_subnet_group", "aws_db_parameter_group", "aws_rds_cluster_instance", "aws_db_snapshot", "aws_db_event_subscription" ], "requirement": "RDS global clusters should run on a supported Aurora MySQL version", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-51" }, { "control_id": "FSBP Redshift.1", "title": "Amazon Redshift clusters should prohibit public access", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Amazon Redshift clusters should prohibit public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-1" }, { "control_id": "FSBP Redshift.2", "title": "Connections to Amazon Redshift clusters should be encrypted in transit", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Connections to Amazon Redshift clusters should be encrypted in transit", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-2" }, { "control_id": "FSBP Redshift.3", "title": "Amazon Redshift clusters should have automatic snapshots enabled", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Amazon Redshift clusters should have automatic snapshots enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-3" }, { "control_id": "FSBP Redshift.4", "title": "Amazon Redshift clusters should have audit logging enabled", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Amazon Redshift clusters should have audit logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-4" }, { "control_id": "FSBP Redshift.6", "title": "Amazon Redshift should have automatic upgrades to major versions enabled", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Amazon Redshift should have automatic upgrades to major versions enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-6" }, { "control_id": "FSBP Redshift.7", "title": "Redshift clusters should use enhanced VPC routing", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Redshift clusters should use enhanced VPC routing", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-7" }, { "control_id": "FSBP Redshift.8", "title": "Amazon Redshift clusters should not use the default Admin username", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Amazon Redshift clusters should not use the default Admin username", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-8" }, { "control_id": "FSBP Redshift.10", "title": "Redshift clusters should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Redshift clusters should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-10" }, { "control_id": "FSBP Redshift.15", "title": "Redshift security groups should allow ingress on the cluster port only from restricted origins", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Redshift security groups should allow ingress on the cluster port only from restricted origins", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-15" }, { "control_id": "FSBP Redshift.18", "title": "Redshift clusters should have Multi-AZ deployments enabled", "severity": "medium", "resource_types": [ "aws_redshift_cluster", "aws_redshift_parameter_group" ], "requirement": "Redshift clusters should have Multi-AZ deployments enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshift-controls.html#redshift-18" }, { "control_id": "FSBP RedshiftServerless.1", "title": "Amazon Redshift Serverless workgroups should use enhanced VPC routing", "severity": "medium", "resource_types": [ "aws_redshiftserverless_namespace", "aws_redshiftserverless_workgroup" ], "requirement": "Amazon Redshift Serverless workgroups should use enhanced VPC routing", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshiftserverless-controls.html#redshiftserverless-1" }, { "control_id": "FSBP RedshiftServerless.2", "title": "Connections to Redshift Serverless workgroups should be required to use SSL", "severity": "medium", "resource_types": [ "aws_redshiftserverless_namespace", "aws_redshiftserverless_workgroup" ], "requirement": "Connections to Redshift Serverless workgroups should be required to use SSL", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshiftserverless-controls.html#redshiftserverless-2" }, { "control_id": "FSBP RedshiftServerless.3", "title": "Redshift Serverless workgroups should prohibit public access", "severity": "medium", "resource_types": [ "aws_redshiftserverless_namespace", "aws_redshiftserverless_workgroup" ], "requirement": "Redshift Serverless workgroups should prohibit public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshiftserverless-controls.html#redshiftserverless-3" }, { "control_id": "FSBP RedshiftServerless.5", "title": "Redshift Serverless namespaces should not use the default admin username", "severity": "medium", "resource_types": [ "aws_redshiftserverless_namespace", "aws_redshiftserverless_workgroup" ], "requirement": "Redshift Serverless namespaces should not use the default admin username", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshiftserverless-controls.html#redshiftserverless-5" }, { "control_id": "FSBP RedshiftServerless.6", "title": "Redshift Serverless namespaces should export logs to CloudWatch Logs", "severity": "medium", "resource_types": [ "aws_redshiftserverless_namespace", "aws_redshiftserverless_workgroup" ], "requirement": "Redshift Serverless namespaces should export logs to CloudWatch Logs", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/redshiftserverless-controls.html#redshiftserverless-6" }, { "control_id": "FSBP S3.1", "title": "S3 general purpose buckets should have block public access settings enabled", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should have block public access settings enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-1" }, { "control_id": "FSBP S3.2", "title": "S3 general purpose buckets should block public read access", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should block public read access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-2" }, { "control_id": "FSBP S3.3", "title": "S3 general purpose buckets should block public write access", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should block public write access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-3" }, { "control_id": "FSBP S3.5", "title": "S3 general purpose buckets should require requests to use SSL", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should require requests to use SSL", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5" }, { "control_id": "FSBP S3.6", "title": "S3 general purpose bucket policies should restrict access to other AWS accounts", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose bucket policies should restrict access to other AWS accounts", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-6" }, { "control_id": "FSBP S3.8", "title": "S3 general purpose buckets should block public access", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should block public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-8" }, { "control_id": "FSBP S3.9", "title": "S3 general purpose buckets should have server access logging enabled", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should have server access logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-9" }, { "control_id": "FSBP S3.12", "title": "ACLs should not be used to manage user access to S3 general purpose buckets", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "ACLs should not be used to manage user access to S3 general purpose buckets", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-12" }, { "control_id": "FSBP S3.13", "title": "S3 general purpose buckets should have Lifecycle configurations", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 general purpose buckets should have Lifecycle configurations", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-13" }, { "control_id": "FSBP S3.19", "title": "S3 access points should have block public access settings enabled", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 access points should have block public access settings enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-19" }, { "control_id": "FSBP S3.24", "title": "S3 Multi-Region Access Points should have block public access settings enabled", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 Multi-Region Access Points should have block public access settings enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-24" }, { "control_id": "FSBP S3.25", "title": "S3 directory buckets should have lifecycle configurations", "severity": "medium", "resource_types": [ "aws_s3_bucket", "aws_s3_bucket_policy", "aws_s3_bucket_public_access_block", "aws_s3_bucket_versioning", "aws_s3_bucket_server_side_encryption_configuration", "aws_s3_bucket_logging", "aws_s3_bucket_lifecycle_configuration", "aws_s3_bucket_acl" ], "requirement": "S3 directory buckets should have lifecycle configurations", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-25" }, { "control_id": "FSBP SageMaker.1", "title": "Amazon SageMaker notebook instances should not have direct internet access", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "Amazon SageMaker notebook instances should not have direct internet access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-1" }, { "control_id": "FSBP SageMaker.2", "title": "SageMaker notebook instances should be launched in a custom VPC", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker notebook instances should be launched in a custom VPC", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-2" }, { "control_id": "FSBP SageMaker.3", "title": "Users should not have root access to SageMaker notebook instances", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "Users should not have root access to SageMaker notebook instances", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-3" }, { "control_id": "FSBP SageMaker.4", "title": "SageMaker endpoint production variants should have an initial instance count greater than 1", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker endpoint production variants should have an initial instance count greater than 1", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-4" }, { "control_id": "FSBP SageMaker.5", "title": "SageMaker models should have network isolation enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker models should have network isolation enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-5" }, { "control_id": "FSBP SageMaker.8", "title": "SageMaker notebook instances should run on supported platforms", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker notebook instances should run on supported platforms", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-8" }, { "control_id": "FSBP SageMaker.9", "title": "SageMaker data quality job definitions should have inter-container traffic encryption enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker data quality job definitions should have inter-container traffic encryption enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-9" }, { "control_id": "FSBP SageMaker.10", "title": "SageMaker model explainability job definitions should have inter-container traffic encryption enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker model explainability job definitions should have inter-container traffic encryption enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-10" }, { "control_id": "FSBP SageMaker.11", "title": "SageMaker data quality job definitions should have network isolation enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker data quality job definitions should have network isolation enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-11" }, { "control_id": "FSBP SageMaker.12", "title": "SageMaker model bias job definitions should have network isolation enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker model bias job definitions should have network isolation enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-12" }, { "control_id": "FSBP SageMaker.13", "title": "SageMaker model quality job definitions should have inter-container traffic encryption enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker model quality job definitions should have inter-container traffic encryption enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-13" }, { "control_id": "FSBP SageMaker.14", "title": "SageMaker monitoring schedules should have network isolation enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker monitoring schedules should have network isolation enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-14" }, { "control_id": "FSBP SageMaker.15", "title": "SageMaker model bias job definitions should have inter-container traffic encryption enabled", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker model bias job definitions should have inter-container traffic encryption enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-15" }, { "control_id": "FSBP SageMaker.16", "title": "SageMaker models should use private registry in VPC for primary containers", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker models should use private registry in VPC for primary containers", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-16" }, { "control_id": "FSBP SageMaker.17", "title": "SageMaker feature group offline stores should be encrypted with AWS KMS keys", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker feature group offline stores should be encrypted with AWS KMS keys", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-17" }, { "control_id": "FSBP SageMaker.19", "title": "SageMaker models should use private registry in VPC for multi-container inference pipelines", "severity": "medium", "resource_types": [ "aws_sagemaker_notebook_instance", "aws_sagemaker_endpoint_configuration", "aws_sagemaker_model" ], "requirement": "SageMaker models should use private registry in VPC for multi-container inference pipelines", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sagemaker-controls.html#sagemaker-19" }, { "control_id": "FSBP SecretsManager.1", "title": "Secrets Manager secrets should have automatic rotation enabled", "severity": "medium", "resource_types": [ "aws_secretsmanager_secret", "aws_secretsmanager_secret_rotation" ], "requirement": "Secrets Manager secrets should have automatic rotation enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/secretsmanager-controls.html#secretsmanager-1" }, { "control_id": "FSBP SecretsManager.2", "title": "Secrets Manager secrets configured with automatic rotation should rotate successfully", "severity": "medium", "resource_types": [ "aws_secretsmanager_secret", "aws_secretsmanager_secret_rotation" ], "requirement": "Secrets Manager secrets configured with automatic rotation should rotate successfully", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/secretsmanager-controls.html#secretsmanager-2" }, { "control_id": "FSBP SecretsManager.3", "title": "Remove unused Secrets Manager secrets", "severity": "medium", "resource_types": [ "aws_secretsmanager_secret", "aws_secretsmanager_secret_rotation" ], "requirement": "Remove unused Secrets Manager secrets", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/secretsmanager-controls.html#secretsmanager-3" }, { "control_id": "FSBP SecretsManager.4", "title": "Secrets Manager secrets should be rotated within a specified number of days", "severity": "medium", "resource_types": [ "aws_secretsmanager_secret", "aws_secretsmanager_secret_rotation" ], "requirement": "Secrets Manager secrets should be rotated within a specified number of days", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/secretsmanager-controls.html#secretsmanager-4" }, { "control_id": "FSBP ServiceCatalog.1", "title": "Service Catalog portfolios should be shared within an AWS organization only", "severity": "medium", "resource_types": [ "aws_servicecatalog_portfolio" ], "requirement": "Service Catalog portfolios should be shared within an AWS organization only", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/servicecatalog-controls.html#servicecatalog-1" }, { "control_id": "FSBP SES.3", "title": "SES configuration sets should have TLS enabled for sending emails", "severity": "medium", "resource_types": [ "aws_ses_configuration_set", "aws_ses_domain_identity" ], "requirement": "SES configuration sets should have TLS enabled for sending emails", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ses-controls.html#ses-3" }, { "control_id": "FSBP SNS.4", "title": "SNS topic access policies should not allow public access", "severity": "medium", "resource_types": [ "aws_sns_topic", "aws_sns_topic_policy" ], "requirement": "SNS topic access policies should not allow public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sns-controls.html#sns-4" }, { "control_id": "FSBP SQS.1", "title": "Amazon SQS queues should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_sqs_queue" ], "requirement": "Amazon SQS queues should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sqs-controls.html#sqs-1" }, { "control_id": "FSBP SQS.3", "title": "SQS queue access policies should not allow public access", "severity": "medium", "resource_types": [ "aws_sqs_queue" ], "requirement": "SQS queue access policies should not allow public access", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/sqs-controls.html#sqs-3" }, { "control_id": "FSBP SSM.1", "title": "Amazon EC2 instances should be managed by AWS Systems Manager", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "Amazon EC2 instances should be managed by AWS Systems Manager", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-1" }, { "control_id": "FSBP SSM.2", "title": "Amazon EC2 instances managed by Systems Manager should have a patch compliance status of COMPLIANT after a patch installation", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "Amazon EC2 instances managed by Systems Manager should have a patch compliance status of COMPLIANT after a patch installation", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-2" }, { "control_id": "FSBP SSM.3", "title": "Amazon EC2 instances managed by Systems Manager should have an association compliance status of COMPLIANT", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "Amazon EC2 instances managed by Systems Manager should have an association compliance status of COMPLIANT", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-3" }, { "control_id": "FSBP SSM.4", "title": "SSM documents should not be public", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "SSM documents should not be public", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-4" }, { "control_id": "FSBP SSM.6", "title": "SSM Automation should have CloudWatch logging enabled", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "SSM Automation should have CloudWatch logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-6" }, { "control_id": "FSBP SSM.7", "title": "SSM documents should have the block public sharing setting enabled", "severity": "medium", "resource_types": [ "aws_ssm_document", "aws_ssm_parameter", "aws_ssm_association" ], "requirement": "SSM documents should have the block public sharing setting enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/ssm-controls.html#ssm-7" }, { "control_id": "FSBP StepFunctions.1", "title": "Step Functions state machines should have logging turned on", "severity": "medium", "resource_types": [ "aws_sfn_state_machine" ], "requirement": "Step Functions state machines should have logging turned on", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/stepfunctions-controls.html#stepfunctions-1" }, { "control_id": "FSBP Transfer.2", "title": "Transfer Family servers should not use FTP protocol for endpoint connection", "severity": "medium", "resource_types": [ "aws_transfer_server", "aws_transfer_user" ], "requirement": "Transfer Family servers should not use FTP protocol for endpoint connection", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/transfer-controls.html#transfer-2" }, { "control_id": "FSBP Transfer.3", "title": "Transfer Family connectors should have logging enabled", "severity": "medium", "resource_types": [ "aws_transfer_server", "aws_transfer_user" ], "requirement": "Transfer Family connectors should have logging enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/transfer-controls.html#transfer-3" }, { "control_id": "FSBP WAF.1", "title": "AWS WAF Classic Global Web ACL logging should be enabled", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic Global Web ACL logging should be enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-1" }, { "control_id": "FSBP WAF.2", "title": "AWS WAF Classic Regional rules should have at least one condition", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic Regional rules should have at least one condition", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-2" }, { "control_id": "FSBP WAF.3", "title": "AWS WAF Classic Regional rule groups should have at least one rule", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic Regional rule groups should have at least one rule", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-3" }, { "control_id": "FSBP WAF.4", "title": "AWS WAF Classic Regional web ACLs should have at least one rule or rule group", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic Regional web ACLs should have at least one rule or rule group", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-4" }, { "control_id": "FSBP WAF.6", "title": "AWS WAF Classic global rules should have at least one condition", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic global rules should have at least one condition", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-6" }, { "control_id": "FSBP WAF.7", "title": "AWS WAF Classic global rule groups should have at least one rule", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic global rule groups should have at least one rule", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-7" }, { "control_id": "FSBP WAF.8", "title": "AWS WAF Classic global web ACLs should have at least one rule or rule group", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF Classic global web ACLs should have at least one rule or rule group", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-8" }, { "control_id": "FSBP WAF.10", "title": "AWS WAF web ACLs should have at least one rule or rule group", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF web ACLs should have at least one rule or rule group", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-10" }, { "control_id": "FSBP WAF.12", "title": "AWS WAF rules should have CloudWatch metrics enabled", "severity": "medium", "resource_types": [ "aws_wafv2_web_acl", "aws_waf_web_acl", "aws_wafv2_web_acl_association" ], "requirement": "AWS WAF rules should have CloudWatch metrics enabled", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/waf-controls.html#waf-12" }, { "control_id": "FSBP WorkSpaces.1", "title": "WorkSpaces user volumes should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_workspaces_directory", "aws_workspaces_workspace" ], "requirement": "WorkSpaces user volumes should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/workspaces-controls.html#workspaces-1" }, { "control_id": "FSBP WorkSpaces.2", "title": "WorkSpaces root volumes should be encrypted at rest", "severity": "medium", "resource_types": [ "aws_workspaces_directory", "aws_workspaces_workspace" ], "requirement": "WorkSpaces root volumes should be encrypted at rest", "source_url": "https://docs.aws.amazon.com/securityhub/latest/userguide/workspaces-controls.html#workspaces-2" } ], "by_resource_type": { "aws_account_alternate_contact": [ "FSBP Account.1" ], "aws_acm_certificate": [ "FSBP ACM.1", "FSBP ACM.2" ], "aws_acmpca_certificate_authority": [ "FSBP PCA.1" ], "aws_alb": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_alb_listener": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_api_gateway_method": [ "FSBP APIGateway.1", "FSBP APIGateway.10", "FSBP APIGateway.11", "FSBP APIGateway.2", "FSBP APIGateway.3", "FSBP APIGateway.4", "FSBP APIGateway.5", "FSBP APIGateway.8", "FSBP APIGateway.9" ], "aws_api_gateway_rest_api": [ "FSBP APIGateway.1", "FSBP APIGateway.10", "FSBP APIGateway.11", "FSBP APIGateway.2", "FSBP APIGateway.3", "FSBP APIGateway.4", "FSBP APIGateway.5", "FSBP APIGateway.8", "FSBP APIGateway.9" ], "aws_api_gateway_stage": [ "FSBP APIGateway.1", "FSBP APIGateway.10", "FSBP APIGateway.11", "FSBP APIGateway.2", "FSBP APIGateway.3", "FSBP APIGateway.4", "FSBP APIGateway.5", "FSBP APIGateway.8", "FSBP APIGateway.9" ], "aws_apigatewayv2_api": [ "FSBP APIGateway.1", "FSBP APIGateway.10", "FSBP APIGateway.11", "FSBP APIGateway.2", "FSBP APIGateway.3", "FSBP APIGateway.4", "FSBP APIGateway.5", "FSBP APIGateway.8", "FSBP APIGateway.9" ], "aws_appsync_graphql_api": [ "FSBP AppSync.1", "FSBP AppSync.2", "FSBP AppSync.5", "FSBP AppSync.6" ], "aws_athena_workgroup": [ "FSBP Athena.4" ], "aws_autoscaling_group": [ "FSBP AutoScaling.1", "FSBP AutoScaling.2", "FSBP AutoScaling.3", "FSBP AutoScaling.6", "FSBP AutoScaling.9", "FSBP Autoscaling.5" ], "aws_backup_plan": [ "FSBP Backup.1" ], "aws_backup_vault": [ "FSBP Backup.1" ], "aws_cloudformation_stack": [ "FSBP CloudFormation.3", "FSBP CloudFormation.4" ], "aws_cloudformation_stack_set": [ "FSBP CloudFormation.3", "FSBP CloudFormation.4" ], "aws_cloudfront_distribution": [ "FSBP CloudFront.1", "FSBP CloudFront.10", "FSBP CloudFront.12", "FSBP CloudFront.13", "FSBP CloudFront.15", "FSBP CloudFront.16", "FSBP CloudFront.17", "FSBP CloudFront.3", "FSBP CloudFront.4", "FSBP CloudFront.5", "FSBP CloudFront.6", "FSBP CloudFront.7", "FSBP CloudFront.8", "FSBP CloudFront.9" ], "aws_cloudtrail": [ "FSBP CloudTrail.1", "FSBP CloudTrail.2", "FSBP CloudTrail.4", "FSBP CloudTrail.5" ], "aws_cloudwatch_event_bus": [ "FSBP EventBridge.3" ], "aws_cloudwatch_event_rule": [ "FSBP EventBridge.3" ], "aws_codebuild_project": [ "FSBP CodeBuild.1", "FSBP CodeBuild.2", "FSBP CodeBuild.3", "FSBP CodeBuild.4", "FSBP CodeBuild.7" ], "aws_cognito_identity_pool": [ "FSBP Cognito.2", "FSBP Cognito.3", "FSBP Cognito.4", "FSBP Cognito.5", "FSBP Cognito.6" ], "aws_cognito_user_pool": [ "FSBP Cognito.2", "FSBP Cognito.3", "FSBP Cognito.4", "FSBP Cognito.5", "FSBP Cognito.6" ], "aws_config_config_rule": [ "FSBP Config.1" ], "aws_config_configuration_recorder": [ "FSBP Config.1" ], "aws_config_delivery_channel": [ "FSBP Config.1" ], "aws_connect_instance": [ "FSBP Connect.2" ], "aws_datasync_task": [ "FSBP DataSync.1" ], "aws_db_event_subscription": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_db_instance": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_db_parameter_group": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_db_snapshot": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_db_subnet_group": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_default_security_group": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_dms_endpoint": [ "FSBP DMS.1", "FSBP DMS.10", "FSBP DMS.11", "FSBP DMS.12", "FSBP DMS.13", "FSBP DMS.6", "FSBP DMS.7", "FSBP DMS.8", "FSBP DMS.9" ], "aws_dms_replication_instance": [ "FSBP DMS.1", "FSBP DMS.10", "FSBP DMS.11", "FSBP DMS.12", "FSBP DMS.13", "FSBP DMS.6", "FSBP DMS.7", "FSBP DMS.8", "FSBP DMS.9" ], "aws_docdb_cluster": [ "FSBP DocumentDB.1", "FSBP DocumentDB.2", "FSBP DocumentDB.3", "FSBP DocumentDB.4", "FSBP DocumentDB.5", "FSBP DocumentDB.6" ], "aws_docdb_cluster_instance": [ "FSBP DocumentDB.1", "FSBP DocumentDB.2", "FSBP DocumentDB.3", "FSBP DocumentDB.4", "FSBP DocumentDB.5", "FSBP DocumentDB.6" ], "aws_dynamodb_table": [ "FSBP DynamoDB.1", "FSBP DynamoDB.2", "FSBP DynamoDB.3", "FSBP DynamoDB.6", "FSBP DynamoDB.7" ], "aws_ebs_default_kms_key": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_ebs_volume": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_ecr_repository": [ "FSBP ECR.1", "FSBP ECR.2", "FSBP ECR.3" ], "aws_ecr_repository_policy": [ "FSBP ECR.1", "FSBP ECR.2", "FSBP ECR.3" ], "aws_ecs_cluster": [ "FSBP ECS.1", "FSBP ECS.10", "FSBP ECS.12", "FSBP ECS.16", "FSBP ECS.18", "FSBP ECS.19", "FSBP ECS.2", "FSBP ECS.20", "FSBP ECS.21", "FSBP ECS.3", "FSBP ECS.4", "FSBP ECS.5", "FSBP ECS.8", "FSBP ECS.9" ], "aws_ecs_service": [ "FSBP ECS.1", "FSBP ECS.10", "FSBP ECS.12", "FSBP ECS.16", "FSBP ECS.18", "FSBP ECS.19", "FSBP ECS.2", "FSBP ECS.20", "FSBP ECS.21", "FSBP ECS.3", "FSBP ECS.4", "FSBP ECS.5", "FSBP ECS.8", "FSBP ECS.9" ], "aws_ecs_task_definition": [ "FSBP ECS.1", "FSBP ECS.10", "FSBP ECS.12", "FSBP ECS.16", "FSBP ECS.18", "FSBP ECS.19", "FSBP ECS.2", "FSBP ECS.20", "FSBP ECS.21", "FSBP ECS.3", "FSBP ECS.4", "FSBP ECS.5", "FSBP ECS.8", "FSBP ECS.9" ], "aws_efs_access_point": [ "FSBP EFS.1", "FSBP EFS.2", "FSBP EFS.3", "FSBP EFS.4", "FSBP EFS.6", "FSBP EFS.7", "FSBP EFS.8" ], "aws_efs_file_system": [ "FSBP EFS.1", "FSBP EFS.2", "FSBP EFS.3", "FSBP EFS.4", "FSBP EFS.6", "FSBP EFS.7", "FSBP EFS.8" ], "aws_efs_file_system_policy": [ "FSBP EFS.1", "FSBP EFS.2", "FSBP EFS.3", "FSBP EFS.4", "FSBP EFS.6", "FSBP EFS.7", "FSBP EFS.8" ], "aws_eip": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_eks_cluster": [ "FSBP EKS.1", "FSBP EKS.2", "FSBP EKS.3", "FSBP EKS.8", "FSBP EKS.9" ], "aws_eks_node_group": [ "FSBP EKS.1", "FSBP EKS.2", "FSBP EKS.3", "FSBP EKS.8", "FSBP EKS.9" ], "aws_elastic_beanstalk_environment": [ "FSBP ElasticBeanstalk.1", "FSBP ElasticBeanstalk.2", "FSBP ElasticBeanstalk.3" ], "aws_elasticache_cluster": [ "FSBP ElastiCache.1", "FSBP ElastiCache.2", "FSBP ElastiCache.3", "FSBP ElastiCache.4", "FSBP ElastiCache.5", "FSBP ElastiCache.6", "FSBP ElastiCache.7" ], "aws_elasticache_replication_group": [ "FSBP ElastiCache.1", "FSBP ElastiCache.2", "FSBP ElastiCache.3", "FSBP ElastiCache.4", "FSBP ElastiCache.5", "FSBP ElastiCache.6", "FSBP ElastiCache.7" ], "aws_elasticsearch_domain": [ "FSBP ES.1", "FSBP ES.2", "FSBP ES.3", "FSBP ES.4", "FSBP ES.5", "FSBP ES.6", "FSBP ES.7", "FSBP ES.8" ], "aws_elb": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_emr_cluster": [ "FSBP EMR.1", "FSBP EMR.2", "FSBP EMR.3", "FSBP EMR.4" ], "aws_flow_log": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_fsx_lustre_file_system": [ "FSBP FSx.1", "FSBP FSx.2", "FSBP FSx.3", "FSBP FSx.4", "FSBP FSx.5" ], "aws_fsx_ontap_file_system": [ "FSBP FSx.1", "FSBP FSx.2", "FSBP FSx.3", "FSBP FSx.4", "FSBP FSx.5" ], "aws_fsx_openzfs_file_system": [ "FSBP FSx.1", "FSBP FSx.2", "FSBP FSx.3", "FSBP FSx.4", "FSBP FSx.5" ], "aws_fsx_windows_file_system": [ "FSBP FSx.1", "FSBP FSx.2", "FSBP FSx.3", "FSBP FSx.4", "FSBP FSx.5" ], "aws_glue_catalog_database": [ "FSBP Glue.3", "FSBP Glue.4" ], "aws_glue_crawler": [ "FSBP Glue.3", "FSBP Glue.4" ], "aws_glue_job": [ "FSBP Glue.3", "FSBP Glue.4" ], "aws_guardduty_detector": [ "FSBP GuardDuty.1", "FSBP GuardDuty.10", "FSBP GuardDuty.11", "FSBP GuardDuty.12", "FSBP GuardDuty.13", "FSBP GuardDuty.5", "FSBP GuardDuty.6", "FSBP GuardDuty.7", "FSBP GuardDuty.8", "FSBP GuardDuty.9" ], "aws_iam_access_key": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_account_password_policy": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_group": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_policy": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_role": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_role_policy": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_role_policy_attachment": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_user": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_user_policy": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_iam_user_policy_attachment": [ "FSBP IAM.1", "FSBP IAM.2", "FSBP IAM.21", "FSBP IAM.3", "FSBP IAM.4", "FSBP IAM.5", "FSBP IAM.6", "FSBP IAM.7", "FSBP IAM.8" ], "aws_inspector2_enabler": [ "FSBP Inspector.1", "FSBP Inspector.2", "FSBP Inspector.3", "FSBP Inspector.4" ], "aws_instance": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_internet_gateway": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_kinesis_firehose_delivery_stream": [ "FSBP DataFirehose.1" ], "aws_kinesis_stream": [ "FSBP Kinesis.1", "FSBP Kinesis.3" ], "aws_kms_alias": [ "FSBP KMS.1", "FSBP KMS.2", "FSBP KMS.3", "FSBP KMS.5" ], "aws_kms_key": [ "FSBP KMS.1", "FSBP KMS.2", "FSBP KMS.3", "FSBP KMS.5" ], "aws_lambda_function": [ "FSBP Lambda.1", "FSBP Lambda.2", "FSBP Lambda.5" ], "aws_lambda_function_url": [ "FSBP Lambda.1", "FSBP Lambda.2", "FSBP Lambda.5" ], "aws_lambda_permission": [ "FSBP Lambda.1", "FSBP Lambda.2", "FSBP Lambda.5" ], "aws_launch_configuration": [ "FSBP AutoScaling.1", "FSBP AutoScaling.2", "FSBP AutoScaling.3", "FSBP AutoScaling.6", "FSBP AutoScaling.9", "FSBP Autoscaling.5" ], "aws_launch_template": [ "FSBP AutoScaling.1", "FSBP AutoScaling.2", "FSBP AutoScaling.3", "FSBP AutoScaling.6", "FSBP AutoScaling.9", "FSBP Autoscaling.5" ], "aws_lb": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_lb_listener": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_lb_target_group": [ "FSBP ELB.1", "FSBP ELB.10", "FSBP ELB.12", "FSBP ELB.13", "FSBP ELB.14", "FSBP ELB.17", "FSBP ELB.18", "FSBP ELB.2", "FSBP ELB.21", "FSBP ELB.22", "FSBP ELB.3", "FSBP ELB.4", "FSBP ELB.5", "FSBP ELB.6", "FSBP ELB.7", "FSBP ELB.8", "FSBP ELB.9" ], "aws_macie2_account": [ "FSBP Macie.1", "FSBP Macie.2" ], "aws_mq_broker": [ "FSBP MQ.2", "FSBP MQ.3" ], "aws_msk_cluster": [ "FSBP MSK.1", "FSBP MSK.3", "FSBP MSK.4", "FSBP MSK.5", "FSBP MSK.6" ], "aws_nat_gateway": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_neptune_cluster": [ "FSBP Neptune.1", "FSBP Neptune.2", "FSBP Neptune.3", "FSBP Neptune.4", "FSBP Neptune.5", "FSBP Neptune.6", "FSBP Neptune.7", "FSBP Neptune.8" ], "aws_neptune_cluster_instance": [ "FSBP Neptune.1", "FSBP Neptune.2", "FSBP Neptune.3", "FSBP Neptune.4", "FSBP Neptune.5", "FSBP Neptune.6", "FSBP Neptune.7", "FSBP Neptune.8" ], "aws_network_acl": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_networkfirewall_firewall": [ "FSBP NetworkFirewall.10", "FSBP NetworkFirewall.2", "FSBP NetworkFirewall.3", "FSBP NetworkFirewall.4", "FSBP NetworkFirewall.5", "FSBP NetworkFirewall.6", "FSBP NetworkFirewall.9" ], "aws_networkfirewall_firewall_policy": [ "FSBP NetworkFirewall.10", "FSBP NetworkFirewall.2", "FSBP NetworkFirewall.3", "FSBP NetworkFirewall.4", "FSBP NetworkFirewall.5", "FSBP NetworkFirewall.6", "FSBP NetworkFirewall.9" ], "aws_networkfirewall_rule_group": [ "FSBP NetworkFirewall.10", "FSBP NetworkFirewall.2", "FSBP NetworkFirewall.3", "FSBP NetworkFirewall.4", "FSBP NetworkFirewall.5", "FSBP NetworkFirewall.6", "FSBP NetworkFirewall.9" ], "aws_opensearch_domain": [ "FSBP Opensearch.1", "FSBP Opensearch.10", "FSBP Opensearch.2", "FSBP Opensearch.3", "FSBP Opensearch.4", "FSBP Opensearch.5", "FSBP Opensearch.6", "FSBP Opensearch.7", "FSBP Opensearch.8" ], "aws_rds_cluster": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_rds_cluster_instance": [ "FSBP RDS.1", "FSBP RDS.10", "FSBP RDS.11", "FSBP RDS.12", "FSBP RDS.13", "FSBP RDS.14", "FSBP RDS.15", "FSBP RDS.16", "FSBP RDS.17", "FSBP RDS.19", "FSBP RDS.2", "FSBP RDS.20", "FSBP RDS.21", "FSBP RDS.22", "FSBP RDS.23", "FSBP RDS.24", "FSBP RDS.25", "FSBP RDS.27", "FSBP RDS.3", "FSBP RDS.34", "FSBP RDS.35", "FSBP RDS.36", "FSBP RDS.37", "FSBP RDS.4", "FSBP RDS.40", "FSBP RDS.41", "FSBP RDS.42", "FSBP RDS.43", "FSBP RDS.44", "FSBP RDS.45", "FSBP RDS.46", "FSBP RDS.47", "FSBP RDS.48", "FSBP RDS.5", "FSBP RDS.50", "FSBP RDS.51", "FSBP RDS.6", "FSBP RDS.7", "FSBP RDS.8", "FSBP RDS.9" ], "aws_redshift_cluster": [ "FSBP Redshift.1", "FSBP Redshift.10", "FSBP Redshift.15", "FSBP Redshift.18", "FSBP Redshift.2", "FSBP Redshift.3", "FSBP Redshift.4", "FSBP Redshift.6", "FSBP Redshift.7", "FSBP Redshift.8" ], "aws_redshift_parameter_group": [ "FSBP Redshift.1", "FSBP Redshift.10", "FSBP Redshift.15", "FSBP Redshift.18", "FSBP Redshift.2", "FSBP Redshift.3", "FSBP Redshift.4", "FSBP Redshift.6", "FSBP Redshift.7", "FSBP Redshift.8" ], "aws_redshiftserverless_namespace": [ "FSBP RedshiftServerless.1", "FSBP RedshiftServerless.2", "FSBP RedshiftServerless.3", "FSBP RedshiftServerless.5", "FSBP RedshiftServerless.6" ], "aws_redshiftserverless_workgroup": [ "FSBP RedshiftServerless.1", "FSBP RedshiftServerless.2", "FSBP RedshiftServerless.3", "FSBP RedshiftServerless.5", "FSBP RedshiftServerless.6" ], "aws_route53_zone": [ "FSBP Route53.2" ], "aws_route_table": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_s3_bucket": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_acl": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_lifecycle_configuration": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_logging": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_policy": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_public_access_block": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_server_side_encryption_configuration": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_s3_bucket_versioning": [ "FSBP S3.1", "FSBP S3.12", "FSBP S3.13", "FSBP S3.19", "FSBP S3.2", "FSBP S3.24", "FSBP S3.25", "FSBP S3.3", "FSBP S3.5", "FSBP S3.6", "FSBP S3.8", "FSBP S3.9" ], "aws_sagemaker_endpoint_configuration": [ "FSBP SageMaker.1", "FSBP SageMaker.10", "FSBP SageMaker.11", "FSBP SageMaker.12", "FSBP SageMaker.13", "FSBP SageMaker.14", "FSBP SageMaker.15", "FSBP SageMaker.16", "FSBP SageMaker.17", "FSBP SageMaker.19", "FSBP SageMaker.2", "FSBP SageMaker.3", "FSBP SageMaker.4", "FSBP SageMaker.5", "FSBP SageMaker.8", "FSBP SageMaker.9" ], "aws_sagemaker_model": [ "FSBP SageMaker.1", "FSBP SageMaker.10", "FSBP SageMaker.11", "FSBP SageMaker.12", "FSBP SageMaker.13", "FSBP SageMaker.14", "FSBP SageMaker.15", "FSBP SageMaker.16", "FSBP SageMaker.17", "FSBP SageMaker.19", "FSBP SageMaker.2", "FSBP SageMaker.3", "FSBP SageMaker.4", "FSBP SageMaker.5", "FSBP SageMaker.8", "FSBP SageMaker.9" ], "aws_sagemaker_notebook_instance": [ "FSBP SageMaker.1", "FSBP SageMaker.10", "FSBP SageMaker.11", "FSBP SageMaker.12", "FSBP SageMaker.13", "FSBP SageMaker.14", "FSBP SageMaker.15", "FSBP SageMaker.16", "FSBP SageMaker.17", "FSBP SageMaker.19", "FSBP SageMaker.2", "FSBP SageMaker.3", "FSBP SageMaker.4", "FSBP SageMaker.5", "FSBP SageMaker.8", "FSBP SageMaker.9" ], "aws_secretsmanager_secret": [ "FSBP SecretsManager.1", "FSBP SecretsManager.2", "FSBP SecretsManager.3", "FSBP SecretsManager.4" ], "aws_secretsmanager_secret_rotation": [ "FSBP SecretsManager.1", "FSBP SecretsManager.2", "FSBP SecretsManager.3", "FSBP SecretsManager.4" ], "aws_security_group": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_security_group_rule": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_servicecatalog_portfolio": [ "FSBP ServiceCatalog.1" ], "aws_ses_configuration_set": [ "FSBP SES.3" ], "aws_ses_domain_identity": [ "FSBP SES.3" ], "aws_sfn_state_machine": [ "FSBP StepFunctions.1" ], "aws_sns_topic": [ "FSBP SNS.4" ], "aws_sns_topic_policy": [ "FSBP SNS.4" ], "aws_sqs_queue": [ "FSBP SQS.1", "FSBP SQS.3" ], "aws_ssm_association": [ "FSBP SSM.1", "FSBP SSM.2", "FSBP SSM.3", "FSBP SSM.4", "FSBP SSM.6", "FSBP SSM.7" ], "aws_ssm_document": [ "FSBP SSM.1", "FSBP SSM.2", "FSBP SSM.3", "FSBP SSM.4", "FSBP SSM.6", "FSBP SSM.7" ], "aws_ssm_parameter": [ "FSBP SSM.1", "FSBP SSM.2", "FSBP SSM.3", "FSBP SSM.4", "FSBP SSM.6", "FSBP SSM.7" ], "aws_subnet": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_transfer_server": [ "FSBP Transfer.2", "FSBP Transfer.3" ], "aws_transfer_user": [ "FSBP Transfer.2", "FSBP Transfer.3" ], "aws_vpc": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_vpc_endpoint": [ "FSBP EC2.1", "FSBP EC2.10", "FSBP EC2.15", "FSBP EC2.16", "FSBP EC2.17", "FSBP EC2.170", "FSBP EC2.171", "FSBP EC2.172", "FSBP EC2.173", "FSBP EC2.18", "FSBP EC2.180", "FSBP EC2.181", "FSBP EC2.182", "FSBP EC2.183", "FSBP EC2.19", "FSBP EC2.2", "FSBP EC2.20", "FSBP EC2.21", "FSBP EC2.23", "FSBP EC2.24", "FSBP EC2.25", "FSBP EC2.3", "FSBP EC2.4", "FSBP EC2.51", "FSBP EC2.55", "FSBP EC2.56", "FSBP EC2.57", "FSBP EC2.58", "FSBP EC2.6", "FSBP EC2.60", "FSBP EC2.7", "FSBP EC2.8", "FSBP EC2.9" ], "aws_waf_web_acl": [ "FSBP WAF.1", "FSBP WAF.10", "FSBP WAF.12", "FSBP WAF.2", "FSBP WAF.3", "FSBP WAF.4", "FSBP WAF.6", "FSBP WAF.7", "FSBP WAF.8" ], "aws_wafv2_web_acl": [ "FSBP WAF.1", "FSBP WAF.10", "FSBP WAF.12", "FSBP WAF.2", "FSBP WAF.3", "FSBP WAF.4", "FSBP WAF.6", "FSBP WAF.7", "FSBP WAF.8" ], "aws_wafv2_web_acl_association": [ "FSBP WAF.1", "FSBP WAF.10", "FSBP WAF.12", "FSBP WAF.2", "FSBP WAF.3", "FSBP WAF.4", "FSBP WAF.6", "FSBP WAF.7", "FSBP WAF.8" ], "aws_workspaces_directory": [ "FSBP WorkSpaces.1", "FSBP WorkSpaces.2" ], "aws_workspaces_workspace": [ "FSBP WorkSpaces.1", "FSBP WorkSpaces.2" ] } }