Cloud
Guardrails

AWS Security Starter Pack

Cloud Guardrails

If you're interested in contributing guidance, please start with these instructions.

Filters
Filters
Categories
Clear
Maturity Level
Clear
Functions
Clear
Cloud Provider
Clear
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Cloudfront OAI usage
Low
AWS
Houston Hopkins
Summary
Utilize Cloudfront OAI with origin type of s3/ Allow ONLY action s3:GetObject to the specific OAI in the bucket policy.
Applicable to
Anyone using Cloudfront with S3 as an origin.
When to use/avoid
Uniform bucket-level access
Low
AWS
Travis McPeak
Summary
Individual object permissions can create surprising ACL issues and should be avoided in favor of explicit policies on buckets.
Applicable to
Always
When to use/avoid
Approval for sensitive network access
Low
AWS, GCP, Azure
Travis McPeak
Summary
Require approval for adding new access to trusted/privileged resources.
Applicable to
As early as possible
When to use/avoid
Enable MFA on the Root Account
Low
AWS
Mark Andersen
Summary
Enable multi-factor authentication on the root account with alerting.
Applicable to
All AWS accounts
When to use/avoid
Public access block
Low
AWS, GCP
Travis McPeak
Summary
Prevent public bucket exposure by enabling public access block.
Applicable to
Always applies
When to use/avoid
Cloud Guardrails

If you're interested in contributing guidance, please start with these instructions.

Filters
Filters
Categories
Clear
Maturity Level
Clear
Functions
Clear
Cloud Provider
Clear
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Name
Cloudfront OAI usage
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Houston Hopkins
Uniform bucket-level access
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Travis McPeak
Approval for sensitive network access
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Travis McPeak
Enable MFA on the Root Account
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Mark Andersen
Public access block
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Travis McPeak
Process
Data
Architecture
Configuration
Change Management
Compliance
Identity
Cost Management
Reliability
Security
Standards