issues
search
turbot
/
steampipe-mod-terraform-aws-compliance
Run compliance and security controls to detect Terraform AWS resources deviating from security best practices prior to deployment using Powerpipe and Steampipe.
https://hub.powerpipe.io/mods/turbot/terraform_aws_compliance
Apache License 2.0
25
stars
3
forks
source link
Add additional TF controls
#72
Closed
rajlearner17
closed
1 year ago
rajlearner17
commented
1 year ago
[x] elb_application_network_gateway_lb_use_desync_mitigation_mode
[x] elb_application_lb_use_desync_mitigation_mode
[x] elb_lb_target_group_use_health_check
[x] elb_classic_lb_use_desync_mitigation_mode
[x] elb_application_lb_drop_invalid_header_fields
[x] elb_lb_use_secure_protocol_listener
[x] appsync_graphql_api_field_level_logs_enabled
[x] appsync_graphql_api_cloudwatch_logs_enabled
[x] appsync_api_cache_encryption_at_rest_enabled
[x] appsync_api_cache_encryption_in_transit_enabled
[x] codecommit_approval_rule_template_number_of_approval_2
[x] comprehend_entity_recognizer_model_encrypted_with_kms_cmk
[x] comprehend_entity_recognizer_volume_encrypted_with_kms_cmk
[x] connectinstance_kinesis_video_stream_storage_config_encrypted_with_kms_cmk
[x] connectinstance_s3_storage_config_encrypted_with_kms_cmk
[x] dlm_lifecycle_policy_events_cross_region_encryption_enabled
[x] dlm_lifecycle_policy_events_cross_encrypted_with_kms_cmk
[x] dlm_schedule_cross_region_encryption_enabled
[x] dlm_schedule_cross_region_encrypted_with_kms_cmk
[x] eks_cluster_control_plane_logging_enabled
[x] eks_cluster_run_on_supported_kubernetes_version
[x] elb_application_classic_lb_logging_enabled > elb_application_classic_network_lb_logging_enabled (updated)
[x] emr_cluster_security_configuration_ebs_encryption_enabled
[x] emr_cluster_security_configuration_encryption_in_transit_enabled
[x] emr_cluster_security_configuration_local_disk_encryption_enabled
[x] emr_cluster_security_configuration_encryption_uses_sse_kms
[x] elasticbeanstalk_environment_use_enhanced_health_checks
[x] elasticbeanstalk_environment_use_managed_updates
[x] es_domain_use_default_security_group
[x] opensearch_domain_use_default_security_group
[x] es_domain_enforce_https
[x] opensearch_domain_enforce_https
[x] es_domain_encrypted_with_kms_cmk
[x] opensearch_domain_encrpted_with_kms_cmk
[x] fsx_ontap_file_system_encrypted_with_kms_cmk
[x] fsx_openzfs_file_system_with_kms_cmk
[x] fsx_windows_file_system_encrypted_with_kms_cmk
[x] glue_crawler_security_configuration_enabled
[x] glue_dev_endpoint_security_configuration_enabled
[x] glue_job_security_configuration_enabled
[x] kendra_index_server_side_encryption_uses_kms_cmk
[x] keyspaces_table_encrypted_with_kms_cmk
[x] elb_application_network_wateway_lb_cross_zone_load_balancing_enabled
[x] lambda_function_code_signing_configured
[x] lambda_function_variables_no_sensitive_data
[x] lambda_function_environment_encryption_enabled
[x] lambda_function_url_auth_type_configured
[x] fsx_lustre_file_system_encrypted_with_kms_cmk
[x] mq_broker_audit_logging_enabled
[x] mq_broker_encrypted_with_kms_cmk
[x] mq_broker_general_logging_enabled
[x] mq_broker_automatic_minor_upgrade_enabled
[x] mq_broker_publicly_accessible
[x] mq_broker_currect_broker_version
[x] msk_cluster_encrypted_with_kms_cmk
[x] msk_cluster_encryption_in_transit_enabled
[x] msk_cluster_logging_enabled
[x] msk_cluster_nodes_publicly_accessible
[x] mwaa_environment_scheduler_logs_enabled
[x] mwaa_environment_webserver_logs_enabled
[x] mwaa_environment_worker_logs_enabled
[x] qldb_ledger_deletion_protection_enabled
[x] qldb_ledger_permission_mode_set_to_standard
[x] eventbridge_scheduler_schedule_encrypted_with_kms_cmk