Skip to content

Instantly share code, notes, and snippets.

@MasahiroKawahara
Last active June 10, 2020 04:00
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save MasahiroKawahara/9cb7e2bd2f91830b212ec4771924df24 to your computer and use it in GitHub Desktop.
Save MasahiroKawahara/9cb7e2bd2f91830b212ec4771924df24 to your computer and use it in GitHub Desktop.
適合パックテンプレートで使われている Configマネージドルール一覧
Rule Identifier CT Dy S3 IAM CIS PCI NIST
ACCESS_KEYS_ROTATED
ACM_CERTIFICATE_EXPIRATION_CHECK
CLOUDWATCH_LOG_GROUP_ENCRYPTED
CLOUD_TRAIL_CLOUD_WATCH_LOGS_ENABLED
CLOUD_TRAIL_ENABLED
CLOUD_TRAIL_ENCRYPTION_ENABLED
CLOUD_TRAIL_LOG_FILE_VALIDATION_ENABLED
CMK_BACKING_KEY_ROTATION_ENABLED
DMS_REPLICATION_NOT_PUBLIC
DYNAMODB_AUTOSCALING_ENABLED
DYNAMODB_TABLE_ENCRYPTION_ENABLED
DYNAMODB_THROUGHPUT_LIMIT_CHECK
EBS_OPTIMIZED_INSTANCE
EBS_SNAPSHOT_PUBLIC_RESTORABLE_CHECK
EC2_INSTANCE_MANAGED_BY_SSM
EC2_INSTANCE_NO_PUBLIC_IP
EC2_MANAGEDINSTANCE_ASSOCIATION_COMPLIANCE_STATUS_CHECK
EC2_SECURITY_GROUP_ATTACHED_TO_ENI
EC2_VOLUME_INUSE_CHECK
EFS_ENCRYPTED_CHECK
ELASTICSEARCH_ENCRYPTED_AT_REST
ELASTICSEARCH_IN_VPC_ONLY
ELB_ACM_CERTIFICATE_REQUIRED
EMR_MASTER_NO_PUBLIC_IP
ENCRYPTED_VOLUMES
IAM_GROUP_HAS_USERS_CHECK
IAM_PASSWORD_POLICY
IAM_POLICY_BLACKLISTED_CHECK
IAM_POLICY_IN_USE
IAM_POLICY_NO_STATEMENTS_WITH_ADMIN_ACCESS
IAM_ROLE_MANAGED_POLICY_CHECK
IAM_ROOT_ACCESS_KEY_CHECK
IAM_USER_GROUP_MEMBERSHIP_CHECK
IAM_USER_MFA_ENABLED
IAM_USER_NO_POLICIES_CHECK
IAM_USER_UNUSED_CREDENTIALS_CHECK
INCOMING_SSH_DISABLED
INSTANCES_IN_VPC
INTERNET_GATEWAY_AUTHORIZED_VPC_ONLY
LAMBDA_FUNCTION_PUBLIC_ACCESS_PROHIBITED
LAMBDA_INSIDE_VPC
MFA_ENABLED_FOR_IAM_CONSOLE_ACCESS
MULTI_REGION_CLOUD_TRAIL_ENABLED
RDS_INSTANCE_PUBLIC_ACCESS_CHECK
RDS_SNAPSHOTS_PUBLIC_PROHIBITED
RDS_STORAGE_ENCRYPTED
REDSHIFT_CLUSTER_PUBLIC_ACCESS_CHECK
RESTRICTED_INCOMING_TRAFFIC
ROOT_ACCOUNT_HARDWARE_MFA_ENABLED
ROOT_ACCOUNT_MFA_ENABLED
S3_ACCOUNT_LEVEL_PUBLIC_ACCESS_BLOCKS
S3_BUCKET_BLACKLISTED_ACTIONS_PROHIBITED
S3_BUCKET_LOGGING_ENABLED
S3_BUCKET_POLICY_GRANTEE_CHECK
S3_BUCKET_POLICY_NOT_MORE_PERMISSIVE
S3_BUCKET_PUBLIC_READ_PROHIBITED
S3_BUCKET_PUBLIC_WRITE_PROHIBITED
S3_BUCKET_REPLICATION_ENABLED
S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED
S3_BUCKET_SSL_REQUESTS_ONLY
S3_BUCKET_VERSIONING_ENABLED
SAGEMAKER_NOTEBOOK_INSTANCE_KMS_KEY_CONFIGURED
SAGEMAKER_NOTEBOOK_NO_DIRECT_INTERNET_ACCESS
SECRETSMANAGER_ROTATION_ENABLED_CHECK
VPC_DEFAULT_SECURITY_GROUP_CLOSED
VPC_FLOW_LOGS_ENABLED
VPC_SG_OPEN_ONLY_TO_AUTHORIZED_PORTS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment