Templates
Operations
AWS Security Checklist
🔒

AWS Security Checklist

1
Identify the AWS resources that need to be secured
2
Check existing security groups and assess their configurations
3
Analyze IAM policies and check for insecure permissions
4
Evaluate the encryption of data at rest and in transit
5
Enable and review AWS CloudTrail logs
6
Approval: CloudTrail Logs Review
7
Activate Multi-Factor Authentication on all accounts
8
Regularly rotate and securely store AWS access keys
9
Perform a security assessment of AWS S3 buckets
10
Approval: AWS S3 Buckets Security Assessment
11
Review VPC flow logs for abnormal traffic patterns
12
Evaluate the need for a web application firewall
13
Ensure proper security measures for RDS and DynamoDB databases
14
Review the possibility of using AWS Shield for DDoS protection
15
Ensure all APIs are secured as per AWS best practices
16
Approval: APIs Security Review
17
Implement stringent password policies for IAM users
18
Ensure use of secure and latest AMIs
19
Check for unused EC2 and RDS instances
20
Approval: Final Security Checklist Review