精选 Skills 索引(第 158 页)
按质量分排序的前 8,000 个 Skills,每个都有可收录的独立页面。需要全库 15.8 万条检索时,请使用 Skills 目录。
- cis-aws-compute-12.11
Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates
- cis-aws-compute-12.12
Ensure encryption in transit is enabled for Lambda environment variables
- cis-aws-compute-12.2
Ensure Cloudwatch Lambda insights is enabled
- cis-aws-compute-12.3
Ensure AWS Secrets manager is configured and being used by Lambda for databases
- cis-aws-compute-12.4
Ensure least privilege is used with Lambda function access
- cis-aws-compute-12.5
Ensure every Lambda function has its own IAM Role
- cis-aws-compute-12.6
Ensure Lambda functions are not exposed to everyone
- cis-aws-compute-12.7
Ensure Lambda functions are referencing active execution roles
- cis-aws-compute-12.8
Ensure that Code Signing is enabled for Lambda functions
- cis-aws-compute-12.9
Ensure there are no Lambda functions with admin privileges within your AWS account
- cis-aws-compute-16.1
Ensure communications between your applications and clients is encrypted
- cis-aws-compute-2.1.1
Ensure Consistent Naming Convention is used for Organizational AMI
- cis-aws-compute-2.1.2
Ensure Amazon Machine Images (AMIs) are encrypted
- cis-aws-compute-2.1.3
Ensure Only Approved Amazon Machine Images (AMIs) are Used
- cis-aws-compute-2.1.4
Ensure Images (AMI) are not older than 90 days
- cis-aws-compute-2.1.5
Ensure Images are not Publicly Available
- cis-aws-compute-2.2.2
Ensure Public Access to EBS Snapshots is Disabled
- cis-aws-compute-2.2.3
Ensure EBS volume snapshots are encrypted
- cis-aws-compute-2.4
Ensure an Organizational EC2 Tag Policy has been Created
- cis-aws-compute-2.5
Ensure no AWS EC2 Instances are Older than 180 days
- cis-aws-compute-2.6
Ensure detailed monitoring is enabled for production EC2 Instances
- cis-aws-compute-2.7
Ensure Default EC2 Security groups are not being used
- cis-aws-compute-2.8
Ensure the Use of IMDSv2 is Enforced on All Existing Instances
- cis-aws-compute-2.9
Ensure use of AWS Systems Manager to manage EC2 instances
- cis-aws-compute-3.1
Ensure Amazon ECS task definitions using 'host' network mode do not allow privileged or root user access to the host
- cis-aws-compute-3.12
Ensure Amazon ECS task definitions are tagged
- cis-aws-compute-3.13
Ensure only trusted images are used with Amazon ECS
- cis-aws-compute-3.14
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS task sets
- cis-aws-compute-3.2
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS services
- cis-aws-compute-3.3
Ensure Amazon ECS task definitions do not have 'pidMode' set to 'host'
- cis-aws-compute-3.4
Ensure Amazon ECS task definitions do not have 'privileged' set to 'true'
- cis-aws-compute-3.5
Ensure 'readonlyRootFilesystem' is set to 'true' for Amazon ECS task definitions
- cis-aws-compute-3.6
Ensure secrets are not passed as container environment variables in Amazon ECS task definitions
- cis-aws-compute-3.7
Ensure logging is configured for Amazon ECS task definitions
- cis-aws-compute-3.8
Ensure Amazon ECS Fargate services are using the latest Fargate platform version
- cis-aws-compute-3.9
Ensure monitoring is enabled for Amazon ECS clusters
- cis-aws-compute-5.1
Apply updates to any apps running in Lightsail
- cis-aws-compute-5.11
Ensure your Windows Server based lightsail instances are updated with the latest security patches
- cis-aws-compute-5.12
Change the auto-generated password for Windows based instances
- cis-aws-compute-5.2
Change default Administrator login names and passwords for applications