精选 Skills 索引(第 162 页)
按质量分排序的前 8,000 个 Skills,每个都有可收录的独立页面。需要全库 15.8 万条检索时,请使用 Skills 目录。
- cis-aws-foundations-3.1.3
Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- cis-aws-foundations-3.1.4
Ensure that S3 is configured with 'Block Public Access' enabled
- cis-aws-foundations-3.2.1
Ensure that encryption-at-rest is enabled for RDS instances
- cis-aws-foundations-3.2.2
Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- cis-aws-foundations-3.2.3
Ensure that RDS instances are not publicly accessible
- cis-aws-foundations-3.2.4
Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- cis-aws-foundations-3.3.1
Ensure that encryption is enabled for EFS file systems
- cis-aws-foundations-4.1
Ensure CloudTrail is enabled in all regions
- cis-aws-foundations-4.10
Ensure all AWS-managed web front-end services have access logging enabled
- cis-aws-foundations-4.2
Ensure CloudTrail log file validation is enabled
- cis-aws-foundations-4.3
Ensure AWS Config is enabled in all regions
- cis-aws-foundations-4.4
Ensure that server access logging is enabled on the CloudTrail S3 bucket
- cis-aws-foundations-4.5
Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- cis-aws-foundations-4.6
Ensure rotation for customer-created symmetric CMKs is enabled
- cis-aws-foundations-4.7
Ensure VPC flow logging is enabled in all VPCs
- cis-aws-foundations-4.8
Ensure that object-level logging for write events is enabled for S3 buckets
- cis-aws-foundations-4.9
Ensure that object-level logging for read events is enabled for S3 buckets
- cis-aws-foundations-5.1
Ensure unauthorized API calls are monitored
- cis-aws-foundations-5.10
Ensure security group changes are monitored
- cis-aws-foundations-5.11
Ensure Network Access Control List (NACL) changes are monitored
- cis-aws-foundations-5.12
Ensure changes to network gateways are monitored
- cis-aws-foundations-5.13
Ensure route table changes are monitored
- cis-aws-foundations-5.15
Ensure AWS Organizations changes are monitored
- cis-aws-foundations-5.2
Ensure management console sign-in without MFA is monitored
- cis-aws-foundations-5.3
Ensure usage of the 'root' account is monitored
- cis-aws-foundations-5.5
Ensure CloudTrail configuration changes are monitored
- cis-aws-foundations-5.6
Ensure AWS Management Console authentication failures are monitored
- cis-aws-foundations-5.7
Ensure disabling or scheduled deletion of customer created CMKs is monitored
- cis-aws-foundations-5.8
Ensure S3 bucket policy changes are monitored
- cis-aws-foundations-5.9
Ensure AWS Config configuration changes are monitored
- cis-aws-foundations-6.1.1
Ensure EBS volume encryption is enabled in all regions
- cis-aws-foundations-6.1.2
Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- cis-aws-foundations-6.2
Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- cis-aws-foundations-6.3
Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- cis-aws-foundations-6.4
Ensure no security groups allow ingress from ::/0 to remote server administration ports
- cis-aws-foundations-6.5
Ensure the default security group of every VPC restricts all traffic
- cis-aws-foundations-6.6
Ensure routing tables for VPC peering are least access
- cis-aws-foundations-6.7
Ensure that the EC2 Metadata Service only allows IMDSv2
- cis-aws-foundations-6.8
Ensure VPC Endpoints are used for access to AWS Services
- cis-aws-storage-1.3
Ensure to create backup template and name