Security Compliance Audit

AWS resource security and compliance monitoring

Critical Issues
3

Require immediate attention

High Risk
2

Security vulnerabilities

Warnings
4

Optimization opportunities

Compliance Score
72%

Based on AWS best practices

prod-data-bucket

S3 Bucketus-east-1

CRITICAL

Public read access enabled

S3 bucket allows public read access which may expose sensitive data

Last checked: 2024-01-15

sg-web-servers

Security Groupus-east-1

HIGH

Inbound rule allows 0.0.0.0/0

Security group allows inbound traffic from any IP address on port 22

Last checked: 2024-01-15

prod-mysql-db

RDS Databaseus-west-2

HIGH

Outbound rule allows 0.0.0.0/0

Database security group allows outbound connections to any destination

Last checked: 2024-01-15

admin-role

IAM Roleglobal

CRITICAL

Admin permissions granted

IAM role has full administrative access (*:*) which violates least privilege

Last checked: 2024-01-15

service-account

IAM Userglobal

CRITICAL

Admin permissions granted

Service account has administrative privileges instead of specific permissions

Last checked: 2024-01-15