{"repo":"nozaq/terraform-aws-secure-baseline","free":true,"listed":false,"github":"https://github.com/nozaq/terraform-aws-secure-baseline","clone":"git clone https://github.com/nozaq/terraform-aws-secure-baseline.git","description":"Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.","language":"HCL","stars":1199,"topics":["terraform","aws","security","security-hardening","terraform-modules","hardening","cis-benchmark","aws-auditing","security-tools","devops"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"terraform-aws-secure-baseline Terraform Module Registry A terraform module to set up your AWS account with the reasonably secure configuration baseline. Most configurations are based on [CIS Amazon Web Services Foundations v1.4.0] and [AWS Foundational Security Best Practices v1.0.0]. See Benchmark Compliance to check which items in various benchmarks are covered. Features Identity and Access Management - Set up IAM Password Policy. - Create an IAM role for contacting AWS support for incident handling. - Enable AWS Config rules to audit root account status. - Enable IAM Access Analyzer in each region. - Enable S3 account-level Public Access Block configuration. Logging & Monitoring - Enable CloudTrail in all regions and deliver events to CloudWatch Logs. - Object-level logging for all S3 buckets is enabled by default. - CloudTrail Insights event logging is enabled by default. - CloudTrail logs are encrypted using AWS Key Management Service. - All logs are stored in the S3 bucket with access logging enabled. - Logs are automatically archived into Amazon Glacier after the given period(defaults to 90 days). - Set up CloudWatch alarms to notify you when critical changes happen in your AWS account. - Enable AWS Config in each regions to automatically take configuration snapshots. - Enable SecurityHub and subscribe available standards. - Enable GuardDuty in each regions. Networking & Computing - Remove all rules associated with default route tables, default network ACLs and default","default_branch":null,"files":null,"tree":[],"storefront":"/r/nozaq","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nozaq/terraform-aws-secure-baseline/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}