- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
What Is the AWS CIS Benchmark?
Learn about AWS Benchmarks created by the Center for Internet Security (CIS), including the AWS Foundations Benchmark and Product-Level Benchmarks.
The Center for Internet Security (CIS) is a non-profit security research body that develops best practices for securing IT systems and data, including cloud security best practices. The CIS Benchmarks draw on the expertise of cybersecurity and IT professionals from government, business, and academia from around the world.
CIS created the AWS Foundations Benchmark, a set of security configuration best practices for Amazon Web Service (AWS). These best practices offer highly specific, detailed guidelines for implementing security controls in AWS services and validating their effectiveness.
In addition to the AWS Foundations Benchmark, the CIS provides security guidance for specific AWS services, in the form of Product-Level Benchmarks and Standalone Cloud Service Benchmarks.
The CIS Benchmark addresses multiple aspects of AWS infrastructure and managed services, including operating systems, cloud service configuration, and network devices. By following CIS controls, organizations can protect their AWS deployments from known cyber attack vectors, to fulfill their part of the shared responsibility model.
Download all the CIS AWS benchmarks at no cost on the CIS AWS page.
In this article:
- AWS CIS Benchmark Benefits
- Levels of CIS AWS Cloud Benchmarks
- AWS Foundation Benchmark Sections
- What Information Does Each Section Provide?
- Ensure Compliance in AWS with Aqua CSPM
Who Should be Using the CIS Benchmarks?
Any organization can use CIS benchmarks to achieve their security and compliance goals in AWS. The guidelines are created by representatives from businesses, governments, and academic institutions with global recognition, and are in line with standards and regulations such as GDPR in the EU, HIPAA in the US, and PCI DSS. In particular, government, healthcare, and financial sector organizations should consider using the CIS benchmark to meet their regulatory requirements.
AWS CIS Benchmark Benefits
The AWS CIS Benchmark provides the following security benefits:
- Industry accepted best practices—CIS benchmarks provide security professionals with clear set of standards and prescriptive guidance for specific assets in their AWS account. Prescribed best practices make it easy for security teams and AWS account holders to implement key security measures. It is referenced and recognized by PCI 3.1 and FedRAMP, and is included in the National Vulnerability Database (NVD) National Checklist Program (NCP).
- Easy integration into security ecosystem—the CIS benchmark can be integrated into products developed by over 20 security vendors. By leveraging these tools, organizations can integrate AWS security best practices into their existing security and audit processes.
- Consistent auditing—security and compliance teams can continuously assess the security of an AWS account. Best practices reduce the complexity of managing risk and make it clear how to audit the use of AWS for business critical and regulated systems, infrastructure, and applications.
Related content: Read our guide to AWS cloud security ›
Levels of CIS AWS Cloud Benchmarks
The CIS provides three levels of benchmarks that can help secure an AWS environment:
- CIS AWS Foundations Benchmark—provides an account-level starting point for securely setting up the AWS cloud. These resources include identity and access management, logging, monitoring, and networking.
- CIS Product-Level Benchmarks—provide guidance for configuring products and services, including areas such as compute, database, storage, and containers. These benchmarks help users choose the right cloud service for their needs and configure it for their environment. They add another layer of security to the cloud services used within cloud accounts.
- CIS Standalone Cloud-Service Benchmarks—these are specific to AWS services that require broader configuration guidance. In this case, the Product-Level Benchmark has a services section that references the standalone CIS Benchmark for the specific service.
AWS Foundation Benchmark Sections
The AWS Foundation Benchmark contains the following sections, each providing recommendations for a different aspect of an Amazon deployment.
Identity and Access Management
This section’s recommendations are for identity, accounts, authentication, and authorization. Most identity and access control concerns on AWS are managed using the IAM service. Most recommendations discuss IAM configurations like a password policy, using security groups and roles, and configuring devices for multi-factor authentication (MFA).
Storage
The recommendations in this section are enhancements and updates to AWS’s storage capabilities which can enhance security. The section mainly focuses on Amazon EC2, S3, and RDS. It covers encryption for data in transit and at rest, access control to resources, and handling sensitive data.
Logging
There are several logging, monitoring, and auditing features available in AWS with associated benchmark recommendations:
- AWS CloudTrail—used to track user activity and API usage.
- AWS Config—used to record and evaluate resource configurations.
- VPC Flow Logs—used to capture network traffic information in VPCs.
- AWS KMS—used to manage keys to encrypt and decrypt your data.
The Benchmark does not directly address some AWS logging features. The main log ingestion and query service, Amazon Cloudwatch Logs, is integrated with many AWS services. The Benchmark recommends users should integrate CloudTrail with CloudWatch Logs.
Monitoring
The recommendations for this section are concerned with monitoring specific API calls using the CloudTrail service paired with CloudWatch Logs filter metrics. Each recommendation sets a specific filter with an associated alarm.
Monitoring recommendations depend on two conditions, defined in the Logging section:
- Users must ensure CloudTrail is enabled in all regions
- Users must integrate CloudTrail with CloudWatch Logs
Networking
Even though networking has a central role in the security of any distributed system, this section’s recommendations are not highly restrictive. The recommendations limit traffic from a zero network (0.0.0.0/0) and, based on the principle of least-privilege, limit routing for VPC peering connections.
What Information Does Each Section Provide?
Each CIS Foundations Benchmark recommendation contains the following subsections:
- Profile applicability—determines if the recommendation relates to Level 1 (standard security profile) or Level 2 (higher security profile).
- Description—explains the recommendation and its importance.
- Audit—describes how to evaluate the recommendation’s status in its current condition.
- Remediation—step-by-step guide of successful implementation of recommendations.
- References—supporting documentation links.
- Additional information—more explanations that can assist with evaluating and remediating the issue.
- CIS controls—recommendation mapping to specific CIS controls.
Ensure Compliance in AWS with Aqua CSPM
Cloud Security Posture Management, or CSPM, is a relatively new cloud security category designed to address configuration and compliance risks in your cloud infrastructure. The concept of CSPM is to enable organizations to automatically discover, assess, and remediate security configuration issues and gaps across multiple cloud providers and accounts – utilizing frameworks such as the CIS Benchmarks as well as custom policies for assessment. This approach is intended to ensure that at any given moment you have a consistent, secure, and compliant cloud infrastructure.
Industry analyst firm Gartner defines the product category as, “CPSM offerings continuously manage cloud risk through the prevention, detection, response, and prediction of where excessive cloud infrastructure risk resides based on common frameworks, regulatory requirements and enterprise policies. The core of CSPM offerings proactively and reactively discover and assess risk/trust of cloud services configuration (such as network and storage configuration), and security settings (such as account privileges and encryption)
Aqua’s SaaS-based CSPM scans, validates, monitors, and remediates configuration issues in your public cloud accounts, including 50 checks for the CIS Amazon Web Services Foundations v1.2.0 Benchmark – covering AWS Identity and Access Management (IAM), AWS Config, AWS CloudTrail, AWS CloudWatch, AWS Simple Notification Service (SNS), AWS Simple Storage Service (S3) and AWS VPC (Default).
Once connected to the AWS environment through a dedicated IAM role,, the Aqua CSPM will query various read-only APIs in your account to obtain information about the configuration of your infrastructure services. This information will be processed and analyzed by Aqua’s security control plugins, with the output represented in a reporting dashboard, integrating findings with compound risk evaluation for remediation prioritization. Aqua’s CSPM assesses configurations against the CIS Benchmarks identify misconfigurations, and generate reports mapped to and certified by CIS Foundation Benchmarks.
Compliance reports are generated by taking existing security controls (represented as CSPM plugins) and presenting them through the lens of the specific compliance report being generated. In this way, you can access all compliance reports and details for all of your cloud accounts without having to pre-configure the reporting types.
Aqua’s CSPM also provides self-securing capabilities to help ensure your cloud accounts do not drift out of compliance by leveraging a policy-driven approach. Aligning with your multi-account strategy, Aqua CSPM integration for AWS Control Tower accelerates the onboarding process by employing automation and enables your organization to start from a secure foundation right out the gate.
The Aqua CSP performs these checks based on the CIS Foundation Benchmarks, along with hundreds of other configuration settings and compliance best practices checks, enabling consistent, unified multi-account security.
- 7 Dimensions of Cloud Security, Top 10 Risks and How to Defend
- Top 7 Cloud Security Challenges and How to Overcome Them
- Cloud Security Tools
- What Is Code to Cloud Security?
- Cloud Protection: Why, How & 6 Essential Technologies
- Cloud Security Frameworks
- 10 Cloud Security Standards You Must Know About
- Cloud Security Controls
- What Is Cloud Security Posture Management (CSPM)?
- What Are AI Workloads?
- What Is Cloud Computing Forensics?
- Cloud Computing Security Architecture: 5 Key Components
- What Is Enterprise Cloud Security?
- Why Is Security Important for Virtual Machines and Other Virtualized Resources?
- CSPM Tools: Going Beyond Cloud Vendor CSPM Solutions
- Top 5 Threats & Vulnerabilities in Cloud Computing
- How Secure Is Cloud Computing?
- Cloud Security Assessment: 8-Step Process and Checklist
- Cloud Visibility
- 3 Pillars of Cloud Governance, Challenges & Best Practices
- Building a Cloud Security Strategy in 2023
- 9 Key Components of a Cloud Security Policy
- DFIR (Digital Forensics and Incident Response)?
- Cloud Workloads: Types, Common Tasks, and Security Best Practices
- Public Cloud Security: The Basics & 7 Ways to Secure Your Cloud
- Private Cloud vs. Public Cloud: 7 Key Differences and How to Choose
- Why Runtime Security is Essential to Cloud Security
- Azure Cloud Security: An Introduction
- 8 Critical Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security: Build-In Security Features and 4 Critical Best Practices
- What Is Cloud Misconfiguration?
- Terraform Security
- What is Hybrid Cloud Security?
- Multi-Cloud Strategy: Why It’s Critical and 4 Challenges to Address
- Agentless vs. Agent Based Security & Monitoring: How to Choose?
- Cloud Infrastructure Security: Securing the 7 Key Components
- How Gartner Defines CSPM and 3 Tips for Success
- Cloud Security Scanner: What do Amazon, Azure and GCP Provide?
- Cloud Configuration Management
- Understanding Cloud Workload Protection (CWP)
- What Is a Cloud Workload Protection Platform (CWPP)?
- Cloud Workload Security: Risks, Controls, and 10 Best Practices
- Top 6 Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security: How It Works and 10 Security Best Practices
- Cloud Shared Responsibility Model: Examples & Best Practices
- What Is the AWS Shared Responsibility Model?
- AWS Cloud Security: The Complete Guide
- What Is Multi-Cloud Security?
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!