Skip to main content

AWS Audit

Audit coverage

Ten domains are analysed in every audit, across the regions you choose, from the configuration of your AWS account.

The ten domains

  • Inventory

    Map of your resources (EC2, RDS, Lambda, S3, DynamoDB…) and tagging quality.

  • Security

    Compliance with AWS Foundational Security Best Practices v1.0.0 and the CIS AWS Foundations Benchmark v3.0.0.

  • FinOps

    Cost optimisation: Cost Explorer, Reserved Instances, Savings Plans, Compute Optimizer.

  • Well-Architected

    The six pillars of the AWS Well-Architected Framework, with Trusted Advisor and AWS Config.

  • Resilience

    Backups, disaster recovery, multi-AZ deployments, RTO and RPO objectives.

  • Network

    VPCs, subnets, routing, peering, VPN, Transit Gateway, NACLs and security groups.

  • Web security

    CloudFront, ALB, API Gateway, WAF, Shield, HTTP headers, TLS and certificates.

  • IAM

    Users, roles, policies, MFA, access key age and excessive privileges.

  • Containers and serverless

    ECS, EKS, Lambda and App Runner: configuration, exposure and best practices.

  • Secrets and encryption

    KMS, Secrets Manager, key and secret rotation, encryption at rest.

Frameworks

  • AWS Foundational Security Best Practices v1.0.0 - the AWS Security Hub security standard.
  • CIS AWS Foundations Benchmark v3.0.0 - the Center for Internet Security hardening baseline.
  • AWS Well-Architected Framework - operational excellence, security, reliability, performance, cost and sustainability.

Optional DAST scan

On request, an OWASP ZAP scan tests the public endpoints of your account, discovered automatically (CloudFront, API Gateway, ALB). Two modes: baseline, passive, up to 20 targets; full, active, with attack payloads, up to 10 targets. A scan failure does not stop the audit.

Regions

20 commercial regions are offered (Europe, North America, Asia Pacific, South America). Opt-in regions, GovCloud and China are not covered.

What the audit does not do

The audit reads configuration: it modifies no resource, installs no agent, and does not replace a manual penetration test or a certification.

Ready to audit your AWS account?

Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.