Compliance Dashboard

Export Compliance Report Based on latest scan
CIS AWS Benchmark

33%

5 / 15 checks passed
SOC 2 Readiness

60%

6 / 10 controls met
HIPAA Alignment

40%

4 / 10 safeguards met
CIS AWS Foundations Benchmark v1.5
1.1 — Maintain current contact details
Ensure account contact information is current
PASS
1.4 — Ensure no root account access key exists
Root account should not have access keys
FAIL
1.5 — Ensure MFA is enabled for root account
Root account must have MFA enabled
FAIL
1.10 — Ensure MFA enabled for all IAM users with console access
All IAM users with console password should have MFA
FAIL
1.12 — Ensure credentials unused for 45+ days are disabled
Remove or deactivate unused credentials
PASS
1.14 — Ensure access keys are rotated every 90 days
Regular key rotation reduces risk
FAIL
2.1.1 — Ensure S3 buckets are not publicly accessible
S3 buckets should block public access
FAIL
2.1.2 — Ensure S3 bucket policy denies HTTP requests
Enforce encryption in transit for S3
PASS
2.2.1 — Ensure EBS volume encryption is enabled
EBS volumes should be encrypted at rest
FAIL
2.3.1 — Ensure RDS instances are encrypted
RDS database storage should be encrypted
FAIL
3.1 — Ensure CloudTrail is enabled in all regions
CloudTrail provides audit logging
PASS
4.1 — Ensure no security groups allow ingress from 0.0.0.0/0 to port 22
SSH should not be open to the world
FAIL
4.2 — Ensure no security groups allow ingress from 0.0.0.0/0 to port 3389
RDP should not be open to the world
FAIL
4.3 — Ensure default security group restricts all traffic
Default SG should have no inbound/outbound rules
FAIL
5.1 — Ensure no Network ACLs allow unrestricted ingress
NACLs should restrict inbound traffic
PASS
SOC 2 Trust Service Criteria
CC6.1 — Logical and Physical Access Controls
Restrict access to information assets
FAIL
CC6.2 — User Authentication
Authenticate users before granting access
FAIL
CC6.3 — User Authorization
Authorize access based on business need
FAIL
CC6.6 — Encryption of Data in Transit
Protect data during transmission
PASS
CC6.7 — Encryption of Data at Rest
Protect stored data with encryption
FAIL
CC7.1 — Detect and Monitor Anomalies
Implement monitoring and detection controls
PASS
CC7.2 — Monitor System Components
Monitor infrastructure for security events
PASS
CC8.1 — Change Management
Control changes to infrastructure
PASS
A1.1 — Availability - Capacity Planning
Plan and manage capacity requirements
PASS
A1.2 — Availability - Backup and Recovery
Implement data backup procedures
PASS
HIPAA Technical Safeguards
164.312(a)(1) — Access Control - Unique User Identification
Assign unique identifier to each user
FAIL
164.312(a)(2)(i) — Access Control - Emergency Access
Establish procedures for emergency access
PASS
164.312(a)(2)(iv) — Access Control - Encryption and Decryption
Implement encryption mechanisms for ePHI
FAIL
164.312(b) — Audit Controls
Implement audit logging mechanisms
PASS
164.312(c)(1) — Integrity - ePHI Protection
Protect ePHI from improper modification
PASS
164.312(d) — Person or Entity Authentication
Verify identity before granting access
FAIL
164.312(e)(1) — Transmission Security
Protect ePHI during transmission
FAIL
164.312(e)(2)(ii) — Transmission Security - Encryption
Encrypt ePHI when transmitted over networks
FAIL
164.308(a)(5) — Security Awareness Training
Implement security awareness program
PASS
164.310(d)(1) — Device and Media Controls
Govern hardware and electronic media
FAIL