Your Amazon CloudWatch alarms have at least one action configured for the ALARM state. When a monitored…
Your CloudWatch alarms have actions enabled (ActionsEnabled: true). When alarm actions are enabled…
You have a CloudWatch alarm configured to detect changes to Network Access Control Lists (NACLs) in your…
You have a CloudWatch alarm configured to detect changes to network gateways in your AWS account. It…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to monitor VPC route table…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to Virtual…
Amazon CloudWatch cross-account sharing is disabled. Cross-account sharing is enabled when the…
Your CloudWatch Log Groups are encrypted using a customer-managed AWS KMS key. By default, CloudWatch Logs…
This check scans your CloudWatch Log Groups for embedded credentials and sensitive patterns such as API…
No CloudWatch Log Groups have resource policies that allow access from any entity (Principal: ). Resource…
Amazon CloudWatch Log Groups have a retention policy that meets or exceeds a configured minimum number of…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to AWS Config…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to CloudTrail…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect failed AWS Management…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to AWS…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect when customer-managed…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to S3 bucket…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect IAM policy changes. It…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect when the root account…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect changes to security…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect console logins that…
Your AWS account has a CloudWatch Logs metric filter and alarm configured to detect unauthorized API…