Skip to content

Commit 05388bb

Browse files
committed
cleaning
1 parent f6eeabf commit 05388bb

File tree

2,184 files changed

+40631
-53143
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

2,184 files changed

+40631
-53143
lines changed
Lines changed: 9 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,12 @@
11
ID: aws_acsc_essential_eight_ml_1
2-
Title: "ACSC Essential Eight Maturity Level 1"
3-
Description: "The availability category refers to the accessibility of information
4-
used by the entity’s systems, as well as the products or services provided to its
5-
customers."
6-
SectionCode: "ml_1"
2+
Title: ACSC Essential Eight Maturity Level 1
3+
Description: The availability category refers to the accessibility of information used by the entity’s systems, as well as the products or services provided to its customers.
4+
SectionCode: ml_1
75
Children:
8-
- aws_acsc_essential_eight_ml_1_2
9-
- aws_acsc_essential_eight_ml_1_5
10-
- aws_acsc_essential_eight_ml_1_6
11-
- aws_acsc_essential_eight_ml_1_7
12-
- aws_acsc_essential_eight_ml_1_8
13-
Tags: {}
14-
Enabled: false
15-
AutoAssign: false
6+
- aws_acsc_essential_eight_ml_1_2
7+
- aws_acsc_essential_eight_ml_1_5
8+
- aws_acsc_essential_eight_ml_1_6
9+
- aws_acsc_essential_eight_ml_1_7
10+
- aws_acsc_essential_eight_ml_1_8
1611
Controls: []
17-
TracksDriftEvents: false
12+
Tags: {}
Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,8 @@
11
ID: aws_acsc_essential_eight_ml_1_2
2-
Title: "ACSC-EE-ML1-2: Patch applications ML1"
3-
Description: "A vulnerability scanner with an up-to-date vulnerability database is
4-
used for vulnerability scanning activities."
2+
Title: 'ACSC-EE-ML1-2: Patch applications ML1'
3+
Description: A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
54
SectionCode: "2"
65
Children:
7-
- aws_acsc_essential_eight_ml_1_2_5
8-
Tags: {}
9-
Enabled: false
10-
AutoAssign: false
6+
- aws_acsc_essential_eight_ml_1_2_5
117
Controls: []
12-
TracksDriftEvents: false
8+
Tags: {}
Lines changed: 12 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,16 @@
11
ID: aws_acsc_essential_eight_ml_1_2_5
2-
Title: "ACSC-EE-ML1-2.5: Patch applications ML1"
3-
Description: "Patches, updates or vendor mitigations for security vulnerabilities
4-
in internet-facing services are applied within two weeks of release, or within 48
5-
hours if an exploit exists."
2+
Title: 'ACSC-EE-ML1-2.5: Patch applications ML1'
3+
Description: Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
64
SectionCode: "5"
75
Children: []
8-
Tags: {}
9-
Enabled: false
10-
AutoAssign: false
116
Controls:
12-
- aws_ecs_service_fargate_using_latest_platform_version
13-
- aws_eks_cluster_with_latest_kubernetes_version
14-
- aws_elastic_beanstalk_environment_managed_updates_enabled
15-
- aws_elasticache_cluster_auto_minor_version_upgrade_enabled
16-
- aws_lambda_function_use_latest_runtime
17-
- aws_opensearch_domain_updated_with_latest_service_software_version
18-
- aws_rds_db_instance_automatic_minor_version_upgrade_enabled
19-
- aws_redshift_cluster_maintenance_settings_check
20-
- aws_ssm_managed_instance_compliance_patch_compliant
21-
TracksDriftEvents: false
7+
- aws_ecs_service_fargate_using_latest_platform_version
8+
- aws_eks_cluster_with_latest_kubernetes_version
9+
- aws_elastic_beanstalk_environment_managed_updates_enabled
10+
- aws_elasticache_cluster_auto_minor_version_upgrade_enabled
11+
- aws_lambda_function_use_latest_runtime
12+
- aws_opensearch_domain_updated_with_latest_service_software_version
13+
- aws_rds_db_instance_automatic_minor_version_upgrade_enabled
14+
- aws_redshift_cluster_maintenance_settings_check
15+
- aws_ssm_managed_instance_compliance_patch_compliant
16+
Tags: {}
Lines changed: 7 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,11 @@
11
ID: aws_acsc_essential_eight_ml_1_5
2-
Title: "ACSC-EE-ML1-5: Restrict administrative privileges ML1"
3-
Description: "The restriction of administrative privileges is the practice of limiting
4-
the number of privileged accounts and the extent of their access to systems and
5-
data."
2+
Title: 'ACSC-EE-ML1-5: Restrict administrative privileges ML1'
3+
Description: The restriction of administrative privileges is the practice of limiting the number of privileged accounts and the extent of their access to systems and data.
64
SectionCode: "5"
75
Children:
8-
- aws_acsc_essential_eight_ml_1_5_2
9-
- aws_acsc_essential_eight_ml_1_5_3
10-
- aws_acsc_essential_eight_ml_1_5_4
11-
- aws_acsc_essential_eight_ml_1_5_5
12-
Tags: {}
13-
Enabled: false
14-
AutoAssign: false
6+
- aws_acsc_essential_eight_ml_1_5_2
7+
- aws_acsc_essential_eight_ml_1_5_3
8+
- aws_acsc_essential_eight_ml_1_5_4
9+
- aws_acsc_essential_eight_ml_1_5_5
1510
Controls: []
16-
TracksDriftEvents: false
11+
Tags: {}
Lines changed: 12 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,16 @@
11
ID: aws_acsc_essential_eight_ml_1_5_2
2-
Title: "ACSC-EE-ML1-5.2: Restrict administrative privileges ML1"
3-
Description: "Privileged accounts (excluding privileged service accounts) are prevented
4-
from accessing the internet, email and web services."
2+
Title: 'ACSC-EE-ML1-5.2: Restrict administrative privileges ML1'
3+
Description: Privileged accounts (excluding privileged service accounts) are prevented from accessing the internet, email and web services.
54
SectionCode: "2"
65
Children: []
7-
Tags: {}
8-
Enabled: false
9-
AutoAssign: false
106
Controls:
11-
- aws_codebuild_project_environment_privileged_mode_disabled
12-
- aws_ecs_task_definition_container_non_privileged
13-
- aws_ecs_task_definition_no_root_user
14-
- aws_eventbridge_custom_bus_resource_based_policy_attached
15-
- aws_iam_policy_custom_no_blocked_kms_actions
16-
- aws_iam_policy_inline_no_blocked_kms_actions
17-
- aws_iam_policy_no_star_star
18-
- aws_iam_root_user_no_access_keys
19-
- aws_sagemaker_notebook_instance_root_access_disabled
20-
TracksDriftEvents: false
7+
- aws_codebuild_project_environment_privileged_mode_disabled
8+
- aws_ecs_task_definition_container_non_privileged
9+
- aws_ecs_task_definition_no_root_user
10+
- aws_eventbridge_custom_bus_resource_based_policy_attached
11+
- aws_iam_policy_custom_no_blocked_kms_actions
12+
- aws_iam_policy_inline_no_blocked_kms_actions
13+
- aws_iam_policy_no_star_star
14+
- aws_iam_root_user_no_access_keys
15+
- aws_sagemaker_notebook_instance_root_access_disabled
16+
Tags: {}
Lines changed: 11 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,15 @@
11
ID: aws_acsc_essential_eight_ml_1_5_3
2-
Title: "ACSC-EE-ML1-5.3: Restrict administrative privileges ML1"
3-
Description: "Privileged users use separate privileged and unprivileged operating
4-
environments."
2+
Title: 'ACSC-EE-ML1-5.3: Restrict administrative privileges ML1'
3+
Description: Privileged users use separate privileged and unprivileged operating environments.
54
SectionCode: "3"
65
Children: []
7-
Tags: {}
8-
Enabled: false
9-
AutoAssign: false
106
Controls:
11-
- aws_codebuild_project_environment_privileged_mode_disabled
12-
- aws_codebuild_project_source_repo_oauth_configured
13-
- aws_ecs_task_definition_container_non_privileged
14-
- aws_ecs_task_definition_no_root_user
15-
- aws_eventbridge_custom_bus_resource_based_policy_attached
16-
- aws_iam_root_user_no_access_keys
17-
- aws_sagemaker_notebook_instance_root_access_disabled
18-
- aws_ssm_managed_instance_compliance_association_compliant
19-
TracksDriftEvents: false
7+
- aws_codebuild_project_environment_privileged_mode_disabled
8+
- aws_codebuild_project_source_repo_oauth_configured
9+
- aws_ecs_task_definition_container_non_privileged
10+
- aws_ecs_task_definition_no_root_user
11+
- aws_eventbridge_custom_bus_resource_based_policy_attached
12+
- aws_iam_root_user_no_access_keys
13+
- aws_sagemaker_notebook_instance_root_access_disabled
14+
- aws_ssm_managed_instance_compliance_association_compliant
15+
Tags: {}
Lines changed: 8 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,12 @@
11
ID: aws_acsc_essential_eight_ml_1_5_4
2-
Title: "ACSC-EE-ML1-5.4: Restrict administrative privileges ML1"
3-
Description: "Unprivileged accounts cannot logon to privileged operating environments."
2+
Title: 'ACSC-EE-ML1-5.4: Restrict administrative privileges ML1'
3+
Description: Unprivileged accounts cannot logon to privileged operating environments.
44
SectionCode: "4"
55
Children: []
6-
Tags: {}
7-
Enabled: false
8-
AutoAssign: false
96
Controls:
10-
- aws_codebuild_project_source_repo_oauth_configured
11-
- aws_ec2_instance_iam_profile_attached
12-
- aws_eventbridge_custom_bus_resource_based_policy_attached
13-
- aws_ssm_managed_instance_compliance_association_compliant
14-
- aws_vpc_security_group_restrict_ingress_ssh_all
15-
TracksDriftEvents: false
7+
- aws_codebuild_project_source_repo_oauth_configured
8+
- aws_ec2_instance_iam_profile_attached
9+
- aws_eventbridge_custom_bus_resource_based_policy_attached
10+
- aws_ssm_managed_instance_compliance_association_compliant
11+
- aws_vpc_security_group_restrict_ingress_ssh_all
12+
Tags: {}
Lines changed: 13 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,17 @@
11
ID: aws_acsc_essential_eight_ml_1_5_5
2-
Title: "ACSC-EE-ML1-5.5: Restrict administrative privileges ML1"
3-
Description: "Privileged accounts (excluding local administrator accounts) cannot
4-
logon to unprivileged operating environments."
2+
Title: 'ACSC-EE-ML1-5.5: Restrict administrative privileges ML1'
3+
Description: Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
54
SectionCode: "5"
65
Children: []
7-
Tags: {}
8-
Enabled: false
9-
AutoAssign: false
106
Controls:
11-
- aws_codebuild_project_environment_privileged_mode_disabled
12-
- aws_codebuild_project_source_repo_oauth_configured
13-
- aws_ecs_task_definition_container_non_privileged
14-
- aws_ecs_task_definition_no_root_user
15-
- aws_iam_policy_custom_no_blocked_kms_actions
16-
- aws_iam_policy_inline_no_blocked_kms_actions
17-
- aws_iam_policy_no_star_star
18-
- aws_iam_root_user_no_access_keys
19-
- aws_sagemaker_notebook_instance_root_access_disabled
20-
- aws_vpc_security_group_restrict_ingress_ssh_all
21-
TracksDriftEvents: false
7+
- aws_codebuild_project_environment_privileged_mode_disabled
8+
- aws_codebuild_project_source_repo_oauth_configured
9+
- aws_ecs_task_definition_container_non_privileged
10+
- aws_ecs_task_definition_no_root_user
11+
- aws_iam_policy_custom_no_blocked_kms_actions
12+
- aws_iam_policy_inline_no_blocked_kms_actions
13+
- aws_iam_policy_no_star_star
14+
- aws_iam_root_user_no_access_keys
15+
- aws_sagemaker_notebook_instance_root_access_disabled
16+
- aws_vpc_security_group_restrict_ingress_ssh_all
17+
Tags: {}
Lines changed: 9 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,13 @@
11
ID: aws_acsc_essential_eight_ml_1_6
2-
Title: "ACSC-EE-ML1-6: Patch operating systems ML1"
3-
Description: "The patching of operating systems is the practice of applying patches,
4-
updates or vendor mitigations to security vulnerabilities in operating systems."
2+
Title: 'ACSC-EE-ML1-6: Patch operating systems ML1'
3+
Description: The patching of operating systems is the practice of applying patches, updates or vendor mitigations to security vulnerabilities in operating systems.
54
SectionCode: "6"
65
Children:
7-
- aws_acsc_essential_eight_ml_1_6_2
8-
- aws_acsc_essential_eight_ml_1_6_3
9-
- aws_acsc_essential_eight_ml_1_6_4
10-
- aws_acsc_essential_eight_ml_1_6_5
11-
- aws_acsc_essential_eight_ml_1_6_6
12-
- aws_acsc_essential_eight_ml_1_6_7
13-
Tags: {}
14-
Enabled: false
15-
AutoAssign: false
6+
- aws_acsc_essential_eight_ml_1_6_2
7+
- aws_acsc_essential_eight_ml_1_6_3
8+
- aws_acsc_essential_eight_ml_1_6_4
9+
- aws_acsc_essential_eight_ml_1_6_5
10+
- aws_acsc_essential_eight_ml_1_6_6
11+
- aws_acsc_essential_eight_ml_1_6_7
1612
Controls: []
17-
TracksDriftEvents: false
13+
Tags: {}
Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,8 @@
11
ID: aws_acsc_essential_eight_ml_1_6_2
2-
Title: "ACSC-EE-ML1-6.2: Patch operating systems ML1"
3-
Description: "A vulnerability scanner with an up-to-date vulnerability database is
4-
used for vulnerability scanning activities."
2+
Title: 'ACSC-EE-ML1-6.2: Patch operating systems ML1'
3+
Description: A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
54
SectionCode: "2"
65
Children: []
7-
Tags: {}
8-
Enabled: false
9-
AutoAssign: false
106
Controls:
11-
- aws_ecr_repository_image_scan_on_push_enabled
12-
TracksDriftEvents: false
7+
- aws_ecr_repository_image_scan_on_push_enabled
8+
Tags: {}

0 commit comments

Comments
 (0)