Skip to content

Commit 8377268

Browse files
authored
Merge pull request #32 from opengovern/fix-framework-structure
2 parents ea3aa70 + 0651c8e commit 8377268

File tree

2,040 files changed

+54452
-44628
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

2,040 files changed

+54452
-44628
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
framework:
2+
id: aws_acsc_essential_eight
3+
title: Australian Cyber Security Center (ACSC) Essential Eight
4+
description: The Australian Cyber Security Center (ACSC) Essential Eight is a set of baseline security strategies designed to mitigate cyber security incidents. The Essential Eight is a prioritized list of mitigation strategies that organizations can implement to protect their systems against a range of adversaries. The Essential Eight is based on the Australian Signals Directorate (ASD) Strategies to Mitigate Cyber Security Incidents.
5+
section-code: aws_acsc_essential_eight
6+
metadata:
7+
defaults:
8+
auto-assign: false
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
control-group:
13+
- id: aws_acsc_essential_eight_ml_1
14+
- id: aws_acsc_essential_eight_ml_2
15+
- id: aws_acsc_essential_eight_ml_3
Lines changed: 17 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,17 @@
1-
ID: aws_acsc_essential_eight_ml_1
2-
Title: ACSC Essential Eight Maturity Level 1
3-
Description: The availability category refers to the accessibility of information used by the entity’s systems, as well as the products or services provided to its customers.
4-
SectionCode: ml_1
5-
Children:
6-
- aws_acsc_essential_eight_ml_1_2
7-
- aws_acsc_essential_eight_ml_1_5
8-
- aws_acsc_essential_eight_ml_1_6
9-
- aws_acsc_essential_eight_ml_1_7
10-
- aws_acsc_essential_eight_ml_1_8
11-
Controls: []
12-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1
3+
title: ACSC Essential Eight Maturity Level 1
4+
description: The availability category refers to the accessibility of information used by the entity’s systems, as well as the products or services provided to its customers.
5+
section-code: ml_1
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
control-group:
13+
- id: aws_acsc_essential_eight_ml_1_2
14+
- id: aws_acsc_essential_eight_ml_1_5
15+
- id: aws_acsc_essential_eight_ml_1_6
16+
- id: aws_acsc_essential_eight_ml_1_7
17+
- id: aws_acsc_essential_eight_ml_1_8
Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,13 @@
1-
ID: aws_acsc_essential_eight_ml_1_2
2-
Title: 'ACSC-EE-ML1-2: Patch applications ML1'
3-
Description: A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
4-
SectionCode: "2"
5-
Children:
6-
- aws_acsc_essential_eight_ml_1_2_5
7-
Controls: []
8-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_2
3+
title: "ACSC-EE-ML1-2: Patch applications ML1"
4+
description: A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
5+
section-code: "2"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
control-group:
13+
- id: aws_acsc_essential_eight_ml_1_2_5
Lines changed: 21 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,21 @@
1-
ID: aws_acsc_essential_eight_ml_1_2_5
2-
Title: 'ACSC-EE-ML1-2.5: Patch applications ML1'
3-
Description: Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
4-
SectionCode: "5"
5-
Children: []
6-
Controls:
7-
- aws_ecs_service_fargate_using_latest_platform_version
8-
- aws_eks_cluster_with_latest_kubernetes_version
9-
- aws_elastic_beanstalk_environment_managed_updates_enabled
10-
- aws_elasticache_cluster_auto_minor_version_upgrade_enabled
11-
- aws_lambda_function_use_latest_runtime
12-
- aws_opensearch_domain_updated_with_latest_service_software_version
13-
- aws_rds_db_instance_automatic_minor_version_upgrade_enabled
14-
- aws_redshift_cluster_maintenance_settings_check
15-
- aws_ssm_managed_instance_compliance_patch_compliant
16-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_2_5
3+
title: "ACSC-EE-ML1-2.5: Patch applications ML1"
4+
description: Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
5+
section-code: "5"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
controls:
13+
- aws_ecs_service_fargate_using_latest_platform_version
14+
- aws_eks_cluster_with_latest_kubernetes_version
15+
- aws_elastic_beanstalk_environment_managed_updates_enabled
16+
- aws_elasticache_cluster_auto_minor_version_upgrade_enabled
17+
- aws_lambda_function_use_latest_runtime
18+
- aws_opensearch_domain_updated_with_latest_service_software_version
19+
- aws_rds_db_instance_automatic_minor_version_upgrade_enabled
20+
- aws_redshift_cluster_maintenance_settings_check
21+
- aws_ssm_managed_instance_compliance_patch_compliant
Lines changed: 16 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,16 @@
1-
ID: aws_acsc_essential_eight_ml_1_5
2-
Title: 'ACSC-EE-ML1-5: Restrict administrative privileges ML1'
3-
Description: The restriction of administrative privileges is the practice of limiting the number of privileged accounts and the extent of their access to systems and data.
4-
SectionCode: "5"
5-
Children:
6-
- aws_acsc_essential_eight_ml_1_5_2
7-
- aws_acsc_essential_eight_ml_1_5_3
8-
- aws_acsc_essential_eight_ml_1_5_4
9-
- aws_acsc_essential_eight_ml_1_5_5
10-
Controls: []
11-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_5
3+
title: "ACSC-EE-ML1-5: Restrict administrative privileges ML1"
4+
description: The restriction of administrative privileges is the practice of limiting the number of privileged accounts and the extent of their access to systems and data.
5+
section-code: "5"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
control-group:
13+
- id: aws_acsc_essential_eight_ml_1_5_2
14+
- id: aws_acsc_essential_eight_ml_1_5_3
15+
- id: aws_acsc_essential_eight_ml_1_5_4
16+
- id: aws_acsc_essential_eight_ml_1_5_5
Lines changed: 21 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,21 @@
1-
ID: aws_acsc_essential_eight_ml_1_5_2
2-
Title: 'ACSC-EE-ML1-5.2: Restrict administrative privileges ML1'
3-
Description: Privileged accounts (excluding privileged service accounts) are prevented from accessing the internet, email and web services.
4-
SectionCode: "2"
5-
Children: []
6-
Controls:
7-
- aws_codebuild_project_environment_privileged_mode_disabled
8-
- aws_ecs_task_definition_container_non_privileged
9-
- aws_ecs_task_definition_no_root_user
10-
- aws_eventbridge_custom_bus_resource_based_policy_attached
11-
- aws_iam_policy_custom_no_blocked_kms_actions
12-
- aws_iam_policy_inline_no_blocked_kms_actions
13-
- aws_iam_policy_no_star_star
14-
- aws_iam_root_user_no_access_keys
15-
- aws_sagemaker_notebook_instance_root_access_disabled
16-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_5_2
3+
title: "ACSC-EE-ML1-5.2: Restrict administrative privileges ML1"
4+
description: Privileged accounts (excluding privileged service accounts) are prevented from accessing the internet, email and web services.
5+
section-code: "2"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
controls:
13+
- aws_codebuild_project_environment_privileged_mode_disabled
14+
- aws_ecs_task_definition_container_non_privileged
15+
- aws_ecs_task_definition_no_root_user
16+
- aws_eventbridge_custom_bus_resource_based_policy_attached
17+
- aws_iam_policy_custom_no_blocked_kms_actions
18+
- aws_iam_policy_inline_no_blocked_kms_actions
19+
- aws_iam_policy_no_star_star
20+
- aws_iam_root_user_no_access_keys
21+
- aws_sagemaker_notebook_instance_root_access_disabled
Lines changed: 20 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,20 @@
1-
ID: aws_acsc_essential_eight_ml_1_5_3
2-
Title: 'ACSC-EE-ML1-5.3: Restrict administrative privileges ML1'
3-
Description: Privileged users use separate privileged and unprivileged operating environments.
4-
SectionCode: "3"
5-
Children: []
6-
Controls:
7-
- aws_codebuild_project_environment_privileged_mode_disabled
8-
- aws_codebuild_project_source_repo_oauth_configured
9-
- aws_ecs_task_definition_container_non_privileged
10-
- aws_ecs_task_definition_no_root_user
11-
- aws_eventbridge_custom_bus_resource_based_policy_attached
12-
- aws_iam_root_user_no_access_keys
13-
- aws_sagemaker_notebook_instance_root_access_disabled
14-
- aws_ssm_managed_instance_compliance_association_compliant
15-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_5_3
3+
title: "ACSC-EE-ML1-5.3: Restrict administrative privileges ML1"
4+
description: Privileged users use separate privileged and unprivileged operating environments.
5+
section-code: "3"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
controls:
13+
- aws_codebuild_project_environment_privileged_mode_disabled
14+
- aws_codebuild_project_source_repo_oauth_configured
15+
- aws_ecs_task_definition_container_non_privileged
16+
- aws_ecs_task_definition_no_root_user
17+
- aws_eventbridge_custom_bus_resource_based_policy_attached
18+
- aws_iam_root_user_no_access_keys
19+
- aws_sagemaker_notebook_instance_root_access_disabled
20+
- aws_ssm_managed_instance_compliance_association_compliant
Lines changed: 17 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,17 @@
1-
ID: aws_acsc_essential_eight_ml_1_5_4
2-
Title: 'ACSC-EE-ML1-5.4: Restrict administrative privileges ML1'
3-
Description: Unprivileged accounts cannot logon to privileged operating environments.
4-
SectionCode: "4"
5-
Children: []
6-
Controls:
7-
- aws_codebuild_project_source_repo_oauth_configured
8-
- aws_ec2_instance_iam_profile_attached
9-
- aws_eventbridge_custom_bus_resource_based_policy_attached
10-
- aws_ssm_managed_instance_compliance_association_compliant
11-
- aws_vpc_security_group_restrict_ingress_ssh_all
12-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_5_4
3+
title: "ACSC-EE-ML1-5.4: Restrict administrative privileges ML1"
4+
description: Unprivileged accounts cannot logon to privileged operating environments.
5+
section-code: "4"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
controls:
13+
- aws_codebuild_project_source_repo_oauth_configured
14+
- aws_ec2_instance_iam_profile_attached
15+
- aws_eventbridge_custom_bus_resource_based_policy_attached
16+
- aws_ssm_managed_instance_compliance_association_compliant
17+
- aws_vpc_security_group_restrict_ingress_ssh_all
Lines changed: 22 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,22 @@
1-
ID: aws_acsc_essential_eight_ml_1_5_5
2-
Title: 'ACSC-EE-ML1-5.5: Restrict administrative privileges ML1'
3-
Description: Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
4-
SectionCode: "5"
5-
Children: []
6-
Controls:
7-
- aws_codebuild_project_environment_privileged_mode_disabled
8-
- aws_codebuild_project_source_repo_oauth_configured
9-
- aws_ecs_task_definition_container_non_privileged
10-
- aws_ecs_task_definition_no_root_user
11-
- aws_iam_policy_custom_no_blocked_kms_actions
12-
- aws_iam_policy_inline_no_blocked_kms_actions
13-
- aws_iam_policy_no_star_star
14-
- aws_iam_root_user_no_access_keys
15-
- aws_sagemaker_notebook_instance_root_access_disabled
16-
- aws_vpc_security_group_restrict_ingress_ssh_all
17-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_5_5
3+
title: "ACSC-EE-ML1-5.5: Restrict administrative privileges ML1"
4+
description: Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
5+
section-code: "5"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
controls:
13+
- aws_codebuild_project_environment_privileged_mode_disabled
14+
- aws_codebuild_project_source_repo_oauth_configured
15+
- aws_ecs_task_definition_container_non_privileged
16+
- aws_ecs_task_definition_no_root_user
17+
- aws_iam_policy_custom_no_blocked_kms_actions
18+
- aws_iam_policy_inline_no_blocked_kms_actions
19+
- aws_iam_policy_no_star_star
20+
- aws_iam_root_user_no_access_keys
21+
- aws_sagemaker_notebook_instance_root_access_disabled
22+
- aws_vpc_security_group_restrict_ingress_ssh_all
Lines changed: 18 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
1-
ID: aws_acsc_essential_eight_ml_1_6
2-
Title: 'ACSC-EE-ML1-6: Patch operating systems ML1'
3-
Description: The patching of operating systems is the practice of applying patches, updates or vendor mitigations to security vulnerabilities in operating systems.
4-
SectionCode: "6"
5-
Children:
6-
- aws_acsc_essential_eight_ml_1_6_2
7-
- aws_acsc_essential_eight_ml_1_6_3
8-
- aws_acsc_essential_eight_ml_1_6_4
9-
- aws_acsc_essential_eight_ml_1_6_5
10-
- aws_acsc_essential_eight_ml_1_6_6
11-
- aws_acsc_essential_eight_ml_1_6_7
12-
Controls: []
13-
Tags: {}
1+
control-group:
2+
id: aws_acsc_essential_eight_ml_1_6
3+
title: "ACSC-EE-ML1-6: Patch operating systems ML1"
4+
description: The patching of operating systems is the practice of applying patches, updates or vendor mitigations to security vulnerabilities in operating systems.
5+
section-code: "6"
6+
metadata:
7+
defaults:
8+
auto-assign: null
9+
enabled: false
10+
tracks-drift-events: false
11+
tags: {}
12+
control-group:
13+
- id: aws_acsc_essential_eight_ml_1_6_2
14+
- id: aws_acsc_essential_eight_ml_1_6_3
15+
- id: aws_acsc_essential_eight_ml_1_6_4
16+
- id: aws_acsc_essential_eight_ml_1_6_5
17+
- id: aws_acsc_essential_eight_ml_1_6_6
18+
- id: aws_acsc_essential_eight_ml_1_6_7

0 commit comments

Comments
 (0)