SEC01-BP01 | Separate workloads using accounts | 24 |
SEC01-BP02 | Secure account root user and properties | 23 |
SEC01-BP03 | Identify and validate control objectives | 24 |
SEC01-BP04 | Stay up to date with security threats and recommendations | 21 |
SEC01-BP05 | Reduce security management scope | 17 |
SEC01-BP06 | Automate deployment of standard security controls | 22 |
SEC01-BP07 | Identify threats and prioritize mitigations using a threat model | 23 |
SEC01-BP08 | Evaluate and implement new security services and features regularly | 11 |
SEC02-BP01 | Use strong sign-in mechanisms | 23 |
SEC02-BP02 | Use temporary credentials | 22 |
SEC02-BP03 | Store and use secrets securely | 24 |
SEC02-BP04 | Rely on a centralized identity provider | 22 |
SEC02-BP05 | Audit and rotate credentials periodically | 24 |
SEC02-BP06 | Employ user groups and attributes | 22 |
SEC03-BP01 | Define access requirements | 24 |
SEC03-BP02 | Grant least privilege access | 26 |
SEC03-BP03 | Establish emergency access process | 18 |
SEC03-BP04 | Reduce permissions continuously | 23 |
SEC03-BP05 | Define permission guardrails for your organization | 21 |
SEC03-BP06 | Manage access based on lifecycle | 25 |
SEC03-BP07 | Analyze public and cross-account access | 20 |
SEC03-BP08 | Share resources securely within your organization | 15 |
SEC03-BP09 | Share resources securely with a third party | 22 |
SEC04-BP01 | Configure service and application logging | 25 |
SEC04-BP02 | Capture logs, findings, and metrics in standardized locations | 23 |
SEC04-BP03 | Correlate and enrich security alerts | 24 |
SEC04-BP04 | Initiate remediation for non-compliant resources | 19 |
SEC05-BP01 | Create network layers | 24 |
SEC05-BP02 | Control traffic flow within your network layers | 25 |
SEC05-BP03 | Implement inspection-based protection | 24 |
SEC05-BP04 | Automate network protection | 17 |
SEC06-BP01 | Perform vulnerability management | 27 |
SEC06-BP02 | Provision compute from hardened images | 27 |
SEC06-BP03 | Reduce manual management and interactive access | 23 |
SEC06-BP04 | Validate software integrity | 22 |
SEC06-BP05 | Automate compute protection | 27 |
SEC07-BP01 | Understand your data classification scheme | 23 |
SEC07-BP02 | Apply data protection controls based on data sensitivity | 20 |
SEC07-BP03 | Automate identification and classification | 17 |
SEC07-BP04 | Define scalable data lifecycle management | 23 |
SEC08-BP01 | Implement secure key management | 21 |
SEC08-BP02 | Enforce encryption at rest | 22 |
SEC08-BP03 | Automate data at rest protection | 17 |
SEC08-BP04 | Enforce access control | 24 |
SEC09-BP01 | Implement secure key and certificate management | 19 |
SEC09-BP02 | Enforce encryption in transit | 23 |
SEC09-BP03 | Authenticate network communications | 21 |
SEC10-BP01 | Identify key personnel and external resources | 22 |
SEC10-BP02 | Develop incident management plans | 26 |
SEC10-BP03 | Prepare forensic capabilities | 17 |
SEC10-BP04 | Develop and test security incident response playbooks | 22 |
SEC10-BP05 | Pre-provision access | 14 |
SEC10-BP06 | Pre-deploy tools | 11 |
SEC10-BP07 | Run simulations | 20 |
SEC10-BP08 | Establish a framework for learning from incidents | 22 |
SEC11-BP01 | Train for application security | 24 |
SEC11-BP02 | Automate testing throughout the development and release lifecycle | 20 |
SEC11-BP03 | Perform regular penetration testing | 22 |
SEC11-BP04 | Conduct code reviews | 19 |
SEC11-BP05 | Centralize services for packages and dependencies | 18 |
SEC11-BP06 | Deploy software programmatically | 20 |
SEC11-BP07 | Regularly assess security properties of the pipelines | 19 |
SEC11-BP08 | Build a program that embeds security ownership in workload teams | 21 |