Trusted Advisor
As the number of resources grows in your AWS account, it can sometimes take work to keep track of them all. Challenges start to arise in the account, such as security groups that have access to anyone across the internet from a security perspective or unused Elastic IP addresses, which costing money despite being idle.
Every AWS customer and account has the ability to access the seven core security checks provided by the service. These include the following:
- Multifactor (MFA) on the Root Account
- S3 Bucket permissions
- EBS Snapshots available for Public access
- RDS Snapshots available for Public access
- Open access (0.0.0.0.0/0) on Security Groups
- That IAM users are being used (as opposed to the root user)
- Service Limits (these are on the service limits section, not the security section)
If you are on the Basic support plan, then you can view these checks easily within the AWS Management Console by doing the following:
- Select...