CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0

Audit Details

Name: CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0

Updated: 10/22/2025

Authority: CIS

Plugin: amazon_aws

Revision: 1.16

Estimated Item Count: 78

File Details

Filename: CIS_Amazon_Web_Services_Three-tier_Web_Architecture_L1_v1.0.0.audit

Size: 261 kB

MD5: afa23718a49f1e9e199f14d05007b727
SHA256: d7ae0cb1ad689fbbf350317eced33815782ae15555c0ee814c6c68720c32c22d

Audit Changelog

 
Revision 1.16

Oct 22, 2025

Miscellaneous
  • Variables updated.
Revision 1.15

Sep 19, 2025

Functional Update
  • 1.7 Ensure all Customer owned Amazon Machine Images for Web Tier are not shared publicly
  • 1.8 Ensure all Customer owned Amazon Machine Images for Application Tier are not shared publicly
Miscellaneous
  • Metadata updated.
  • References updated.
Added
  • 2.8 Ensure an IAM policy that allows admin privileges for all services used is created
  • 4.1 Ensure a SNS topic is created for sending out notifications from Cloudtwatch Alarms and Auto-Scaling Groups
  • 4.2 Ensure a SNS topic is created for sending out notifications from RDS events
  • 5.10 Ensure an AWS Managed Config Rule for encrypted volumes is applied to Web Tier
  • 5.11 Ensure an AWS Managed Config Rule for encrypted volumes is applied to App Tier
  • 6.10 Ensure NAT Gateways are created in at least 2 Availability Zones
Removed
  • 2.8 Ensure an IAM policy that allows admin privileges for all services used is created - Policy Exist
  • 2.8 Ensure an IAM policy that allows admin privileges for all services used is created - Review Policy Document
  • 4.1 Ensure a SNS topic is created for sending out notifications from Cloudtwatch Alarms and Auto-Scaling Groups - CloudwatchAlarms
  • 4.1 Ensure a SNS topic is created for sending out notifications from Cloudtwatch Alarms and Auto-Scaling Groups - List SNS Subscriptions
  • 4.2 Ensure a SNS topic is created for sending out notifications from RDS events - List SNS Subscriptions
  • 4.2 Ensure a SNS topic is created for sending out notifications from RDS events - RDS Event Subscriptions
  • 5.10 Ensure an AWS Managed Config Rule for encrypted volumes is applied to Web Tier - Encryption
  • 5.10 Ensure an AWS Managed Config Rule for encrypted volumes is applied to Web Tier - KMS ID
  • 5.11 Ensure an AWS Managed Config Rule for encrypted volumes is applied to App Tier - Encryption
  • 5.11 Ensure an AWS Managed Config Rule for encrypted volumes is applied to App Tier - KMS ID
  • 6.10 Ensure NAT Gateways are created in at least 2 Availability Zones - Subnet1
  • 6.10 Ensure NAT Gateways are created in at least 2 Availability Zones - Subnet2
Revision 1.14

Jun 17, 2024

Miscellaneous
  • Metadata updated.
Revision 1.13

Dec 22, 2023

Miscellaneous
  • Metadata updated.
Revision 1.12

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.11

Jan 4, 2023

Miscellaneous
  • Metadata updated.
  • Variables updated.
Revision 1.10

Dec 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.9

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.8

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.7

Jun 17, 2021

Miscellaneous
  • Metadata updated.
  • References updated.