[ Applies to ] StorageGuard / AWS storage and backup / Cloud Storage & STaaS
This article lists the recommended baseline checks for AWS storage and backup. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
AWS storage and backup services include Amazon S3 for object storage, Amazon EBS for block storage, Amazon EFS for file storage, S3 Glacier for archival and AWS Backup for centralized data protection.
Why hardening AWS storage and backup matters
Misconfigured buckets, unencrypted volumes and permissive backup vault policies are among the most common causes of cloud data exposure. Validating encryption, access policies, Object Lock, logging and backup settings protects stored data and backup copies from unauthorized access, loss and tampering.
Recommended baseline checks
The baseline below contains 44 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-C0093T001V01 | AWS Backup lifecycle configuration status | AWS Backup |
| SG-C0061T001V01 | AWS Backup recovery point encryption status | AWS Backup |
| SG-C0125T001V01 | AWS Backup vault access policy | AWS Backup |
| SG-C0094T001V01 | AWS Backup vault data retention status | AWS Backup |
| SG-C0289T001V01 | AWS Backup vault lock status | AWS Backup |
| SG-F9774T025V01 | AWS CloudFormation Stack deletion policy status | Amazon S3 |
| SG-F4520T025V01 | AWS CloudFormation Stack Termination Protection status | Amazon S3 |
| SG-F5880T025V01 | AWS CloudFormation storage services deployment status | Amazon S3 |
| SG-F8411T025V01 | AWS CloudTrail enabled for storage services | Amazon S3 |
| SG-C0062T007V01 | AWS CloudTrail log file encryption status | AWS CloudTrail |
| SG-C0026T007V01 | AWS CloudTrail log file validation status | AWS CloudTrail |
| SG-C0027T007V01 | AWS CloudTrail multi regional trail status | AWS CloudTrail |
| SG-F3781T025V01 | AWS CloudTrail S3 bucket MFA delete status | Amazon S3 |
| SG-F3890T025V01 | AWS CloudTrail S3 Bucket Object Lock Status | Amazon S3 |
| SG-C0028T007V01 | AWS CloudTrail trail logging status | AWS CloudTrail |
| SG-C0369T025V01 | Cross origin resource sharing (CORS) status | Amazon S3 |
| SG-F3436T025V01 | EBS point-in-time recovery status | Amazon S3 |
| SG-F9592T025V01 | EBS Public Snapshots | Amazon S3 |
| SG-F7762T025V01 | EBS snapshot encryption | Amazon S3 |
| SG-C0020T013V01 | EBS volume encryption | Amazon EBS |
| SG-F1505T025V01 | EBS volume encryption by default | Amazon S3 |
| SG-C0290T019V01 | EFS backup status | Amazon EFS |
| SG-C0045T019V01 | EFS encrypted with customer managed keys (CMK) | Amazon EFS |
| SG-C0066T019V01 | EFS encryption status | Amazon EFS |
| SG-C0302T019V01 | EFS replication status | Amazon EFS |
| SG-C0082T025V01 | Enforce S3 data in-transit encryption | Amazon S3 |
| SG-C0048T001V01 | KMS customer master keys for AWS Backup | AWS Backup |
| SG-C0222T025V01 | S3 Bucket access control list | Amazon S3 |
| SG-C0021T025V02 | S3 Bucket block public access | Amazon S3 |
| SG-C0021T025V01 | S3 Bucket block public access - Policy | Amazon S3 |
| SG-C0104T025V01 | S3 Bucket lifecycle Status | Amazon S3 |
| SG-C0105T025V01 | S3 Bucket object lock status | Amazon S3 |
| SG-C0022T025V01 | S3 Bucket owner enforced | Amazon S3 |
| SG-C0092T025V01 | S3 Bucket replication encryption status | Amazon S3 |
| SG-C0304T025V01 | S3 Bucket replication status | Amazon S3 |
| SG-C0223T025V01 | S3 Bucket server access logging permissions | Amazon S3 |
| SG-C0003T025V01 | S3 Bucket server access logging status | Amazon S3 |
| SG-C0070T025V01 | S3 Bucket server-side encryption | Amazon S3 |
| SG-C0240T025V01 | S3 Bucket versioning MFA delete status | Amazon S3 |
| SG-C0339T025V01 | S3 dedicated role for replication | Amazon S3 |
| SG-C0224T025V01 | S3 Object access control list | Amazon S3 |
| SG-C0106T025V01 | S3 Object retention mode | Amazon S3 |
| SG-C0252T025V01 | S3 Object versioning status | Amazon S3 |
| SG-C0285T001V01 | Unprotected AWS Backup resources | AWS Backup |
Related components
A complete baseline also covers the components that manage, connect to or protect AWS storage and backup. Review the configuration of:
- AWS IAM and AWS Organizations policies
- AWS KMS
- AWS CloudFormation stacks that deploy storage services
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.