logo

Setting secure defaults on AWS and avoiding misconfigurations 

ID: ecb8f6ca-9689-50e6-870a-0a1fccd769b9

STIX ID: report--ecb8f6ca-9689-50e6-870a-0a1fccd769b9

Feed Name: Wiz Blog

Date Published: 2023-12-21

Date Updated: 2026-05-01

...
...

This blog post outlines AWS security guardrails and SCP examples to enforce secure defaults across accounts, including blocking public S3 buckets, preventing public AMIs and SSM document sharing, requiring IAM-authenticated Lambda URLs, restricting RAM external sharing, disabling S3 ACLs via BucketOwnerEnforced, prohibiting IAM users/access keys in favor of roles, enforcing IMDSv2, limiting network egress paths (e.g., IGW/peering/global accelerator), enabling and locking EBS encryption-by-default, and constraining admin role use by source IP; it advises assessing CloudTrail/Access Advisor for usage, creating scoped exceptions, and combining SCPs due to policy quotas.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.