{"_id":"@cloudgraph/policy-pack-aws-cis-1.3.0","_rev":"10-8abc5c4c83be10d5996827e537dc01b3","name":"@cloudgraph/policy-pack-aws-cis-1.3.0","dist-tags":{"latest":"0.5.0","alpha":"0.5.1-alpha.2"},"versions":{"0.1.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.1.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"cb1917a1e4c7fb1eb6760bdaaca4bdf1eff3a69d","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.1.0","_nodeVersion":"16.14.2","_npmVersion":"8.10.0","dist":{"integrity":"sha512-Zi3lTvZBh2rFP7NPKKtmIR5Jg3TQBk5u+8udVGmMFzWYTc2NcmXkGG3CfiKf4sgz0od39h13cA62mxZV6I1voQ==","shasum":"8bf457f8f101769d61c486992bbeb2272b423cd4","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.1.0.tgz","fileCount":31,"unpackedSize":173595,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDL+wplnjr9fJeIPv6QQNtrX8QcUADOhiFngrg2t6abIAIhALBgjZPdnsD/SUfRW38BhPAOvtcn+T6n15qin7Eglqdh"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJifUt8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpxEw/8D5Ee20K6VFP7qpc4rpoTt35VSlEHrHZ4QhjdRjeUMHX66mS0\r\nk4bfUXcoJjxVNLKtVmKx3PGnZdt2YNoTDNmMQo7eSjHTQ+9fkIZu+Sp/0Xb1\r\nvTLPo92yCKIh6D+4GydZhRARWlL0MD7G6+8Q/yvb/m/2oCeS0pDUTZ/it/ym\r\nSXaQQZyMGfNXFdmjlxYAQdt/G8ZrqTee2mKHCDDglIq5iTpA/q8mNR4L0zJy\r\nEkX9isgD0hKiuTR0YMvHBVDBkikR6h8HyOOH8cdHNeHzgfZrFCyEhjj/RRdw\r\nelsuwjka78VIjctfmR47dFWK7cpFVJCxBMWzyYaQ4kBE7LA5WNcN4UvhAJ6C\r\nPTW06oonhJvKAlA8jAh/FCBcu6FNG8J13EHVixo3mpQLJN+yOiz1b6DSQcDL\r\nYJvyxiCFDXT2M2lpA08jj3e8gujZiooPMleJnrH8ZJrybmPL7dbHQ3hUrO/x\r\nKJ3lCRi9GpFEbULWtzkUhCJZ2MwMG+re0wEH5MIRoDijprbJpfQ1+wYI/+K4\r\ngMdxhTawRlDZQ2eGqh+TO7tbKKcf3Fiq9wLli9+dTYICZcjOxba/9hDOtWZM\r\noJ/donRdfe4hKBkCfuXlc7YXAzX6z3rrLWk/2XW6aLmN3sjEy7gMyut9UYam\r\njkbJlacmf+BZ75EoOQSzLuODdavPTw3dGpw=\r\n=XaRx\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.1.0_1652378492614_0.7007133916362123"},"_hasShrinkwrap":false},"0.2.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.2.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"12bfdbfd5da75dc802c6ec97cfce2e6147393652","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.2.0","_nodeVersion":"16.15.0","_npmVersion":"8.10.0","dist":{"integrity":"sha512-4onOqcDgv7XCXFJt9SvbueBhxc3EGezbmZ2g31/1lL1T4cyzZHQRWJrbIyIKZ5pGLyebEWQrpGY7xU46SlbKag==","shasum":"b0e692d7ed081ec174bef75e4dfa2b9a668e9050","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.2.0.tgz","fileCount":61,"unpackedSize":311022,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBQnryI/rUmauGxtZPIJdr7IWtDoXxs0+88hNGfr0msJAiEA7iFXpLWSCeD5ATvD7F3HMNKP5Al3GiZ2x8iy1EQHDQg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJij+PhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoT+A//V1cailpApuSa6SB4R/iC6zFjqxlKWsQRuIkvL4I1eAxRZMxX\r\n0MV+R0CI2VuHo+rq6jnWZlt+mPNffLoSiQtl7/kJOcZ7VA5kWdm9PDdyew8U\r\nig5NnA7PI4Xq1HakjREEg6R01v/vnclQK84dV5o82mnscwIHDn8NzPoip2KQ\r\nlWWQQhxSVzU+IBA9S2hs+fp2nbVZineO3tXxyfGNK4SUBLJhqrPf5NUxfPiw\r\naJka+820vH891rvhNzzn8KeHYbhQCvR0NqtXO+Y7X6nKlymPuAgFUyjQvWKw\r\nJz58lLY3A9d/+TRsrj1ByfT0PtIu+VLI5hCwygJOqnHwKHOx5U3ujSeO8srR\r\nSB+czvx8ykqMHtsYhjjNh2qkEKT/0Mb5kIreAeXNVJD4CTLz/+wDuDrkAWWW\r\norId4gKGuxDobOmqggQ6qW9qoc59uR4lr7ssJs30D5UoPtfOqcHpdbkmBv6d\r\n7P3lMhpI/iL+mcWh045tuQE5w+esNv+W8uT3AP/BGjmkhDKuSi+AtlFIdUf0\r\nchvcKhY4x9zuXU+mSQo5aRKg1a94duBieD4NlOXpW3NCFNmqkfBf+Rqr9Ava\r\nj8SEGEc4hu99IrE+F+qzuQeu7S/BGDAwR3rBf73oG7AUqCMGpBgvo0Ovlny4\r\nMllhsAS4o4NgcUF9E/dCE9k41jBab5qB704=\r\n=NVBX\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.2.0_1653597152862_0.3609023755435481"},"_hasShrinkwrap":false},"0.2.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.2.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"0a3278eb6efb547a18993b5a675e9788c399ecfb","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.2.1","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-zbuog/765kWz9MYdmpg/1p6mFzK/ORzVzjhqdm2Q89wdjU8fxpjtZ+j8lIXLFeGTmACq3g84gymfIYDuDWf80g==","shasum":"1b81ce06f8435084c785ebd51f509cfa0fefc5b4","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.2.1.tgz","fileCount":5,"unpackedSize":14932,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDGiqt3p+nJc2+ox9fqORJdATG1SCbnW3j5DGbvNTT0GQIgJ72WX74bzOxCILcbBL4Vx+qavgBccFqdagpK6l06PYo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixJfRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqx7A/+NPgYmLEM8lsUXU6YjajCOhBlEHq42aq9H+YBNvrCWOEpOh9+\r\nDRnagArjcTJ9DwMxNeV1i+FbUGRlRcyAvNpenRV+KBJ5WhieIbj/hoIkfZwa\r\nun5XYPoEaJKzrHqvDi13lURMuKKLhi0r5meP2FK5q7SLPoXAL5i7FK1mYtBy\r\nQ7DY/RIGm+Wnz5rl43sNRc9mv4juQLBo4dslZjVwrox50jCmOBgcLfPkh3o4\r\njhhplSMl9gPtZmwyP4V0ktjV/UE7D6C92AdVNUbsDJIqLFgS2pLNJv+ZMeIa\r\nDjox8Dx08YPr8et30IkJ3RSShNOHFf0gex+CHZ03BDOVpWqvBO88IZUQ78bS\r\nJRCsDBgPLSRakeIs/neI7kdo/qo5KUz91pz59oKAYcGaFg+EeJOMAp0SifQ1\r\nGsbHtn66vgYV1JhJb/htDAITVCWz0QDYm/gNBee65XKqNUMne866C2dqoGKc\r\nV1ODe8HfGMwn/1OI/GhLCEA5dyUd9P7j/iQe8gl8a3ZJjdjBskP3juNsfpAe\r\nu+VYKEmNl+faTFcmi+775ef3fMMMrR/RWgQxX2elfPb1RvAqm00jA//m+fVo\r\n7svjI28h0jBjukiCt3Dz/rSqI+hI1h+duHJTwQh/H1p3sJFiEpohwTD/yzbM\r\naAN9Xtft9wQqzC2fAYPNsNSg/Id06SvFpsU=\r\n=S1o9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.2.1_1657051089433_0.05098396152219631"},"_hasShrinkwrap":false},"0.2.2":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.2.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.2.2","_integrity":"sha512-Ox1iGNcfGHjLt/lZhUgRRVI8FgtP/2cuBO+LP7JFhZszL0/JD/pukidCirHkVC/nge99QDQ7MTmd205Uuun8vw==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/b402ec35e403c2fa9795b0a7120629d9/cloudgraph-policy-pack-aws-cis-1.3.0-0.2.2.tgz","_from":"file:cloudgraph-policy-pack-aws-cis-1.3.0-0.2.2.tgz","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-Ox1iGNcfGHjLt/lZhUgRRVI8FgtP/2cuBO+LP7JFhZszL0/JD/pukidCirHkVC/nge99QDQ7MTmd205Uuun8vw==","shasum":"368aa72f4f882a5d1e84b0fa89303f5f45962af9","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.2.2.tgz","fileCount":118,"unpackedSize":383236,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCORbpGUCG8ux7ntw4l5poP+i9PTDmAhp7sI6KcdpKL+wIgLwfVvaXomuAOJwr7lavYXfIGZoafFzns0LL/vVCwZSQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixLEJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpphQ/+OsKuf+lka37MI81TqdhcmjCUxqCeIrMjLqmPxyyBrOa4i5Xr\r\nW8x1uanDLpLZViPHfUGN6oWkS1imXrm4K4wUY1c2IkiGeHBcV6mP0H5tD0m6\r\n6fBhhe573rriHZdjbMa15DYgaofNiMjQsNGDK0Ut2gsw3H7xhXz6xhUTqVvT\r\n5+KHAwo6eGNK9NrYxALT8X0Z2ZbsYg7Z9XiYEAZrv6uD/bUT7Fbv9E8lm8mg\r\n6ScZA349fiILRv3Bh4UxXj9VazIJ3vouozwrye2jQtqiXxd6TjaenqiOm8ng\r\n4WXe289uExdsJUvJkI6Xb0kvKf1y4LVSe31vH0v2ZUfC93MAKScQ5HnRjZpn\r\nPRrYxBuJVkQpmeiLhjBfKESxUGBODqvNY8xzor5JwpTzz/lWFyn4IkZ2mRGN\r\nucQPCNm0PFTL6zBOfOV0alcskjs8lzEC0LLleBdkVrsDsCvNrJu9bg8nULn0\r\n3dvk0JhFXXKNL6wnmTQ4+1GcarmFXchI3B9lQSMmbJnEaU3jRq1yyE7yuXJW\r\n5CYTYzROJqGFcT1Pm5ECBZSj6uGo4Fsr6LwvxfE1tU/KzmfPzxC7z8xkGvWR\r\nC40d+tvjjIYzmDSP7IFY4aw3oyAtDv66XSnpRB1w6JM0gYbm9wZCBIzK17Cn\r\nIA2SJv8ypkDiNH5TUPc8sib/HyaUG4uVf6U=\r\n=GVdf\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.2.2_1657057545279_0.12446305082491871"},"_hasShrinkwrap":false},"0.3.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.3.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"2207a06ca2e660756751b7fb4e0293ca2d19feea","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.3.0","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-DD5KUvs6XHbw/DSTKQ6ymzeErcqFNDRFm9F0EDQ/cKXkOC+xIHSTaHnSmhyDyZeZvVQet/N9tgBgFR5yvs9S9w==","shasum":"ff2de8ec15073d5e4165759a3c60dd8ec704e350","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.3.0.tgz","fileCount":61,"unpackedSize":46285,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGdYM1RwdvSR8aM2SdIFPoMAcpWPrCN1XAMN6vva1ZeeAiBpQjYTPxGyMUGXQZ0xBQrQD9jx4jLw2w3cbzgaSANW7A=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizE1TACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoG9Q/8DYGvmNpWYagX2b7jPn/wuCHY9cZRK2qRHCbDwC6KUvXbisHC\r\n2Qw+T0QhA3UCsld4ekBuV81hXyHzA+PhyLYyuLQo5rT1keJzt+4l9nuB9QyQ\r\n5XlcmTXL7EFjre5WlkAqrSWK/s26XCEiaBFNRb5Nig66rZCERXYqH/27Wv5+\r\nNRzkTFLKy8HJz4PJzpX6/OjrOb3WfONhcuXs5pp+JSN3Jr2uDcDmBZQjYM6z\r\nTzxHs6aUjINq8gbRWX0uHYdS6E1yUtxwQYjCQa3fHy+9LbxBkOFUAgXk8Qc/\r\n1RUA2VR5ZiHhG2zZB/NTpQwZH1Ho36K+4T8S8hvgi5+SJYRqxJ4KJYFc5w1u\r\n0VOCO4T/SH59LgWmDlTM0erJ/QAS+8JcPsgNBzcqRllAyzFmVqJattOjrBOE\r\nk9c8grlUdp7XN4l3PglcwO91OrV0103ru4umdzmBsW6TClyTnpgKuZnRW7jk\r\niq0pSFvL4+vOhmSoKg9A8H+iHcZjoQw4Jzh5Vq+WhXT3jQi5pgMBRT8bCOCS\r\nHS41AUqNqbyAFKv6vcyl/B9thvrpCRoqm2PKku9chHjoZ31SJcbChGObXhQd\r\nHaYba9fWhXvAtVbXZa8lbi33bZfOyyFhhaDEYpzIP8tT3qFEDeAGmDVeylNC\r\nx/5kWhUFvmQ4+Avm6rH0FYO5pXlWQWrMcSw=\r\n=kRxr\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.3.0_1657556307603_0.6721847555294778"},"_hasShrinkwrap":false},"0.3.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.3.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"daa87500fd4648f9674a6fe5f6de8ab68a0c83bf","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.3.1","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-ZMK5KNUSLIqP6RztN36h5ZFYi0vRVHhJI+zi2pa8ZOkHeFt+v8w86qnLrRKDdihVsJ3dmNL7xX6bUlpyM2T+0Q==","shasum":"b10e9c7f6853b93eaf5d058257cf912a7e2afdc9","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.3.1.tgz","fileCount":117,"unpackedSize":333087,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDjyRZnvDGhFTnilmgfd1pFocuqESK9bxs4XhaYzdq2HgIhAMOfWLDNY52gS9bVC4qRzDcpj95Bn++mgt3/0ustR0h4"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizH1uACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrjrA//SqA69TeOTK3HjeGHI3Jig3uF92CXfuQO3Kyoq4uqeUaINrJ2\r\nRyiXUZV8OWYCoiswjBfrveegzJ8m3CiiUKY/j/PTpdqsMxCfvj5Mwnj7R3Mw\r\nP0fiiJyKiu0re35n5+n6LQzN6sbaTundVb9/6MjLHKDWLXZX/khagv9wKsNF\r\nlUT6DCAjAxY4L/jZMlDKTvX7go7pO6t7YY+2xtZnxmhOArDfNUYvTOZOwbBq\r\nlYZYIaLmumLWxMSVWNpThwSlzbaIqm6LDtWeILa6VbwlCwGqultyQ8hsFDbg\r\nZ5x2Fe8HetYCKlAAAdTdyMSToWhetHczMYv+uLule53c21zTC6enr1J6gpcl\r\neMO+dywaLdfhyqvvsEzQvhLAim3tpltcDyfZyOt5hjWk7Nf0zxCOushkVSg0\r\nspRhXuPDQVr7UVunKXl9RIg1cO2Uykt6TKqpBEucd66WVfwZycUhuAWVrJem\r\nWnlZ/sKmA+WTlEcE06TVPj8INwMmPC/HSq6yJDV/1XgY0P792xcpqW8UBhMA\r\njOGe0Mu8DevpaX7wM8vcaSGpvhl0paEsfs7e53xGRO2xdqV2uT1OdOkqUw9W\r\nlA/MFx13Dccxla8JdoOreZPhveK2Vy+eFmW6NunZEkNEgqqtB7ovmHTUsqsX\r\n8f9syXHYcWPXMEgpR89zAdprtdpdHP6T+uA=\r\n=NVF/\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.3.1_1657568622770_0.9915614311215319"},"_hasShrinkwrap":false},"0.4.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.4.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.4.0","_integrity":"sha512-VUwPkwcH4DXwIoxHDN0JYraxJe0q//w19WF3LZyd983i8zOiMoMeTuDUhi7lIqZAFSEyCNP6MjkG2MzuzgMdHw==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/970ff4bbe74a2d866d0f6ca16e7407ea/cloudgraph-policy-pack-aws-cis-1.3.0-0.4.0.tgz","_from":"file:cloudgraph-policy-pack-aws-cis-1.3.0-0.4.0.tgz","_nodeVersion":"17.9.1","_npmVersion":"8.15.1","dist":{"integrity":"sha512-VUwPkwcH4DXwIoxHDN0JYraxJe0q//w19WF3LZyd983i8zOiMoMeTuDUhi7lIqZAFSEyCNP6MjkG2MzuzgMdHw==","shasum":"5ed96d62fa1af93677f24b1613bb5cbec5174c65","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.4.0.tgz","fileCount":118,"unpackedSize":349414,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD6RB7MoklQmrYKFLwLNQOMEhsrkU+JM6mIw+cwDZvr4wIhANze0gLEm2phbnQjtcJ6L9gAvvNj+YTjTnS4WE4JeuB1"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi6E+9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr1Hg//aA3GIFidm5HrPhH6VqThXIJr0B0OB1W9JGWRsJ8OuAhmAM3x\r\n+Q/FjkCpuTRjwPRUeqsxcj2q/ebfHgCel4jX3qsXoppNKd9pi08maIlnRPC6\r\nUGMPrMRsbfc49dnw/hWZLPsaP+0a/wdmpRiwGwIZAQRFi2Uyr1XdxDUAEDim\r\naNXKQuRF/iQOt24HKmPr2BEapNr3mmUBGLkivusWvuOb6c0VUj4p3Y6w35uW\r\ngbGc7nH0YCPa7R7MzlCkNscvYMU+ZN9oOgExpresi3RIlgI7ZWDHNU4zWlAH\r\nSkd0oBliRCbEzMf3BmEpObvSmxGvY8FD0W8rLFAVJ+sBNXh0u9i68LS/+yqx\r\nQmYXuimHXySqqjfA5hVXvGAAJ5Fh9v3D4lZapiw6oMxHtonyIMeX01qULVrx\r\n2E/bcfu0yvYV5YNKGHwTbI0Aywe3qIGiXOVdTSqEnUbMfmBq9bYHfzkpAUAL\r\ny+WCLdW/szyVAtU11XSfiEzqEcvIoA2hsZuwzM2LWTvhc1deH2adhJ9KZjKn\r\nyQcYi4kKHjeQUmUVDkmyq/mBTd0Qa4FseFDeurzWml800g0tPxYj3C9Qu5ZC\r\n9SxfzTjaaznbtyLSWF6RucCUS79pC10LBnCxmEc7b8ZzQEziNDduX/8xWZST\r\nZI5uDCgCEZmEWoilXswKHxzLnXGAvJ9qMPk=\r\n=R24Z\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.4.0_1659391933028_0.006736588277181266"},"_hasShrinkwrap":false},"0.4.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.4.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci -e semantic-release-monorepo"},"readme":"# CIS Amazon Web Services Foundations 1.3.0\n\nPolicy Pack based on the [AWS Foundations 1.3.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-3.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.3.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root user' account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the root user for administrative and daily tasks                                                           |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 90 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                          |\n| AWS CIS 1.21  | Ensure that IAM Access analyzer is enabled                                                                                  |\n| AWS CIS 1.22  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"9473a78b103158ec9b554df5fbfe51ea7dcd8217","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.4.1-alpha.1","_nodeVersion":"18.12.1","_npmVersion":"8.19.3","dist":{"integrity":"sha512-IgdEtnc3Ko3aDpCmmCCUpZ+MZmnUzG8TMJHfP2Z9wkMgrOh1vPpSIgTGKrZdg0ROr2+zDdn9XN3+gmRWNsYDjQ==","shasum":"7107e941356f740ac3e9b13aaab3374b9f84a747","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.4.1-alpha.1.tgz","fileCount":117,"unpackedSize":333941,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCQoK3K7t8sf0uh+deffXLeFFfzGoGvFGyM57dfh1r46gIgElqbiKQm4nWTzh0oywI5k9WHmyBD0WCSNyQdn6ycKc0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmRwOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmozsg/8CtjXgEPoIXLwJ/6v6OOV7M9sP5DdajmZpJS8Zs5Xf3vc7UEF\r\nKR1ZkrWOtJOD91+90Sy2tzdjKnDNbFzaJRNvXvqUV6LHLjokobwCQSkeG410\r\nd56/zdyuk7kvEJhSWnxGq91ID0qEum7twLqLTPC3PKmQHbXg7L7DlS7kueFT\r\nVishFLPsJckkniCYIxCrK6giYY7T8YQpPptGch/eMeTQrqeb1Jy+DgXRxYJr\r\n4WaflxhJUNV69mCdDKPkFhe7ohmwm8mou9f37C6bjiRiYJf3OxWsdlZKTRYx\r\n7p0wy4ufjQTc9g7jiBWtuMj+BukMxId673Dg6awhho0j8P4sb9mSK497vZJw\r\nMBzdNZAgDZ8XGH5dmiYDFs9S5zvhkkDVLPfB2AQR/YdiEi3T/K67f2IMpsIF\r\npX5nSvZ8K//rbl/JlItmwMhVw7+fAsu0t3BvkhpDA0B3aA2BWmlIiwRgS7i7\r\nxDAvRL13jnxWfrRUvoEmCq1LT8VDhxz/6HNNC6aFIjEH7yva1k9EkrhwHrov\r\nplGFtc0BBly0j4bgGwwbI76efONFg+JKYGKAtksB3ofaJhlkRrGQCzz/4J3I\r\nkqr6MjezamHZUkqQ2vJ3R+FCaJeOCLCNannjx4QPXq3e4rdrRpQ7mGzjVqWS\r\nnWxuuQblLQiK+HbDJevr1peZZvDqROUNcEk=\r\n=1MYW\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.4.1-alpha.1_1670978574561_0.3050015445001115"},"_hasShrinkwrap":false},"0.5.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.5.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci"},"gitHead":"a66711ce1f0f97ad85f2c410346dad2fdb979c66","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.5.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-11CqrajH5ZZqjP2uV51KGxNe26ItOP+o9mNwpOqvwTx1ojenU5HlELDEBwP73jigKNgOd5q6tvPPMxBpdZUMZA==","shasum":"8fed9ef531ce0e257a8d4aef16f4abda76651bbc","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.5.0.tgz","fileCount":117,"unpackedSize":343265,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIA1Kx9vlwOh8LJAqGDVowUUNcQ12BaNYChvcNh8uNzC+AiEAvUNXNwEPjT4A8pShOMg7WYTPy5Q8zOa/1V5FxuTX6Uo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkS/q4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqtlQ/9HkRtDmEfGsZ0p4xdRUpACm9XHBKktbK1gs4s9VyxIY3tTmxF\r\nGeLqFVPn6UbrxknUAf79WBkZgFEXDLrGZZCHXSd5fm/zex22QkTCegRSuTQX\r\n+TwcDFJn6QxRIlxKWSqxxEO6l1/EBsenjpG2jo3mrNm9DuXzsvZ4zxWjW5pw\r\n1cMsz3lcyqWK1+tujZURWTVQoqTaK3ZqNUV17gomvmM0zS4SRd6DjFFGS9oW\r\nayq51Jey0I8ruUrUx4us4RkTRWIEPEyUJRhNe4vzG9VsKyv2L48SvEvgVygm\r\nq2tJILMIj9+wvbPqDxEIxWIklu1L7u8gEjHs+OPUXsobOiHXDOF+RkX2x2nf\r\nMCNDHBNUGnzf/6BRLc1TwHWILUfqQmsnreAycdeU+2eCuhRuKUIcYiFkkQq3\r\nzicoxjpAh6smZ0gyHvyQnsWN8351HsuZSHHEWQqozvzEyrBKvCcjGxQmnso/\r\nLSVY/5ENkNK79Qv3CZJr2kGrhACi5JT0nuuvtfVx6F61ldxArywk8a0AIrF6\r\n/LG9MY4KLt8bRtNoPaOchuiCQXfpmlbBNV6O95oHOhtn2P6IDEsRTZ00GGa7\r\nYERMQtq8lUHDJUyPmwWbNJ4yZ8e3baAmbV304NYGbJ59XRSeWzZ/gtz00zS6\r\nzYJ0VzYdPQKEZtjcNoXSH/xJPkQBam5OZ1A=\r\n=rfAA\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.5.0_1682700984384_0.2568414754130761"},"_hasShrinkwrap":false},"0.5.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.5.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Amazon Web Services Foundations 1.3.0\n\nPolicy Pack based on the [AWS Foundations 1.3.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-3.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.3.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root user' account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the root user for administrative and daily tasks                                                           |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 90 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                          |\n| AWS CIS 1.21  | Ensure that IAM Access analyzer is enabled                                                                                  |\n| AWS CIS 1.22  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"abaff35a507d7c8b30f06bc574feb5aab7301fbb","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.5.1-alpha.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-mj4/c5PJB8MOBooYdErkGRgl1ESY/p/LnEqLny/kd4ZMmj+VBIe7S7GN/eCCdTQuw5L+teYXhubDaTsmBpFpVw==","shasum":"c542ab5b08733f0060911f6be309c347912e3c38","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.5.1-alpha.1.tgz","fileCount":3,"unpackedSize":26329,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDGbdw0AXME/KUe548CjWSOO2EnyPKCRE3wV5Y9/sa47AIgdT5WAWTmcY9KVS2qzy3XAxXjzhxmfF4s3EZHeegz7cs="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.5.1-alpha.1_1684332594503_0.8944715661303297"},"_hasShrinkwrap":false},"0.5.1-alpha.2":{"name":"@cloudgraph/policy-pack-aws-cis-1.3.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","version":"0.5.1-alpha.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Amazon Web Services Foundations 1.3.0\n\nPolicy Pack based on the [AWS Foundations 1.3.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-3.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.3.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root user' account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the root user for administrative and daily tasks                                                           |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 90 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                          |\n| AWS CIS 1.21  | Ensure that IAM Access analyzer is enabled                                                                                  |\n| AWS CIS 1.22  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"859c85793bc43805ee9e0ede60a3a0934fc0cfc0","_id":"@cloudgraph/policy-pack-aws-cis-1.3.0@0.5.1-alpha.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-TgaKDVYYHRyZP6YsEIffsEji+UcWo/Fj0pnQXRcNfoWboROVkH40w7vYbNTak2V17Z0lZ448ZbX7aKkkUsswIg==","shasum":"c65b050c0c0fd3fad14d3c1cf2e836dc560ebf78","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.3.0/-/policy-pack-aws-cis-1.3.0-0.5.1-alpha.2.tgz","fileCount":117,"unpackedSize":344032,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCQRTrgBopL15u2nFdTbmrGRkcDtwHxE+rN7ndJodBBtgIgZ+6FzyWe1qsdNH7F46JL9B0bmTRxdy+Gbo6M7sdNNPA="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.3.0_0.5.1-alpha.2_1684337576286_0.4810638846381321"},"_hasShrinkwrap":false}},"time":{"created":"2022-05-12T18:01:32.566Z","0.1.0":"2022-05-12T18:01:32.777Z","modified":"2023-05-17T15:32:56.678Z","0.2.0":"2022-05-26T20:32:33.126Z","0.2.1":"2022-07-05T19:58:09.685Z","0.2.2":"2022-07-05T21:45:45.492Z","0.3.0":"2022-07-11T16:18:27.790Z","0.3.1":"2022-07-11T19:43:42.934Z","0.4.0":"2022-08-01T22:12:13.215Z","0.4.1-alpha.1":"2022-12-14T00:42:54.747Z","0.5.0":"2023-04-28T16:56:24.592Z","0.5.1-alpha.1":"2023-05-17T14:09:54.651Z","0.5.1-alpha.2":"2023-05-17T15:32:56.539Z"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"description":"Policy pack implementing CIS Amazon Web Services Foundations 1.3.0 Benchmark","homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.3.0"},"author":{"name":"AutoCloud"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"license":"MPL-2.0","readme":"","readmeFilename":""}