{"_id":"@cloudgraph/policy-pack-aws-cis-1.4.0","_rev":"11-a6d601124d6739268ae32a690204a094","name":"@cloudgraph/policy-pack-aws-cis-1.4.0","dist-tags":{"latest":"0.4.0","alpha":"0.4.1-alpha.2"},"versions":{"0.1.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.1.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"640c6f930e605ba6a5cc7526e596b977d316aa3e","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.1.0","_nodeVersion":"16.14.2","_npmVersion":"8.10.0","dist":{"integrity":"sha512-gd1Lbyhh17LJk1g/qWw5cH4dPTlTkbdyysviYdjNFWit9UAsbNal3zPwz++gJo4kDX3vLX9X+IkPEeItLBKV2Q==","shasum":"11984c9ccc69b844ec22cfacd6142107e8320b1f","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.1.0.tgz","fileCount":64,"unpackedSize":324248,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC4IC2KCQ43QA72DSloyKLAOqKUo/b50k3/8w/zRBOxpgIhANke33EVKo/vF3eKwLomMsFRqkms4+n2GqrKjFAkVXcX"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJifUuYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoVLg//Vda25NOzkwLiYf86g1YspCdMIX+SpkgssDYU8uCnRIUobVGH\r\nbbDzQ9MTlFiJ5VLt2dahs3c11QSMBVYgKL25UmSo4e4Kt8ifSLLAktOnVPbU\r\n3KAzABfAlWbIElWTEHekegnWLLgDiWhXJ8o3GE1D6nHyuSc8cb0KSCr+tOpZ\r\nhGjH9fhltle0aBPL/reXh2iuLkXi04rg5rVxhL45z295zX9qr6LaGWRJ8DIY\r\nvLCuCI5jWlEZ48D2DirxLPqkL0Cs/Ad4KUZLdvK6vzgw228rD/uD06NCkJJl\r\nYaNQpbbBHuxv6oJNflW4FsBiHx2EYGvCI3QV6z11DleXrM8JFa12ujAPRmcT\r\nZ1Sjc+JnpHdb+5qyx8QpmEtuNYNbgJYlBJOMp5OoUfGZnbo/c+v0OvXK6ztR\r\n4FeUhsQ/rtuzX+hXnnRE3/KEz3PtQlbQBa3kGSnkGXUbkIHFBlSsSd0FArJU\r\n5xYuXqt0hQJpj/rgKKV26YXORJx/GhEyhsPLT3QtfYkeaa1YhXpuwIixRnW6\r\nuZdjEATf0SbT9OpipUcGCoUgSzyDIs8Q2B14wxwZ9Y+h1okKG/zBT8ohPpR4\r\nGjAmr1hhad6iSZSzeZSDNyK4JmORXq7BKJtmhVOEHB8LOqCofqErcRuqlRyb\r\nJZnpLLsX/Gf4dc73U1TJ3/u6EJYVIs15+wU=\r\n=BEJj\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.1.0_1652378520484_0.7644481217904877"},"_hasShrinkwrap":false},"0.1.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.1.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"ee4a811581b5c49f8ec50fa73e085de76c3aa26a","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.1.1","_nodeVersion":"16.15.0","_npmVersion":"8.10.0","dist":{"integrity":"sha512-LNEiKJKVRLTOQm3vjKBIHeRAYDNPIe86FfkuDsNKiUiRvk+N6tx02jP7YBCNjapVWbnVoPj2K5GqjXRLq0ICgQ==","shasum":"2615c55ed7c69142bcc4ae373e96051b03c266d6","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.1.1.tgz","fileCount":64,"unpackedSize":324674,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC9wl276Pqe07z+xXcViDj4rmHm62PYzqC4QTm0JeLoSQIgPxPVH6OzaFhS9aW3G1nOcvAiQewftqxui/6M4DrO12Q="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJij+PwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpCHA//YN11uWTcJd3Vf6vprCOSCvu8zvIfRx7RIkTp4PTfQ5MZWWXs\r\n2HyW6AwWYgwUnlIgCBuGE+QCY9zzbZtFSbYzsZm9MH34p389afkGp19kYeCr\r\nbGOM6b9M0t4E6x9XVUyW4PytXfLvvARV5sQ9koUcaMzQh1WFxOHghDqIVL1s\r\npNg7ovAwhv/SNh5QFQuYGXK6EkJJb1FiigLLEta/cTVlOJfvgYelp91Zq4I/\r\nFZ9YrOdj9qci7yyZ94XcejWUz9uKPH6ipYVi6tdujZG8eKSIAOwpfAK3jgDu\r\nibBQGlbqpmCNMpyBivijrEVUeY8WeTyuAZ6q6c3ceCkAVl7aYFCgqbgbX6GQ\r\nvz4F6Ty+dHX4ILhoMPsDkJqsiXVbzoBCZv71pOkK8cGdYc3uBVczRSAjHipo\r\nQWftlpsc46sJx7h5S5bTkUZi7aP2c0cK2ioCU0XnJ9AGZlk/Lxun9VlzfbIL\r\n14jKZhbitsv30UQizqsA/jWa+igJ8odueY69cGPDkAF6ZDfrvdI8kgjDKB0s\r\nb+IhT/KCUMfKIi/L6AQC0IPvGZ6qeOhqGsnz5ov51SfZt7AwWzw2EtgeBCw+\r\nw/3QoiyGOf+46coFTZsh8qtIelm7I73+rVmG0iIiLcjqMMxfurandupI6Hta\r\nwfa4uLyVcgOyaAwIw50ab/xGUGAmEV6eKx4=\r\n=/ebh\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.1.1_1653597168457_0.2001629163484313"},"_hasShrinkwrap":false},"0.1.2":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.1.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"0a3278eb6efb547a18993b5a675e9788c399ecfb","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.1.2","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-hPSkITutUIHC0Q1fLfpPtMchKB1amrgaw5nCnAitHdBoQjVDtu0Ofov9nCSt0MqWmajc81XIo6GODUFWod8Vgg==","shasum":"71729edc78580bbf0308fb93258576affa606318","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.1.2.tgz","fileCount":5,"unpackedSize":15469,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFtrLIenf/YiC6IJyQ/sGu8JMPWtEVJ03sSIK0fiM2HDAiAVXry8/p7/pITwvl/ocvwDeYlp4ZxtjKOb46MdU3fxKw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixJf5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo80Q//auKj+83HNja48ntyX7FoQKmNpmjDZhnjjvyt2an17jfosIOS\r\nBbMFPnfaQslXjdSYVvRSvC+bxaNHCnwoieboYLe84HplX6ORwshyR2rrfl3K\r\nWrpPxNma99+1mjk4LKL6ABZTvxnqEmAqOxo9AtW8pyR0agrqRSYZClMgxTYr\r\n6T5lQclG6D9l+edD4EFblQWnbDre2Qtc/6mTxfnsVHlWM6Skc4NxyPwOuEUp\r\n6HlsedUPaJeZR/Ynd+pQ7wJ4afwKprCka5cZ1qQ19drWmD4/lry5B900R8z7\r\nGLmxdoktD8uz9qtibrJaTN1T3gQFjTgUmDcJYoIAKyLKvHtwOMehKw1mfa7v\r\nQjFuOXG2eR6kkQ4QuRliJKj3iKjOBNEjtaZJWF5yOpLZ7UcWY45f2ttcpJzW\r\nUnqqx12SQnH1UajLquHuw6K/qQ/yRA+ae0gM8qYmWBQyEOVT/PZCAc2vpudL\r\nAd12QkgngjE9IliuKpA9E7JqkI/AiTtpLT8J+fq63qCnxfNqJ6RDTA6pj3n8\r\nctVFZmh2NqW//lBketrMnI0Am8GBJGAvUCVLUKBYpvMQhr8wDqe5y7QhKH11\r\nEUeI3watwrUppZGS3MWj71MYStQHs59CBPKawbo2xekbS0xYhBkEz7GADIWd\r\nKLGZv8DaReAdR2qPWyrGQjsPRIk+n127Akc=\r\n=RmYZ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.1.2_1657051129014_0.9568984898812225"},"_hasShrinkwrap":false},"0.1.3":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.1.3","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.1.3","_integrity":"sha512-GDdXxWC9cAhkRupu1gd0EKisAYhftd2w2tgAwU7yCijYoPq7gqkDrsCeo7Gu9/ffSfc20S3V5eOy3AtdbcC9sQ==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/9e52a5b22c8c4711b45fd7cd2c136838/cloudgraph-policy-pack-aws-cis-1.4.0-0.1.3.tgz","_from":"file:cloudgraph-policy-pack-aws-cis-1.4.0-0.1.3.tgz","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-GDdXxWC9cAhkRupu1gd0EKisAYhftd2w2tgAwU7yCijYoPq7gqkDrsCeo7Gu9/ffSfc20S3V5eOy3AtdbcC9sQ==","shasum":"2f95aca9a721d7d429bb1c4c82aee2a27d793f0e","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.1.3.tgz","fileCount":124,"unpackedSize":394653,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD16Y/97GDknMdafe17myL3qQk8z9x8HMIStsfkSJj0NgIhAOvqBc1LfDhrzUYITVzmKuyQoNOnp0eHWU+5+LJhEJAF"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixLAOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZJg//UVsTCLRslrUn3f95TSdsOvecr0kREOdIh88Zg0ZLYQ/n98Tp\r\nhU5zgfLAM9eMa2PH2WcfBbW05nQCVHY4fZ/shcnxsbR8fALwYutti+Rgvgt0\r\nFsf5Ftsy1JSsSUgYg/K3UoZ3+fHc728pTdaF+vNAljp1RDNk1LsHh1pHwsvE\r\n52pgxovE9u1OIhMfBqcHfeESU815/wAj5g4WNAKCLDiwUhrGgrWvSUOnOEjJ\r\nt3uXthfoMfwdwiZNXYN3qVdq1159bFKlAOsMOurN9OwoPZu/KJxU7lbmHlr9\r\n43WXZ6d2LhZRa0eg3cOyU4AjPT+e5O2YkA5C6VDo5YjdNTp1VFs2IlEiFiHH\r\nu1AGiNT1GI3/ad7VRG24XsG3xKvRDRf2GEyl4yVfrSfi7rE6/CmPmKJnNtdv\r\n7huGk9vYw5+0m3gZCDvSIo75cd9IvsVO8yplGOwNlLbC/xL7ZW7u8MNbwaFp\r\nxstEkFpQ+ZYSIquUKqWCH+b9kGNnhyohhHIa/zBpTay33MgcOUtlC7QANvP4\r\nYp3SZjypYPacAFRYHQUD0XZDnA9O+YQVYyQGybPALSIQFWhnUn8K3RDwoHjP\r\nhVwcMpXMjt2dduJjRNOsNOPMPoR0Opp9AZw+HlSPTQqkKPenFpDfnsfJBfG0\r\nNtUV9xzuLQ89iLjNVu3+/+Zbs/Pwezn2cLs=\r\n=9PEe\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.1.3_1657057294358_0.8588593882079083"},"_hasShrinkwrap":false},"0.1.4":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.1.4","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.1.4","_integrity":"sha512-EteZO3MDJITvuO/oo7N51MT8sug6DvT07ECYKyOK/qCclfr4/wEGO7u4LawzWdQwE4AA2MQ0ElzyCKxgmmYzvQ==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/bdb076f5e34dfe1064d5118278580b23/cloudgraph-policy-pack-aws-cis-1.4.0-0.1.4.tgz","_from":"file:cloudgraph-policy-pack-aws-cis-1.4.0-0.1.4.tgz","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-EteZO3MDJITvuO/oo7N51MT8sug6DvT07ECYKyOK/qCclfr4/wEGO7u4LawzWdQwE4AA2MQ0ElzyCKxgmmYzvQ==","shasum":"d199a8f961fb5a8f6f292ddfae331e747084efcb","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.1.4.tgz","fileCount":124,"unpackedSize":394653,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDwdLuNWpszOI9s4FeoH92SATkiZfvKdykpFde1ugKuzwIgaAz46QvSD69frlGyag801DWWjgI3OahNirpGOdM4hHA="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixZZsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoA4g/+NB5bDanjvANTBOudWKPbiQx0LbTCg6wlHN9qMDiikdABe0a0\r\n2RBzYPHqPLbusD7vJpUGofDqs/dwG2+7Eg7zY+9zADvIk2J96ctrQKQlWkUN\r\n/uJrYL0Jj2+Mfr858s34c8T8V3HVBi91XTaaRu5yU9PQkUn/wuwotIoZ85NX\r\n306qhJnrYk0Txx7dzu0clUaVSBTPTEWN2cIE/5FH/DVoDLrjl5HcCH/NV6vz\r\ns+F44aDR7JQBEkTXgRlLHFIXo2nnUdiHDtQVbr+R0iJkW6FY6ODiNTB46fVr\r\nMYWNZUMNuFeHiJ9FXNScf71eWdDPIKCxGBbWUFMEcdG8IMQZzaxy2flchBpK\r\n8uUpI8XMYOoc2kFNOLkZYj76LdTYgTuby8g5jYdyih6SCpi0ZzbrfPHwJFlM\r\nDsObk4PHdluupo6z7zWFDppNaaccORS4bAKbu/cF169RAFE0TXsSzqaIFW/t\r\ntJ/3iti3CCflMVQPROGt/o5dJWaMsVlSbsENZYWHWjq/jnfP84H3KvyLjJ5O\r\nNtl2AoIQoTA5FyOZrj7Fe+TDiYt26NeOYybzs3zKVontkobZQPMHXpCawxfq\r\ngplfcXiZkpAolJwWcARYItf+WDvtNjRj6Qfj7vYfxCfovzazR4lswR75Na5D\r\nmNgwfoo9GHoEgp8//tVJ4ufL7CLq11ARpOY=\r\n=i/Hp\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.1.4_1657116268043_0.6886257822885213"},"_hasShrinkwrap":false},"0.2.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.2.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"ba137102b96ac4ad9b63a3a3ed6fbf48ddb770e4","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.2.0","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-AWxw81R+6hYNz7JvF4c9Wnpvzva5ysxFyrq4lLPPMSqghTc/onTHtikZ18SsZgO6Fu+ze9qNgkQ2neSbWayA7g==","shasum":"dfcdca4a7a6c03d2f9adab00eeb44e63a271292e","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.2.0.tgz","fileCount":64,"unpackedSize":45949,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHVT2GpnFQLoh81NFiq9nargHXF1r3AdBOltWbqqm7KOAiAYOdSjJLD+oD0AgyU16xKDhELGi1bzh+pxfToNtBQKiQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizE9tACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMCA//Q3K064eqn3tN2lZ/2YLtfBr6Mq7/33UI5upzMEwQuJ7X5GGN\r\n1S66mCyKCOeZBXt5OurybU8c7ACbXpd4yYQ0Rbx48pmZBNiEEVMp6YXLRxJO\r\neqaOMU6HIx8J2dtkPw8SkbpF2/h/GpuuPbNdVPLH4Hab84hRmlE1Wpz7OmXp\r\nF8W9DySJyMEt03FPNCRQP9Wrzz+nIRXjL9s6r33h127X75miQzrC2X44zT1D\r\nHZ3lT+fyn27JBUUyhTFM3UDNyQpNLyiSA882p5POUo4PAJ48ptgYSz8a4G2a\r\nczx+SAktO55RbPReX0nrPmFj6qcDeD+KuFtlj8xxh5pd17GYBsrc3BJ4tDZE\r\n+SPu4rWo9VthKMmu2fx8rIryRA1DytJVSKINrCL2BnxmX2cE3QLiyWpoXvSB\r\nh84bmQTzOHapTKE6unglWnchWiq5vEQ9+AkDWWsbab1K4RrrdshXugJdlhAY\r\nJriIxWZ80CiHSmFjW0oKBixAq4tuxcPjqGUp8LR6xCbE0RKe9y0gUyzwD6Wr\r\n5CKH1Eubll8mLtErp4BUBbjDVDPl3YiteUZ2VrLSZonxO7S6iwZY++cR7JcG\r\nThsvUNx/1mTlBdANbAIXYTDkEYl3bM7rBIcT/O+k/R9RRdJzw6FnwwLg+tT/\r\nQSJQTQR4ad/LeEjLia34VEM+8A6m1DiR8JM=\r\n=w/B9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.2.0_1657556845673_0.22151916659241744"},"_hasShrinkwrap":false},"0.2.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.2.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"adcb2bd928697a61ca266b13bb76ccba61b3e2fd","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.2.1","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-/yw4TOyfeRwBviePl5v3LTroC5Du5ug7U9ibDQKMVhV+jmJ45goIdjhqMBnVwoum4EkePcfuSSCagKglFnHP0g==","shasum":"df45a4d55827d5cc2304a206bf1f3359f9d9e957","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.2.1.tgz","fileCount":123,"unpackedSize":343748,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBPm9GjVvqI3QRaYMDciO74Y5SCP8QZDBsuqQ9X/qWy8AiBBnlP9nO4ocaHak9i/TA0cszu5cUuqu9Xjtjw2JMtDPg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizH32ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq/ew/9FT5xGIBO8TVJtHWdd8BA3VZgfWvsCrbmAjQOhJeCc3AhLyWN\r\n37jR0JEFVPD6GSm99LwQ44JqAbs3Hs+I0geK2OZppg0kg8b0TTCGkQksZwYQ\r\n9y7uWBfUX8+YzASrxwiwV52YujVeGVG2TwIpD+ml7bEXNnIKIGaPTeKw/yYw\r\n6f/LFJwrj3plG0xZfBOesMlaWPfyl3Up5U77CXOOcDsso7odfUSbNlP+7QW/\r\nAhNqtwI4I51Yd6yMFq+XoxNHnsLvniuWhOwNvHc/AhJzZtm4NvTv3pB6TJNl\r\nxk5I7mT8TInkQSPCuVDfH7xXvZ7LtZS6nWH7qYHJTMHKOcDVBzr8nlpaaAFL\r\nDpWzhq6BR5Cj8gnBGl21zpJIMUjYDqhkey6ySkD7Jx04/ZMsaybHxXUYDA06\r\nrbseTXHuyuyIjcMG+XO4g0QtloyY/l4HCYMeuNn/FJVvjIz67U9C6L4yqpUq\r\nGC0FQNuMUki01X0dXI3LbT8duw/8gfw12sbie1+wQs2LkKtC1VBqv77DvKqy\r\nYL3m4rX5KQkoDR5vJVG8lUfWl1Lzd+FjqxYdv4myLBt8ZyqDXZKbUYPvln2S\r\nzJpRGG6Q7CYeYBThEv4kjGiwNFhLG9M4b3uUNHFVYmaIfZ/PntyeU6ymIeuO\r\nsa8JjxM5DLcApITiyvg2B46gFcLPTYV32CE=\r\n=gkYU\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.2.1_1657568758687_0.8937180685398247"},"_hasShrinkwrap":false},"0.3.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.3.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.3.0","_integrity":"sha512-+x5Nz8kpnj2eEQQxByO9XLtMrbg/7XeMnbNBdRbeRSsJBTDn66PPBry4O8mavOfP4ZVA6LE8Zrnalv9eh1y+xg==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/5fdbfe2e48df7bac41a8ca83eb39dc82/cloudgraph-policy-pack-aws-cis-1.4.0-0.3.0.tgz","_from":"file:cloudgraph-policy-pack-aws-cis-1.4.0-0.3.0.tgz","_nodeVersion":"17.9.1","_npmVersion":"8.15.1","dist":{"integrity":"sha512-+x5Nz8kpnj2eEQQxByO9XLtMrbg/7XeMnbNBdRbeRSsJBTDn66PPBry4O8mavOfP4ZVA6LE8Zrnalv9eh1y+xg==","shasum":"4c16955b8eb49a81fed455e086a9dc1d930ebf3c","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.3.0.tgz","fileCount":124,"unpackedSize":360075,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGPA/2GBcTaZ/dukAu42DLha22A6/bX4NlUD6EX0JGAnAiBykdDCRtEYpRM99pd8hO9Tw2OhjJw2O60ldgkIot4v/g=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi6FBdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8wA//Ubfq7YEZc2TJ55HuB8LacEs9leKlyROJhG2Ha2Lieah83CA/\r\n9cdaEGAeuTiAYqeFc4N7ehxQe0lUUjefiqG8Jw0CzkoarArf+jIy49ESVN4v\r\nGcUR0lKUIY/1tmlu+wZzEkSNMPwFSBitEfzO5uvChhPls9UHu4e77xxGpGfG\r\nPAuK4FzWfvBCO1uVIa8OoF4m2hLIebnDVQ36O9VBLdbuq1L/eJZ/4R6OAkFY\r\njtYc1g6ou24Xq8zmecmg66yDY7YFt9NRK03YcUfH7RvDnz1iSW1CkB/IKO/w\r\neUla4GxKu4vGmUqoda4wxrzNhJaTqS2u+LR38JO7q25B4U8MLdlQsSmmroad\r\nNVby2C/63j4MLKJ4+BM9BV7htb4c8sOhD5c16oYiVSmVry5f8XqfhaRBXqV0\r\nlHNWR0pSTH2RwFlHQJBaad1qqf2ULdNmbmtLYubkB69gfNP6y+X9SGeTnInR\r\nW1yRh0m4kPllAUdfFW/5oJLnmKzWkxx2xhJsOEdRkIR2jN0FdHr4rt4e4UXR\r\nFPn/Rx0INaXzT3/qkqVnSgxwjLY4zWvKuH18+ykXJtFW1/ZAfFAEIkvedeAf\r\nTcKMzRyfnY1NafMxFHKe/Z0ip7bWon+XmjuZP5aPnHa9m6IaGf5mDI6XU+0E\r\nrkqsYtn3sSrMKyWgcAD0fEgZO2sv246OeUE=\r\n=hwjI\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.3.0_1659392093182_0.7309208568653895"},"_hasShrinkwrap":false},"0.3.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.3.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+ssh://git@github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci -e semantic-release-monorepo"},"readme":"# CIS Amazon Web Services Foundations 1.4.0\n\nPolicy Pack based on the [AWS Foundations 1.4.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-4.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.4.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root' user account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the 'root' user for administrative and daily tasks                                                         |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 45 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that IAM Access analyzer is enabled for all regions                                                                  |\n| AWS CIS 1.21  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.1.3 | Ensure MFA Delete is enable on S3 buckets                                                                                   |\n| AWS CIS 2.1.4 | Ensure all data in Amazon S3 has been discovered, classified and secured when required.                                     |\n| AWS CIS 2.1.5 | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                          |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 2.3.1 | Ensure that encryption is enabled for RDS Instances                                                                         |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"57609f23120ab4788e103afa74682af6d42eb456","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.3.1-alpha.1","_nodeVersion":"18.12.1","_npmVersion":"8.19.3","dist":{"integrity":"sha512-a5gqvEA9P6pGbRx32cDnaKT1Cm0P2JBV1LiZJrIbMV8ZMooWfXuFyrOZy0gUn8UpNPYtqgoMuoPfyWc1t9A2yA==","shasum":"8f5a8755378c934b7ff8d3e0d3c3f632a9035f90","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.3.1-alpha.1.tgz","fileCount":123,"unpackedSize":344633,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHLVhj9jX+LO8m/5FmisfLtU3dQhcOZUNo5BCZrSapmzAiEAkIyVg0IxAVR82dXvRr+iGdVn0Ho5sfg8cvY1sjygxjM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmRwlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq6Jg//YwRkP1Rer7vg6PeOo1lZGa/K5gTvu6tKa98NJ5j2B/GSvr8n\r\nCKDgv85YUGSlg0YGnOKPiWAhkUrykIZGGeOl2GIdJS5bRfafehq91sCQspv7\r\nRINu8uFr5txI1+iPia3DJkhzt1RrwcdgCCiH2XkEj2K5rcZAdSFCjkZht9WJ\r\nH2/4kxHFpItZ9GA0GEpENCJM+zy2CrLCAyx/qi1PZ4o6wiRaIGbMN7qBlNSX\r\nlvOZluFEXeSF5XElPg3P5rkV+OlYLOE48sa+5Fb2qIi7WHkGW9pqMKbWoCrO\r\n0dxMcHYs9evZizVx1lCXWB5GcNWpWE414kFFumBUUD0FcwTZfHdAbvQ633nH\r\nDWp5RBHYhscLHTMAg7XKY89w4lLg2jLJ7kvoLD2pZouvkFhQKtTX0tzXGXNG\r\nSxm7IyHCbbL5TmMMccnI0GDbiPEWO+6L45QbWfssisQ29df8Wtw3dlE4hh5A\r\nVszB+wD6TxxcO6BJV4MVhQ3tAHELrjTqs3RTByV0CkD6Sx6yeB1vbNAWl7Gs\r\n7YbuaqdyUlnFSFfvGvBIW0HAJezKaNmAaTsn94RLDDXTDNfNTs3xtjzjBoHF\r\nXIjob+/4oxIGbCDR9u9KJOn6mZi5qTKuT/dG3E0qDae+q3eUm06kZ86wAz2X\r\nlz2MJ5qPG17f5QNjttshjX4vVh8e+iJWdik=\r\n=fIZZ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.3.1-alpha.1_1670978597091_0.9501263110779425"},"_hasShrinkwrap":false},"0.4.0":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.4.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+ssh://git@github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci"},"gitHead":"bcee02a33e52bc8ffde0651f3e8251598d70a61b","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.4.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-T5JZ3kfRiypgW1O2Pj2elIMc7jmCSyNv0W+GcVnIenjpfhZWopsqBRTxZhETZhHAd/lqUVGs/gjjm4OBD9JZAw==","shasum":"151e64b1105ee5210f42156b966faf9854508009","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.4.0.tgz","fileCount":125,"unpackedSize":360451,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAHus0dmAdmDbiffqkccPWDarrHDzReVSiTfObcG6MHuAiEAzvVpzSEbQLimXjkoMdlAejZL+nFh1zL3b1DwuyHP9TA="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkS/rOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpsCg//STSsiJrGlu9jdBU69ZSVYg3QnR7oitPqZfTPptj20CJuLDGE\r\nJ69loQD6spyYUyM3pfSuVFkLjGi13Fbr4HElBuZaBmNBb8XKCwjTdWPWp90d\r\neZQHuGADvBA/qdtIRrq/qt0z8mwHo0UT7+thRBMHrFkn1EvovLmJVjU061vc\r\ne2lCmJUYC5jwNK9oa1HNh8HK63BzFujFHgDL5DN1GkC0fNbH/J6ahqFNXLIp\r\n3qt+n3VL0s9pqWc1XqP/zAXXcPxKE/TyNW2TGr/weW1kI9eneQ2O43JASOqp\r\n+N8NpovKp7PXt9Vvo7Yv1TozWPDFqSA0+XykgB2HFO7Z75jUGmiYLi+FFtTr\r\nvkHc3wCjj4N8Jd4eTjZ+3dWq/BvgKvq94fw+w5H+J99gtkhWkBwCKMzlKzYY\r\nwW2xJMOcjtz1LeqYuQ+73r3sL49jxbu0+QozMVcr2WNp6liQR5S/h+KRfclF\r\nAYDpTxZTXStK9o4vk4WJGDXcXGMttTPvHJLPzb4aSI5dvoVi1xYTURu+8Nso\r\n4os/Iwo6pAOUgLhRsag4D0y8DYo/KLsaeSqzyKXQVv21kIlzaOOnsMT6vS+R\r\nLw/olbcL4P5mS5LLOnaMCKscG6ZXAUPTW1uGWTwzt9RDphF7OOKgd2KTX/1X\r\neBnZdDvgvi6VNx0T7f2OuN/NUFw9iEOG9XA=\r\n=Wwhm\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.4.0_1682701005770_0.8540748007516381"},"_hasShrinkwrap":false},"0.4.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.4.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+ssh://git@github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Amazon Web Services Foundations 1.4.0\n\nPolicy Pack based on the [AWS Foundations 1.4.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-4.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.4.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root' user account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the 'root' user for administrative and daily tasks                                                         |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 45 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that IAM Access analyzer is enabled for all regions                                                                  |\n| AWS CIS 1.21  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.1.3 | Ensure MFA Delete is enable on S3 buckets                                                                                   |\n| AWS CIS 2.1.4 | Ensure all data in Amazon S3 has been discovered, classified and secured when required.                                     |\n| AWS CIS 2.1.5.1 | Ensure that S3 Buckets are configured with 'Block public access (account settings)'                                       |\n| AWS CIS 2.1.5.2 | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                        |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 2.3.1 | Ensure that encryption is enabled for RDS Instances                                                                         |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"058055e1aa9d09015a3c53cfdc651609501c842e","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.4.1-alpha.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-Ep50YEKw55EJaTbiMUUhiMbGF71PLqO60/lXJziyV6wKymVzzRWYi26ACf5t+DQiEtzJAXguqOYB8A6RKae37A==","shasum":"86b687669a2287e3643c41c4d81799da777ad807","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.4.1-alpha.1.tgz","fileCount":3,"unpackedSize":26366,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDAif2o54RHg503vs1DuVugJhlTZ14PHLcRbX0H8g5AQAIgf58ApNvMP4Qm5uHDwVgXlV7Diq3yyCgBVCA2TOy2eYA="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.4.1-alpha.1_1684332625716_0.7960668436277796"},"_hasShrinkwrap":false},"0.4.1-alpha.2":{"name":"@cloudgraph/policy-pack-aws-cis-1.4.0","description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","version":"0.4.1-alpha.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+ssh://git@github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.0.3","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Amazon Web Services Foundations 1.4.0\n\nPolicy Pack based on the [AWS Foundations 1.4.0](https://docs.aws.amazon.com/audit-manager/latest/userguide/CIS-1-4.html) benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/amazon_web_services/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack for CIS Amazon Web Services Foundations benchmark using `cg policy add aws-cis-1.4.0` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                 |\n| ------------- | --------------------------------------------------------------------------------------------------------------------------- |\n| AWS CIS 1.1   | Maintain current contact details                                                                                            |\n| AWS CIS 1.2   | Ensure security contact information is registered                                                                           |\n| AWS CIS 1.3   | Ensure security questions are registered in the AWS account                                                                 |\n| AWS CIS 1.4   | Ensure no 'root' user account access key exists                                                                             |\n| AWS CIS 1.5   | Ensure MFA is enabled for the 'root' user account                                                                           |\n| AWS CIS 1.6   | Ensure hardware MFA is enabled for the 'root' user account                                                                  |\n| AWS CIS 1.7   | Eliminate use of the 'root' user for administrative and daily tasks                                                         |\n| AWS CIS 1.8   | Ensure IAM password policy requires minimum length of 14 or greater                                                         |\n| AWS CIS 1.9   | Ensure IAM password policy prevents password reuse                                                                          |\n| AWS CIS 1.10  | Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password                          |\n| AWS CIS 1.11  | Do not setup access keys during initial user setup for all IAM users that have a console password                           |\n| AWS CIS 1.12  | Ensure credentials unused for 45 days or greater are disabled                                                               |\n| AWS CIS 1.13  | Ensure there is only one active access key available for any single IAM user                                                |\n| AWS CIS 1.14  | Ensure access keys are rotated every 90 days or less                                                                        |\n| AWS CIS 1.15  | Ensure IAM Users Receive Permissions Only Through Groups                                                                    |\n| AWS CIS 1.16  | Ensure IAM policies that allow full \"*:*\" administrative privileges are not attached                                        |\n| AWS CIS 1.17  | Ensure a support role has been created to manage incidents with AWS Support                                                 |\n| AWS CIS 1.18  | Ensure IAM instance roles are used for AWS resource access from instances                                                   |\n| AWS CIS 1.19  | Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed                                              |\n| AWS CIS 1.20  | Ensure that IAM Access analyzer is enabled for all regions                                                                  |\n| AWS CIS 1.21  | Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments          |\n| AWS CIS 2.1.1 | Ensure all S3 buckets employ encryption-at-rest                                                                             |\n| AWS CIS 2.1.2 | Ensure S3 Bucket Policy allows HTTPS requests                                                                               |\n| AWS CIS 2.1.3 | Ensure MFA Delete is enable on S3 buckets                                                                                   |\n| AWS CIS 2.1.4 | Ensure all data in Amazon S3 has been discovered, classified and secured when required.                                     |\n| AWS CIS 2.1.5.1 | Ensure that S3 Buckets are configured with 'Block public access (account settings)'                                       |\n| AWS CIS 2.1.5.2 | Ensure that S3 Buckets are configured with 'Block public access (bucket settings)'                                        |\n| AWS CIS 2.2.1 | Ensure EBS volume encryption is enabled                                                                                     |\n| AWS CIS 2.3.1 | Ensure that encryption is enabled for RDS Instances                                                                         |\n| AWS CIS 3.1   | Ensure CloudTrail is enabled in all regions                                                                                 |\n| AWS CIS 3.2   | Ensure CloudTrail log file validation is enabled                                                                            |\n| AWS CIS 3.3   | Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible                                               |\n| AWS CIS 3.4   | Ensure CloudTrail trails are integrated with CloudWatch Logs                                                                |\n| AWS CIS 3.5   | Ensure AWS Config is enabled in all regions                                                                                 |\n| AWS CIS 3.6   | Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket                                                      |\n| AWS CIS 3.7   | Ensure CloudTrail logs are encrypted at rest using KMS CMKs                                                                 |\n| AWS CIS 3.8   | Ensure rotation for customer created CMKs is enabled                                                                        |\n| AWS CIS 3.9   | Ensure VPC flow logging is enabled in all VPCs                                                                              |\n| AWS CIS 3.10  | Ensure that Object-level logging for write events is enabled for S3 bucket                                                  |\n| AWS CIS 3.11  | Ensure that Object-level logging for read events is enabled for S3 bucket                                                   |\n| AWS CIS 4.1   | Ensure a log metric filter and alarm exist for unauthorized API calls                                                       |\n| AWS CIS 4.2   | Ensure a log metric filter and alarm exist for Management Console sign-in without MFA                                       |\n| AWS CIS 4.3   | Ensure a log metric filter and alarm exist for usage of 'root' account                                                      |\n| AWS CIS 4.4   | Ensure a log metric filter and alarm exist for IAM policy changes                                                           |\n| AWS CIS 4.5   | Ensure a log metric filter and alarm exist for CloudTrail configuration changes                                             |\n| AWS CIS 4.6   | Ensure a log metric filter and alarm exist for AWS Management Console authentication failures                               |\n| AWS CIS 4.7   | Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created CMKs                     |\n| AWS CIS 4.8   | Ensure a log metric filter and alarm exist for S3 bucket policy changes                                                     |\n| AWS CIS 4.9   | Ensure a log metric filter and alarm exist for AWS Config configuration changes                                             |\n| AWS CIS 4.10  | Ensure a log metric filter and alarm exist for security group changes                                                       |\n| AWS CIS 4.11  | Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)                               |\n| AWS CIS 4.12  | Ensure a log metric filter and alarm exist for changes to network gateways                                                  |\n| AWS CIS 4.13  | Ensure a log metric filter and alarm exist for route table changes                                                          |\n| AWS CIS 4.14  | Ensure a log metric filter and alarm exist for VPC changes                                                                  |\n| AWS CIS 4.15  | Ensure a log metric filter and alarm exists for AWS Organizations changes                                                   |\n| AWS CIS 5.1   | Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports                                   |\n| AWS CIS 5.2   | Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports                                |\n| AWS CIS 5.3   | Ensure the default security group of every VPC restricts all traffic                                                        |\n| AWS CIS 5.4   | Ensure routing tables for VPC peering are \"least access\"                                                                    |\n","readmeFilename":"README.md","gitHead":"e8e611b009c8ec979f5e99075610f2a47991f504","_id":"@cloudgraph/policy-pack-aws-cis-1.4.0@0.4.1-alpha.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-CwKTES6TavVXdsRuaEgzrliSB2hNhDGov8UH64m1/m/ZFtSHgMSvprJ5tCZFBRNv2zVBWWiy1wYeymAi34mdUA==","shasum":"a9d070b46c5afeb266c5ef1a7cc8c3dea61d73c0","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-cis-1.4.0/-/policy-pack-aws-cis-1.4.0-0.4.1-alpha.2.tgz","fileCount":125,"unpackedSize":361218,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDw7QHV2gd0R1Yh7J59Z4Clfvs9xRv2VvJ4Rz2bR79OUQIgd/zYM1vHrnmWdMgWeUab4GfhTr9VsoJRcfpUYGL7pbs="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-cis-1.4.0_0.4.1-alpha.2_1684337594341_0.4318836287193173"},"_hasShrinkwrap":false}},"time":{"created":"2022-05-12T18:02:00.417Z","0.1.0":"2022-05-12T18:02:00.653Z","modified":"2023-05-17T15:33:14.695Z","0.1.1":"2022-05-26T20:32:48.652Z","0.1.2":"2022-07-05T19:58:49.188Z","0.1.3":"2022-07-05T21:41:34.544Z","0.1.4":"2022-07-06T14:04:28.256Z","0.2.0":"2022-07-11T16:27:25.834Z","0.2.1":"2022-07-11T19:45:58.853Z","0.3.0":"2022-08-01T22:14:53.452Z","0.3.1-alpha.1":"2022-12-14T00:43:17.313Z","0.4.0":"2023-04-28T16:56:46.007Z","0.4.1-alpha.1":"2023-05-17T14:10:25.869Z","0.4.1-alpha.2":"2023-05-17T15:33:14.561Z"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"description":"Policy pack implementing CIS Amazon Web Services Foundations 1.4.0 Benchmark","homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"repository":{"type":"git","url":"git+ssh://git@github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/cis-1.4.0"},"author":{"name":"AutoCloud"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"license":"MPL-2.0","readme":"","readmeFilename":""}