{"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","_rev":"19-0cbbb15f84b3e605b67490a5916785b9","name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","dist-tags":{"latest":"1.9.0","alpha":"1.9.1-alpha.2","beta":"1.4.0-beta.1"},"versions":{"1.0.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.0.0","author":"AutoCloud","license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.14.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.0.0","gitHead":"7963a29d0d86d5f688962a5e4ea87cd7fa00ea9f","dist":{"shasum":"f8ad5598f3f2aeab8d83f3be62bf77f7225fc3fb","integrity":"sha512-N5/YkrkxyeihyU9oLnDfbKm4gWoRDQhljeywVNugDe19GAYPCqH5Y/eqkLSs3jo0sPg5Yfm1fXNp5hHmNgJbeg==","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.0.0.tgz","fileCount":7,"unpackedSize":4298,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiGSjWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpu0xAAhl6YHJaUeEafqqjHhEZixBtjQtcGqYli5xeSl0DBkK8id4zf\r\nfIB7k2YlzGmEENrt6zwCKxyrl6PwuVVHgzoy7JF6aB2WErb1H6vXwTXXJDDo\r\noDZhI/W6SiMHjOTDodCLvTuQECut6gvp9nTYJycDQc7OPTuFi0nCAYgu/fiu\r\nlR5QDvO2lKjrSO6H35m+IvyAA7OL5Qe3YAMVUzVm9bLhlbyVD+s4xWKy62MH\r\nUyfWDJMNO+WqRuAfWjx+eMQHwLpZz4P9+yYqWh57LwHZ4qkTITJvRCB8VB8H\r\nwpxHRryapMG0j/hBCOCKb/4+jZNDigGMJEoK34lAtIujFqvilbFer7AUasvq\r\nWzY3wx/onDpn3sfNVb9/Y1ANeDgGWJ8RrNs06t0BRA0fakPb8lM1quN3SKrM\r\n/cP7vwb1pY6biPUpLfeq69azRL45Qtv4gR31TdmSMmZw5tgpk/GpVczd92v9\r\nb0AOWFHdbIv71df6tDWwcejBGYzsbouqFxHZdQomOienNaBFlf1bwEkszMr1\r\nfrMMvG+Ww2Iq8yuDNF7CF14VZm0C0b6NrKCKQpDfQwLmlauOlIzgYbV0Z2Sf\r\nDAdLNcujEqCJizq5NEA9zKoAgxH4DVWU10ZEQT6ZhHpk9lu/sHNE1W+M40P9\r\nUelG58FkoEUNxhinAbx0P5LoooT9YaNFVu8=\r\n=0brU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC2ak6qE5HJBoIqjRoPv4oiLj2SLBPYyC279y7Ijsge6AiA9uDQ86/vAO1/ac8SDFwq3qgfuVqbR7jQYWTwHN/Dj2A=="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.0.0_1645816022600_0.9877675818554068"},"_hasShrinkwrap":false},"1.1.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.1.0","author":"AutoCloud","license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.14.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.1.0","gitHead":"74413027aefd6fdce36411c57d7aa7ef6697f0ed","dist":{"shasum":"dabcf07947507e570a71c397881c0c36bd24a02e","integrity":"sha512-iP/+Yn7AiL6kjXzU/aiYW8cdYzYUb0vhsQTYoKqGVpkRFRX9Pu2RZxCSNQrvVxW81F3jkkIxG+QTjPUT7lIrCA==","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.1.0.tgz","fileCount":28,"unpackedSize":79991,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCCaVi0u0IwaPSl2UY/rm6gehS9viugq6lffl9OAB6TyQIhALNnXaoKDfY9EjQ34tgA6V9Xyw3IFfB8WyyRfdZwB2M0"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRyUSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpR8A//c9LouIL1XRVnWZrkBrWyDuaoRFd2Uo3TEPOwSmF1YH42ytA8\r\neUHh7jzgEYfi54VHlZVhSAITRxcZZvkASOXRCm/hXxa21zLXgRQfpGFPRusM\r\nHh+LoJhJvodEM3LfYjBukN6WL1md5vIgxCwiCUuOke6A6WkMCyLKZf1V0TxK\r\nMjyaD1DAImS/A/Pxd+/u9Cw1Ucoq4VT16lXZJaclZd3ViMSedfm5VfbH/ZG8\r\nYb+/A84qb6JHPpgN/2QlIbUoiCvDnbczT81syLBzyXg3qdIfLMCi7eivA/BV\r\nV9Dj3yXKPKooNVF4HY9bDqbJN76d+cqxpP74K/SSnUp5MvPZs/H1KNceIWJY\r\nRBUJD77XFXG0ry4B3VFD6/DnPyVWwJ+HdiWidpGCLoilhSZrUx8QzJ6Y/A10\r\nUo8T2ek5I5By1+YM1eP0HnBaftEVWf2nA8XssgzJ5uvWvtnlrg1m+ds3q0/U\r\nwuPWOdxYh/42IhQQ8m2/+dRhU91C6j4IVLpdQkLlml7O3wZHH6TQ36Ew++lb\r\nfavvAfKlCj9y6oNNjCLWGEcFPsKj6NwXtQ09pHkQL7rCB5hH2mWyjwtMlCz1\r\nU9umOR720epmuoqqj49b0wIAQAe1PEPJkbUZAEkOmfzgi+ltsg5dyxqQpLOS\r\nv41qxtrrrkMdtVVDP/uJIURUz/rSFgE/ufc=\r\n=gQaV\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.1.0_1648829714322_0.1584997296897619"},"_hasShrinkwrap":false},"1.2.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.2.0","author":"AutoCloud","license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.14.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.2.0","gitHead":"60d19a322ec1421a3cd94e07280080190f740469","dist":{"shasum":"d1c49d280fc197442288062c4af0af750dd5e74f","integrity":"sha512-3o6x46CNF37JR0yK4qmHAltSvE2ykaq+oCSLJiybRwg4vS5/qfzh4HtS7pYISCMoDJoAvLWAtsWYBeyAG9+brA==","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.2.0.tgz","fileCount":28,"unpackedSize":80800,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDSTL3G2g7lIfop5Ra4Wl5PTWWzU3CtsgVS+gfXxxzHpAiA4Umdj/ZwwhaWSby7bCYji8KC1jNOdkQyOyg4tIRZnCg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRy3OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrmpw//Z+mBQOLcI0HNwJ3fhz0iL/GNVPQpBrPdqj2sFP762j4m3VN8\r\ns/JgIxNgR1Ayg/41dwpCWD/OUwa+zEQFMcLBJD2X7qzHr4mJ3p085OcNgbNs\r\nBxoePnjdzTbfgXnFPw0kCRJZ8cpK7O3aEQht1AMO1SpELFurWHJv27YWxZAl\r\nFSxGUmgAzktwmXyVV40nrnZOFB9ccVGWGM8eYn83s+8MF82reTOhPxfEMGoh\r\nyMvBK5fBsf8yeGn4PPo8BEwKnV6/T5RtoWGCi5BIdcpXD6XF36kY/0dSfymV\r\nVioQfrM1kLQBI8wwzISD3kOZh32xX092W14UnIlD+/YumWeEahAQtDlmOoll\r\nu5usfruhz3oa6d3NEHdQ39tPTjNAh670BETOqAmfjXQtfL+V2RB61+Qb1dT+\r\nv6aWI8xrGBr/5fdG5foi+YtkkbhHprDt8CzicaipcYNgrLj/LDKICJeLChX+\r\n9tLCr6o6KdRrXOIUE1MbCOZw9VkhTrdQJ4AtYky7CWYPt11VIOxAoEKSfUIV\r\nBf06lQw+l8fysrb4A7t+oGEzA5wwhMyDxkhPQsl1HvPFg+aRP/2tr6X4bYlY\r\nwlg4suRkC5S5QaCfvybSss1aTDZOoqWOX8brWzyfH5TT69dW4oJxhSCPcI/R\r\nPKrj90G03fDk/qA0MtDI2AqDBYK8FK1zWlo=\r\n=XFKx\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.2.0_1648831950425_0.1970334499839479"},"_hasShrinkwrap":false},"1.3.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.3.0","author":"AutoCloud","license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=14.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepublish","lint":"eslint","prepack":"rm -rf dist && tsc -b","prepublish":"rm -rf dist && tsc","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.3.0","gitHead":"ca64ba2d9a14592ae7d39d159fc234dcb1a0d76d","dist":{"shasum":"2a234ab392e4a5d63f0460cb4cb6c9dcc4814074","integrity":"sha512-0Sr2EN23IprJkpbrOzLyVkwUsA6Cg1VH1Xycn117coZx1RuXbW3vHMpUYyrKHwkr4+V2ld5/Au5TxN0UTkMEcw==","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.3.0.tgz","fileCount":37,"unpackedSize":675960,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD0P9ugLDhCH6QxD7KINZaoobV1KaN9l9qIMg3i2S5vzQIgH0pVtt/vKnR0edmIZdFBbDoEMXFCC168UsewJ9E4S7Q="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiR1OhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoqbA/8Dj0LGEOQhD8xVNe3XKhvKVkYU5dp7hxX2POS5E31jeMcJ9OU\r\nPtBADPjy5Rik4ygAbg5zl4w8LbRk4p1+sDYtpG8EPAyqSGSoTAohtY/5zwm+\r\n+LfqXyKQZbzxZYV/dt+rTRwOSAISxl7htkD4DEEirSahG3VFGMX3fd0zq+1c\r\nu4ZxB/zXKG996+D21YRZT5KqQU1IIeEL5G1jzxjIJxoFzZzJMf+bDw0jxpI5\r\n004FRh+KCU454ADAu8lir1P+A5N4/i4wJVLIX2gitisoRdJZHzEDz8ywYV15\r\nsCO7aX0jObqs6LivLw0VVkhWqe5dDrU8awqjRK7THxDO4nKCC/A8hno9BeeI\r\nmiDuB4Ts1DQ1hmBFiXyOiH9NShNTApNNumgIIdJ+2nYFU+Za6UiA4B8/Oseq\r\nEIFwUC/1glTvcm3Ouf4XI+u2/Zcu2QUmlIKpvALcbQhN6TkICsUn7qvsqcZm\r\nGERRD6ecSQLBv/Epl1KhzKybhu1FOzxShgmMSsBbG4A4v4G1p9Ps+etFVWmL\r\nCKvvg1etYGypRgwk9R6lDqwJePncr0StlvavLePSogJw9Ha3eT3u46+hSpuz\r\nYcKE3Hc1sp2nnGq9QLwlhWLkMMvtdHKsVE7ykavF3A8BTpI2mz8PdcRQJrp9\r\nI2XD47BZ+y2FJQF8yXZ0BcfWuG6PYU7/6C8=\r\n=uV0c\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.3.0_1648841633291_0.5136822933610452"},"_hasShrinkwrap":false},"1.4.0-alpha.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.4.0-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"yarn clean && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"readme":"# NIST 800-53 Rev. 4 for Amazon Web Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Amazon Web Services benchmark using `cg policy add aws-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| AWS NIST 1.1  | IAM role trust policies should not allow all principals to assume the role                                                         |\n| AWS NIST 1.2  | IAM roles attached to instance profiles should not allow broad list actions on S3 buckets                                          |\n| AWS NIST 1.3  | S3 bucket ACLs should not have public access on S3 buckets that store CloudTrail log files                                         |\n| AWS NIST 2.1  | Auto Scaling groups should span two or more availability zones                                                                     |\n| AWS NIST 2.2  | ELBv1 load balancer cross zone load balancing should be enabled                                                                    |\n| AWS NIST 2.3  | RDS Aurora cluster multi-AZ should be enabled                                                                                      |\n| AWS NIST 2.4  | Require Multi Availability Zones turned on for RDS Instances                                                                       |\n| AWS NIST 2.5  | S3 bucket replication (cross-region or same-region) should be enabled                                                              |\n| AWS NIST 3.1  | CloudTrail log files should be encrypted with customer managed KMS keys                                                            |\n| AWS NIST 3.2  | CloudWatch log groups should be encrypted with customer managed KMS keys                                                           |\n| AWS NIST 3.3  | DynamoDB tables should be encrypted with AWS or customer managed KMS keys                                                          |\n| AWS NIST 3.4  | EBS volume encryption should be enabled                                                                                            |\n| AWS NIST 3.5  | RDS instances should be encrypted                                                                                                  |\n| AWS NIST 3.6  | S3 bucket server-side encryption should be enabled                                                                                 |\n| AWS NIST 3.7  | SQS queue server-side encryption should be enabled with KMS keys                                                                   |\n| AWS NIST 4.1  | CloudFront distribution origin should be set to S3 or origin protocol policy should be set to https-only                           |\n| AWS NIST 4.2  | CloudFront viewer protocol policy should be set to https-only or redirect-to-https                                                 |\n| AWS NIST 4.3  | ElastiCache transport encryption should be enabled                                                                                 |\n| AWS NIST 4.4  | ELBv1 listener protocol should not be set to http                                                                                  |\n| AWS NIST 4.5  | S3 bucket policies should only allow requests that use HTTPS                                                                       |\n| AWS NIST 4.6  | SNS subscriptions should deny access via HTTP                                                                                      |\n| AWS NIST 6.1  | CloudFront access logging should be enabled                                                                                        |\n| AWS NIST 6.2  | CloudTrail log file validation should be enabled                                                                                   |\n| AWS NIST 6.3  | CloudTrail should be enabled in all regions                                                                                        |\n| AWS NIST 6.4  | CloudTrail should have at least one CloudTrail trail set to a multi-region trail                                                   |\n| AWS NIST 6.5  | CloudTrail trails should be configured to log data events for S3 buckets                                                           |\n| AWS NIST 6.6  | CloudTrail trails should be configured to log management events                                                                    |\n| AWS NIST 6.7  | CloudTrail trails should have CloudWatch log integration enabled                                                                   |\n| AWS NIST 6.8  | Exactly one CloudTrail trail should monitor global services                                                                        |\n| AWS NIST 6.9  | Load balancer access logging should be enabled                                                                                     |\n| AWS NIST 6.10 | S3 bucket access logging should be enabled                                                                                         |\n| AWS NIST 6.11 | S3 bucket access logging should be enabled on S3 buckets that store CloudTrail log files                                           |\n| AWS NIST 6.12 | S3 bucket object-level logging for read events should be enabled                                                                   |\n| AWS NIST 6.13 | S3 bucket object-level logging for write events should be enabled                                                                  |\n| AWS NIST 6.14 | VPC flow logging should be enabled                                                                                                 |\n| AWS NIST 7.1  | Alarm for denied connections in CloudFront logs should be configured                                                               |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for AWS Organizations changes should be configured for the master account                   |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for changes to VPC NACLs should be configured                                               |\n| AWS NIST 7.4  | CloudWatch log metric filter and alarm for changes to VPC network gateways should be configured                                    |\n| AWS NIST 7.5  | CloudWatch log metric filter and alarm for CloudTrail configuration changes should be configured                                   |\n| AWS NIST 7.7  | CloudWatch log metric filter and alarm for IAM policy changes should be configured                                                 |\n| AWS NIST 7.8  | CloudWatch log metric filter and alarm for Management Console authentication failures should be configured                         |\n| AWS NIST 7.9  | CloudWatch log metric filter and alarm for Management Console sign-in without MFA should be configured                             |\n| AWS NIST 7.10 | CloudWatch log metric filter and alarm for unauthorized API calls should be configured                                             |\n| AWS NIST 7.11 | CloudWatch log metric filter and alarm for usage of root account should be configured                                              |\n| AWS NIST 7.12 | CloudWatch log metric filter and alarm for VPC changes should be configured                                                        |\n| AWS NIST 7.13 | CloudWatch log metric filter and alarm for VPC route table changes should be configured                                            |\n| AWS NIST 7.14 | CloudWatch log metric filter and alarm for VPC security group changes should be configured                                         |\n| AWS NIST 8.1  | ELB listener security groups should not be set to TCP all                                                                          |\n| AWS NIST 8.2  | VPC default security group should restrict all traffic                                                                             |\n| AWS NIST 8.3  | VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 22                                                        |\n| AWS NIST 8.4  | AWS NIST 8.4 VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 3389                                         |\n| AWS NIST 8.5  | VPC security group inbound rules should not permit ingress from ‘0.0.0.0/0’ to all ports and protocols                             |\n| AWS NIST 8.6  | VPC security group inbound rules should not permit ingress from a public address to all ports and protocols                        |\n| AWS NIST 8.7  | VPC security group inbound rules should not permit ingress from any address to all ports and protocols                             |\n| AWS NIST 8.8  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ except to ports 80 and 443                                     |\n| AWS NIST 8.9  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 3389 (Remote Desktop Protocol)                         |\n| AWS NIST 8.10 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 61621 (Cassandra OpsCenter Agent)              |\n| AWS NIST 8.11 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 636 (LDAP SSL)                                 |\n| AWS NIST 8.12 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 7001 (Cassandra)                               |\n| AWS NIST 8.13 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11214 (Memcached SSL)                          |\n| AWS NIST 8.14 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11215 (Memcached SSL)                          |\n| AWS NIST 8.15 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 135 (MSSQL Debugger)                           |\n| AWS NIST 8.16 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 137 (NetBIOS Name Service)                     |\n| AWS NIST 8.17 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 138 (NetBios Datagram Service)                 |\n| AWS NIST 8.18 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 139 (NetBios Session Service)                  |\n| AWS NIST 8.19 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 1433 (MSSQL Server)                                |\n| AWS NIST 8.20 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 1434 (MSSQL Admin)                             |\n| AWS NIST 8.21 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 22 (SSH)                                               |\n| AWS NIST 8.22 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 23 (Telnet)                                        |\n| AWS NIST 8.23 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 2379 (etcd)                                        |\n| AWS NIST 8.24 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2382 (SQL Server Analysis Services browser)    |\n| AWS NIST 8.25 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2383 (SQL Server Analysis Services)            |\n| AWS NIST 8.26 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2484 (Oracle DB SSL)                           |\n| AWS NIST 8.27 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27017 (MongoDB)                                    |\n| AWS NIST 8.28 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27018 (MongoDB)                                    |\n| AWS NIST 8.29 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27019 (MongoDB)                                    |\n| AWS NIST 8.30 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3000 (Ruby on Rails web server)                |\n| AWS NIST 8.31 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3020 (CIFS / SMB)                              |\n| AWS NIST 8.32 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3306 (MySQL)                                   |\n| AWS NIST 8.33 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4505 (SaltStack Master)                        |\n| AWS NIST 8.34 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4506 (SaltStack Master)                        |\n| AWS NIST 8.35 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5432 (PostgreSQL)                              |\n| AWS NIST 8.36 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5500 (Virtual Network Computing)               |\n| AWS NIST 8.37 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5800 (Virtual Network Computing), unless from ELBs |\n| AWS NIST 8.38 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5900 (Virtual Network Computing)                   |\n| AWS NIST 8.39 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 80 (HTTP), unless from ELBs                        |\n| AWS NIST 8.40 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 8000 (HTTP Alternate)                          |\n| AWS NIST 8.41 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9200 (Elasticsearch)                               |\n| AWS NIST 8.42 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9300 (Elasticsearch)                               |\n| AWS NIST 8.43 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 8.44 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to TCP port 389 (LDAP)                    |\n| AWS NIST 8.45 | VPC security groups attached to RDS instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n","readmeFilename":"README.md","gitHead":"411bf33d4cf3f4c64b2888be5ccbd3c2c8459091","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.4.0-alpha.1","_nodeVersion":"16.14.2","_npmVersion":"8.7.0","dist":{"integrity":"sha512-YDm1AYZ3hsy6GsizvOsAWzQFr9+U/6Ipe8eip8t7LW7+LEBkyjeMBQSeYM3zcUC3iMxQM+M/rjv87uxgc7r27Q==","shasum":"03d4bba6fa2aff56415dbdd0581aaebefe1c8502","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.4.0-alpha.1.tgz","fileCount":99,"unpackedSize":452314,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDG07WwaKllaYVjTDnMzZWpGGGYpZuu6pCS1mv/LXxbAAIhAKRldk2s0RV5BoliaLjUmVdRWNLbgALaKAHYjhh/7KzN"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiaZmkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpPWg//TS+P2IKQbfFBwtl7CqZJZuabaFUjQ7hPKmQMMyJ7j9pG+7lX\r\noAVdsgaPF0pm6VB7YfLcWP5MPK9O3rk3bPMNxix31JQME47nh10oD5jDsKhZ\r\nFgPP3Fo+shYMymntC27WP8NZP75Sg9aFT2ZiEp/3DHgryBa4w2fyoKq46AKy\r\ntg/DuXPsa7IoHmrFo30pqOuN6ffkVG77XJFvQnnVfK+gk5IB+r+Kfve07q1+\r\nNACG295z2+gQicfvrORxAlks3ACkatORz4bsLUbgt1e//RCGDyXihY07WGB/\r\nYxH/X0pOWsXmMVww+2fRRQnDKtizaTijjqe7OWLK2Mmcq9cha0RvfVPKQLYG\r\nnc+sD3qdScDZYZlqetCzpS6+t/x3wse4jwkLQU+ndu3ANdXkSy6V7KcI3Lcn\r\nRgBVZ9M/A2SLqE3XCqc+mN5ewHvfY2H1kyD+yQ9ZjRbW5jgXqr5Xa8mbQ0Zd\r\nymYLfD68atkPtUPN9KKDB/teh8njAd0SRjXxKjEcXiqBg1Y2/hzXkJ0VrVY+\r\nlKtexeHlrUrrJy3CBa+k1lvyd5xlMvUeyWUIge9ga51XynCClTK+WMCEWgXg\r\nGm/bw7A5sCt9uyJiGGAutZ09LtPlwQ0dHB/jLRsoqpnPuXfwck/6BvqXTbb0\r\n5Jw5kq4Eog61CvT4eJOwQbfdnm4xY33OgsI=\r\n=hwXe\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.4.0-alpha.1_1651087780538_0.31611860797600877"},"_hasShrinkwrap":false},"1.4.0-beta.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.4.0-beta.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"ebd301a317668b7c3a04b43d94013b0fb4158555","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.4.0-beta.1","_nodeVersion":"16.14.2","_npmVersion":"8.7.0","dist":{"integrity":"sha512-eLsoTeQcbdk9MlFNa30xCPzRJwYwewXOEdiQToKnBCmD/Bms3ikDFDnd2isLB0nQ5FH7NF/Xl4/+cJS2+GPqcg==","shasum":"8f8b162298101625e4adc79fe36d093ef0e8bad2","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.4.0-beta.1.tgz","fileCount":122,"unpackedSize":550146,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEMCHwiylAVfdcNfc3GcyEBBmgkYe7zVjPu1laAgPTDqxwcCIHwkyN/nQg8/7tufYpWb6KsEaimex6iPXI7BLK9IKFIF"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJicB0+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpiLw/+MEuOaiM50LZpjtfjD3aSQYTMjKcNaHAA1OjQ1SwuECttYNs1\r\nFGAW4NfPYq+qfgW0x7cnD5rD6Pt18hq3PQTUCwQCIPXdkNtwLH2Nk2CyS5OE\r\nrO2+d9LuGM3s8b2wEW3sbijDsWUXW/yPBtI7SM1pkZVtQQgo9qVRlGlFxWZ3\r\nAP2R5a+Enplyid03PCbxtHXQfTInwlP72YCAV1lC6lU6SCt3avf3DQ/xmCj1\r\nJKdHBg/OiiNuzK04aUDJE9XrSvLYWk8/uLmUKUV+MR9B/lxmR/ucvLLgxZF7\r\nQFBwDjSAMqtfv/ThUihGYLIhex45lKZuvm7wQJ4BYoBZAiaxeI5j1WTCD33R\r\nJFzbe1AJrO28ZpArjorjNWXNsUfDZ+uQ3b8rAl5/8CJhpHZ0qjrxBdT1YlUK\r\n6ZhfNR/tTrlPQRKAokkEFtu6jbbIesFjaUTPaz4TMJOo4CIIdnJsXkx/iwa3\r\nnVWxfNjtJvntHIkwB0Wyc4Gxdu3JWDA0FocYl4FNL0xzi4DR23bhnFxWUsMA\r\nBX5IUrbUv98U7EC4M7cyy6TzwdIGnXf5co6p/iX62TMvoy+DO0g5npSChwi4\r\nVYNXJyD9j1zyUA3Tl3DcYxh6nBIWHWhqAd7jrjco6+pS6iFZdIoFARi2L2Jf\r\nrXv6Ur8sjqTQFFW6zPvfDfcYixxzNaN1t/Y=\r\n=Yp1p\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.4.0-beta.1_1651514686478_0.9516537536146903"},"_hasShrinkwrap":false},"1.4.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.4.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"90ff67caf41d6bffccbac20dd9b9bc5ff7014f6d","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.4.0","_nodeVersion":"16.14.2","_npmVersion":"8.7.0","dist":{"integrity":"sha512-2Q7JMebvZ19gSSfKoK6fqcQCJrZeAzZarV9d2vdBZ/RKwvtBfBRUXHtuuKVXae1EeeOdZn1t3ng+rg0ZSxqncg==","shasum":"22a36ae0394474fcc641beb00bbadf299c4e31ba","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.4.0.tgz","fileCount":122,"unpackedSize":553561,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFL4TQB+gicMMI6pmacCEVEfWPn7NtQvTEqN7WJmi8qoAiBjwgHABwyub71xULWclGawJ3Y2sTQVYeFpPlZdxXPv9w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJicDg2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqa6w/8Dw/DRYdD5xlQA8iLY4o9sx+TDYP4JDKl4GmnB816OXLI7A9C\r\nIydDG+slwueJY6/+WKA04JuHipYPdvY20UCCKa6P98d/QMzE7haSuPaNsEfe\r\nRdCPtZUz8eoGm9E5OllOGCzWjSu4/uV/avfTUchLdhaue9a4Ese7JJASmMWL\r\nsiHeBGm891N7TP2XbQ+hE/LbBzEYyAzi7LH2ZhMBK5gWtduwHTazWNCSjpwb\r\ndyiQUBnDZYObmSR5Rz7z3cp+wFq3DYBiCQdNf/iyzxWuinIAKqGCK+BDvIQw\r\nRNGtCTB/xCT6LTRp1vn23/DSqmiaE6bCZ6+5aj6D+FIM44WBzI9JPXKLmKwl\r\nazsMqDmYfvu2X59iTZJBFb1ytMnmzngJcAZBfsGplOhSwaIs+K9ak/YS5mQH\r\nbef8D4emOg6QWeOw24nvGjVVBhepaw4td2Nmm/qAbgt4PDQnFoXgr2yGgp6F\r\nIYy0KCXFjUpV0+glwU3gfqC11xQkBTzmG1b4VR4p6LIEPwWbCAstTYrnXrh1\r\nAID/DWnP+uKdhTzypByfYyHNDpd7s00IrcIH6k9/Lmn0YQvUNUibu21vu1rQ\r\nVonAygBflVosB5H4M9q2Mpplssy5J7RdStnS7x2cizDOyxz04BrNA46NBjZ0\r\n4e72+w1C/tohjEligylI1k96tAVX5BEsJfI=\r\n=UOG0\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.4.0_1651521590176_0.14034524232204926"},"_hasShrinkwrap":false},"1.5.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.5.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"47ca482c99973b0c1e107e256551439f4dba47d0","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.5.0","_nodeVersion":"16.14.2","_npmVersion":"8.10.0","dist":{"integrity":"sha512-FZkc+2h0uzkKIGgH9Mv20/PKpbBiSxvAVWmakSjnz99426o0RFK8hi7eNARvySJEflrff6U9rbFLHA5SjRh03g==","shasum":"c532f14f8fcee300238aadba5f7aebd4b0f7042d","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.5.0.tgz","fileCount":123,"unpackedSize":558003,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHMfufov3qNUUoTYbwA1G/Qq6YzXqBMczqRrzjoPskx0AiEAx+Urc1NNBxLB7JHuLedgRCtPpuAjEoQPy9a/x2xEoZ0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJifUu2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoa7Q//T5EaZd+Pbvc1EaAjrDglgLW3ketpqUXl//cq3DhaKQPrLFj3\r\nKdJs2pEggSxCApA7rRExptwElWxRH9jFRW1UTQWb5yZo+LkU47j3J5F6Q/Rw\r\nKwjCoC2TGr89K9RIywOPFgl+Z08v8rJc7jUZQQEQEJC70Y6f8JTL3yHGHNrY\r\n/vbJs/d/ksYc2I3NCjWiRNnpb/PTLqrn7WDj8t4Qid7AGsnt2LzVvRcpgEqe\r\nrCwK9jcAr850msZYEoFCirlgTGo/vg31hzP7E7AE5Y/GLkw441J8+zqPvIu2\r\nQ+S8V0HH/woOLh2H4WC8GQbBRARLWAxXioKTXhHH4A9/RrUVA44urMprhGIj\r\nHnuoPgK66j33fFbdpDF25aiKQqM8L5RSpMO4OHsGOXstp+Egz5li9TDJpW9C\r\nXXl6x/OWZXtRMbYngHyw2gjwwL3U95XhfDrlhLq7sG2qwabd43oKwMM1vJUJ\r\nBeQksFgNk8/NLfDuiEHGag5Kk6W0eYlfoOQfNss2vyB7tJIc2SUnz/avAres\r\nQhOha/rMwT6abTslyvvBznRqXNigq/osAkaPYlrjahKY83AIu9p9eTfIwhmb\r\nE/LEfMBJhiji0yr9tnCgUFdaUGlXWFpj1fJ3/ojvT0TJCqLUtR/8z3FQhSvF\r\nrcZXNp1r2kTn4voW2ilRT2mv//ak8K+P7fs=\r\n=sQRu\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.5.0_1652378550744_0.3422307479301272"},"_hasShrinkwrap":false},"1.6.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.6.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"7e5c70a7d59ec24a58b4067dd115b7210154eb37","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.6.0","_nodeVersion":"16.15.0","_npmVersion":"8.10.0","dist":{"integrity":"sha512-KPy0NE0N5cCfdT66xfFhlzS3URtXoOwssTDUeTRFoeRp8Dv+EL6F4gYljEGMSkSmPi4RINfuMD9zNSnhDIpsAQ==","shasum":"6061e376d7f2d5ef75ad0971563322bc4d786c4d","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.6.0.tgz","fileCount":131,"unpackedSize":587116,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDYhkJIpbnz9VDx3SQESmPQu5zZYw9TBXM+WMQcGJhXRQIgWOYgZ3mZrQ+nlpYlcmhcs2GjcwKquZMx6kxQylzjOaM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJij+QBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpOlQ/6AiNL3Toyqr72AF2EB61AfTjoobBIVCblDIdmvOfmjGas03vj\r\n40xlsnFbCVTeoJUd8KZECpISTcHq0aZvZw5VWDKFqj1tnXmRKekr3n/5uTDz\r\noEIgKwfYf/NjlEfBksVge6siSMRr2vvRpfEud4ILlbxS71Umq8PZqZnM1vLC\r\nLe2i/kXpEIe2e/3Mv26i7kwqIIohBSgcbgx70hHnYBcfyTkKA5eNyHPEb8Ft\r\nhudYgSnW5JBArbRm4LxILGs5VuSKMZWTjLTeWKWmrKS2qeb8HNS8dysG4dVn\r\n1F2KPvafl0MBCqFbmA+3vaWfym/4lUFlsrzXvorDKE4PqTp2tS8lwarcr48k\r\noVjVetDnQWehr5OJBWVSGyFJdIf7xSUpnAqqVrkwNa6EM6+DM7NLIgcSvlpB\r\nZzgQL4LByxoi7qWinHOrYTFJQbfs2rJkRi36vCl5qFRzkWYqtvMJs7Kl1foN\r\nJcEmsFf5riblHUgL9e0xP6t65OvRVcF1qO/wU2tBIA4acoIbyGXYGNltklJ7\r\nV8J/k/yrzpa05fuTpWe+w01TdI6+BLcGaJDvOIJUuysYLHlXOt5xRf1ZuDt/\r\nj5+MkvV4kNpReA1+A7Y+Q75bntVwfeLg6G1CIWOALT1U2063GoA+rs9ExoHa\r\nAPH2x9FXlwpV4hItWmcjMq85ve8X2LkbPhY=\r\n=rEXf\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.6.0_1653597185540_0.8767635752097083"},"_hasShrinkwrap":false},"1.6.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.6.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"0a3278eb6efb547a18993b5a675e9788c399ecfb","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.6.1","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-i9GMhABsR0KDk28ndzcaVVIkuvr/1GgX5qEtcITU0AsxP0m6mbMyZFOAVsbnCpP97SbhxfZ3fkEvi24QyyO3Mg==","shasum":"f5538ed99f85a5ed71858df288f22c4c2aca0a1c","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.6.1.tgz","fileCount":131,"unpackedSize":588349,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCWnOjc0MEmZPh4D1Wt+u89HqmHbp2YYlbSu87/tjcXEgIhAPLzVykAR0VTJsnPFuVJ57WUMoCJd5QO/tYsVZULSn9f"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJivGGTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpZlQ/5ACAclqKbxZg3gWkexAnZk3LvLbz6pgu86SidIkR8jbqFeTEi\r\nPzhCas6eV5QsyFXfd1vmDaQTw2ifA/osbfy9jqjJlPCezbkgh2KZx83+tYiY\r\ncg2l4UUawCszAAWN080T5vjdDeN+zWNbyNLAFHgLkyxqKWLzReZPUGbUKN5R\r\nbW8TzO0HQ3VTdtOcwyHj3O78v22Cv/q3xC08gydnNJNt7WI/nToyVm5GBgDR\r\n4NE0EHV5+cP4mxl2227DefB++spiL5KkGevuGfSo5+0EDlW40dt6WhYyfBq1\r\nY9ER5PCtDQFH8uuyZLKzIdh1YTTkw0fycf6AimoEu/5cfI8oN3A94QoQUM37\r\nDyugdcaEZJjEBTAozm5PFf0MWnpV6R6jMjbP2tHTQ7Gny3IW831i3PdPQSAw\r\n3k6K/E7ZLGCwDoeZtZX5/Dc3udpLlCimMHxyS0o3ClVmUw35Xf3JQ0aYMIOR\r\naFhHSAy6zZ6I9QbULdAsZZpp62M8iiiUNILc406o4ZkvgPqpj9gKjIqBOxJB\r\nxLDsJ/cpMU3VH9CksMirbSUva8ibVMlqUinH8QjCQ93e00OwUCDzZu2LOJE6\r\nHVMamXcS5GmlYuf6dt8Q+54pQAfBaQuH/c/poprXGFC+MInTDmt98AD5M3fc\r\n8sVgvedq9DWFe5ImsjNRo+lC4eYGLZaU6KY=\r\n=J8Si\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.6.1_1656512914874_0.39086204070041686"},"_hasShrinkwrap":false},"1.7.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.7.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"c0892c51a761dcf71c9c5c1804c56c65f1731880","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.7.0","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-QAbqyfDU8D78JO2WQ4KcP+X4v7uKspDUEp0DtRFkiVQ8kP+mwNFF94ihS5JmYjQ/N0WFSLMaGCBqAGVd/Rvpog==","shasum":"ebe028e23c166d744852a1404df40fb0baa63d80","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.7.0.tgz","fileCount":131,"unpackedSize":190600,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDtJ2XsMznxb78KT7c82ennfa6jqhTr2KnIIdCpBfXOQAiBhmWJxguxMNw1E34ohTcAUu0VX06Mt178eExOGOu82TA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizFAuACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpliRAAkm5t4+97lhfcQmUuBHfhA+VLf/XyC281og4j08V+ly6fL/lv\r\n6cnIZSBpw6u+IqdL08vyQLTmPqTdLq8GRWmAofyczf6uSE0EuZ3xxyW99R47\r\nnqksLcUeXvDby+4vEIhzCaAbRqmIhmu71hQy+fYwnODGN7LX4eucGMO7T6Ur\r\n5pnDeQA2qh0rBr5VSUEcalCbC60c5pxrf7z7UBsPzLDPW1TR2Ek9h9nUPZS5\r\nsasdb2sVRGlAwHnxc+c5f4EjDHOMEtEmho7ia7zJfDVVoGqzhBI+DcdkYNWQ\r\nkCI2uUD6x0ZqE3Q6uip0LKAG0JRcpyrSf1kBM6RIumcZ0uv6XTX0ehGLMw5H\r\nmgBovMwErOHj9sz7Q5pSu49nCY8fW87xNe/wxd6Yt8b672TnuAycMgozVoQM\r\nLHx2SsfSflVAMBoN27nYHND4uefZ87z5GjnlIgFpcPXO/AjcTVzhjlCehnk/\r\nYu8ZotIudK6oL8Frhacua5X9YGQuKVtpMexrq2MpepCgxNIvjlVK5iZvSGd/\r\nwQ4M/5pWz/l3CkZl9WonQ8Beq9npJCkM3ewZ+mKInZu495fkzarf/aWEZ3up\r\ndK+nSbu82Z9sxk8x+MPa9wd18UdjnEHDX5g1aCtzlgwseIHyHdev9O6n2RVh\r\n2Ane+ZTsdbQSfC5lsUwnIKJi2apD00Wuezk=\r\n=w08X\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.7.0_1657557038095_0.5800508668304343"},"_hasShrinkwrap":false},"1.7.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.7.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"f6abfbab60a821d27839a2e453b54ad223804535","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.7.1","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-FI8+tstWXh0fNoSj4p6kV5vfmTZ9tBeKNmyqtrpKMmff+hEzMK4G+wk/4aT0mTJ7zT0TJpxzUpvcnpWRFBFerw==","shasum":"b3544089ad4a6d2e13bbf0b67a6f23f8e39f7009","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.7.1.tgz","fileCount":257,"unpackedSize":697725,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCU4YSUD+7qPlN8c7qjakIQfo0XkGV/zIEGvtzNLf3K8gIhAI7tz8Qe2s/wieed/rxI36NI3D8UssXnlzLmOr0fDkGR"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizIDyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpHAA//e00cbwlqXbP28N533zax3MMbEK9BTTpVVZ8MzAil/YJLnBHz\r\nkLv1Nn+3elT/UCTGeajunvCEaQ/rokJUaAoLyC1NTt3KAUAmVvb4DjMUfNXH\r\nzIWv8PnSI6fzQeSvKNPwRf2OIQIqznY+cTrKDINMeH6svkrwKjiGr+YssXk3\r\ng2yX0bLSQkCoQFuDErdz2gJRFlvYy3GxzUuv1sEC+3etBYb+pXQ2Tuya1HSz\r\nQ4dHZRMaJINawxSlYul8KmMV6fLnI+ifI46w2CnU8PyyS/htUNiOtqVGWwpQ\r\nLkXMac5WU1v3Nym52omn4ozyiwUOHKxKVv3SEG7fpT8rQ16OfNq17LD3CLLr\r\naTa10JHHSgeBm7FEUN0hP7+98J14Yccopuwnlx22YdgSjB5wvJsLRjz9Wnba\r\njs69cYzPMhQBd+DQnPIVQouy0zIJLHMXJqeuXMRXFo90gUz7qD0629bCsfIT\r\nrsOXIUo2sfA+RFbXvxWbT4J4eBK3flN3IEEfW4HPIhPPBj1Ol01R5PPq2fyk\r\nmd+OIZERHJpvWMlj6bmGilNu0xcMmlG7mqKx+/cGAkH6HOggy8YeZqtDapdQ\r\nLzVTXWDiSarif1/K7tqLbqXkyJFq1e6WM3ALbiQzPtb8mkicCuQvHMqUFozv\r\nFmU23zJJRASUJHvqVY0wR+9zBOcoJ9GPV3A=\r\n=eeFl\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.7.1_1657569521734_0.9909046949547009"},"_hasShrinkwrap":false},"1.8.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.8.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","test":"NODE_ENV=test jest"},"_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.8.0","_integrity":"sha512-rgD40yhV1eqdpfiDSzZxJk+I2KpV/Y6atE7UkR4PgvJRGtDEw8O2I0tVccglWYeK8+Xj688yOJII0w68ZjKgVg==","_resolved":"/private/var/folders/bg/rvffzk01675c1h3n5znh7r_00000gn/T/68eba688bb7e0c29270763edceb51579/cloudgraph-policy-pack-aws-nist-800-53-rev4-1.8.0.tgz","_from":"file:cloudgraph-policy-pack-aws-nist-800-53-rev4-1.8.0.tgz","_nodeVersion":"17.9.1","_npmVersion":"8.15.1","dist":{"integrity":"sha512-rgD40yhV1eqdpfiDSzZxJk+I2KpV/Y6atE7UkR4PgvJRGtDEw8O2I0tVccglWYeK8+Xj688yOJII0w68ZjKgVg==","shasum":"f1cc4b97bba39c508a38582f53b54f111672a01f","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.8.0.tgz","fileCount":258,"unpackedSize":714073,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFdlMJpc+a+7bjAwb8HtEvtJjO9IVaovb2JJCc2iB4EIAiEAzDrgSH4oAfTS5Y6MDufB1C4QPkHI7T3AfN+7MTrwioA="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi6FDdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpA2w/+PZhfzczOnhHXW5gYG05oOx4/WsaGfsAb0FqGmOJcq72NwL1z\r\noAIPwaTwqBcMuR/IKhBWkz5dsSL5WpdnMmNF2unAU2aSVoGoIjrc/htdlNjv\r\no6YbS3Zd8g9GxCN8c5l6ToboRI4u9cCvQCG1Awg1H0Vr8webWqbtMk9AGD8A\r\nw9OgeoY0QxrO83Dhqy6ZHFYH1ujgyNJAHQ1jil1Q21jhywkkBXwCbDHlVATm\r\nQ+YXvSJca6BlxWUaM51Zwd92kQX83yu9mINCyQga6gpsd20PSoaUJV9rDe6H\r\nrEBJOW7s2pC3mZR1v4I/ooz1SaSSDt248ND36FJ0UjuYODDTXzk/e9TzrqUZ\r\n5929vfBZxhLgssJ3EfcRQn+yGhLiapINOsxl0PtNk2If/jtcMHPFKcHgKuWm\r\n3/4mDp/tGiZjU52MuKjwtmpMPCbGW7kcWk31kD2yNOgZ2eD/WsKRfb0LJ6Jw\r\n6VvrGWxtEa/0+b+XYl0KXcFjQM+9d+fr+1TVljKGHJowyFlFzkeaI367s2+O\r\n69dgCXAp9Uu9l/MYMIgt7l+ujK3MubJn7fJplDv6LqIgaLo0NuXLh6Kvcoij\r\njLkixSxO/zRWTzCZpvL6NU8yWDYF63brSLZCpRa0SwCChxFt266Zeu1dP1Zk\r\niTx2DTmiODw9sg4tUnsBnmIszULXeIkkIYg=\r\n=evHi\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.8.0_1659392221573_0.13277049834604804"},"_hasShrinkwrap":false},"1.8.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.8.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci -e semantic-release-monorepo"},"readme":"# NIST 800-53 Rev. 4 for Amazon Web Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Amazon Web Services benchmark using `cg policy add aws-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| AWS NIST 1.1  | IAM role trust policies should not allow all principals to assume the role                                                         |\n| AWS NIST 1.2  | IAM roles attached to instance profiles should not allow broad list actions on S3 buckets                                          |\n| AWS NIST 1.3  | S3 bucket ACLs should not have public access on S3 buckets that store CloudTrail log files                                         |\n| AWS NIST 2.1  | Auto Scaling groups should span two or more availability zones                                                                     |\n| AWS NIST 2.2  | ELBv1 load balancer cross zone load balancing should be enabled                                                                    |\n| AWS NIST 2.3  | RDS Aurora cluster multi-AZ should be enabled                                                                                      |\n| AWS NIST 2.4  | Require Multi Availability Zones turned on for RDS Instances                                                                       |\n| AWS NIST 2.5  | S3 bucket replication (cross-region or same-region) should be enabled                                                              |\n| AWS NIST 3.1  | CloudTrail log files should be encrypted with customer managed KMS keys                                                            |\n| AWS NIST 3.2  | CloudWatch log groups should be encrypted with customer managed KMS keys                                                           |\n| AWS NIST 3.3  | DynamoDB tables should be encrypted with AWS or customer managed KMS keys                                                          |\n| AWS NIST 3.4  | EBS volume encryption should be enabled                                                                                            |\n| AWS NIST 3.5  | RDS instances should be encrypted                                                                                                  |\n| AWS NIST 3.6  | S3 bucket server-side encryption should be enabled                                                                                 |\n| AWS NIST 3.7  | SQS queue server-side encryption should be enabled with KMS keys                                                                   |\n| AWS NIST 4.1  | CloudFront distribution origin should be set to S3 or origin protocol policy should be set to https-only                           |\n| AWS NIST 4.2  | CloudFront viewer protocol policy should be set to https-only or redirect-to-https                                                 |\n| AWS NIST 4.3  | ElastiCache transport encryption should be enabled                                                                                 |\n| AWS NIST 4.4  | ELBv1 listener protocol should not be set to http                                                                                  |\n| AWS NIST 4.5  | S3 bucket policies should only allow requests that use HTTPS                                                                       |\n| AWS NIST 4.6  | SNS subscriptions should deny access via HTTP                                                                                      |\n| AWS NIST 5.1  | RDS instances should have FedRAMP approved database engines                                                                        |\n| AWS NIST 6.1  | CloudFront access logging should be enabled                                                                                        |\n| AWS NIST 6.2  | CloudTrail log file validation should be enabled                                                                                   |\n| AWS NIST 6.3  | CloudTrail should be enabled in all regions                                                                                        |\n| AWS NIST 6.4  | CloudTrail should have at least one CloudTrail trail set to a multi-region trail                                                   |\n| AWS NIST 6.5  | CloudTrail trails should be configured to log data events for S3 buckets                                                           |\n| AWS NIST 6.6  | CloudTrail trails should be configured to log management events                                                                    |\n| AWS NIST 6.7  | CloudTrail trails should have CloudWatch log integration enabled                                                                   |\n| AWS NIST 6.8  | Exactly one CloudTrail trail should monitor global services                                                                        |\n| AWS NIST 6.9  | Load balancer access logging should be enabled                                                                                     |\n| AWS NIST 6.10 | S3 bucket access logging should be enabled                                                                                         |\n| AWS NIST 6.11 | S3 bucket access logging should be enabled on S3 buckets that store CloudTrail log files                                           |\n| AWS NIST 6.12 | S3 bucket object-level logging for read events should be enabled                                                                   |\n| AWS NIST 6.13 | S3 bucket object-level logging for write events should be enabled                                                                  |\n| AWS NIST 6.14 | VPC flow logging should be enabled                                                                                                 |\n| AWS NIST 7.1  | Alarm for denied connections in CloudFront logs should be configured                                                               |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for AWS Organizations changes should be configured for the master account                   |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for changes to VPC NACLs should be configured                                               |\n| AWS NIST 7.4  | CloudWatch log metric filter and alarm for changes to VPC network gateways should be configured                                    |\n| AWS NIST 7.5  | CloudWatch log metric filter and alarm for CloudTrail configuration changes should be configured                                   |\n| AWS NIST 7.7  | CloudWatch log metric filter and alarm for IAM policy changes should be configured                                                 |\n| AWS NIST 7.8  | CloudWatch log metric filter and alarm for Management Console authentication failures should be configured                         |\n| AWS NIST 7.9  | CloudWatch log metric filter and alarm for Management Console sign-in without MFA should be configured                             |\n| AWS NIST 7.10 | CloudWatch log metric filter and alarm for unauthorized API calls should be configured                                             |\n| AWS NIST 7.11 | CloudWatch log metric filter and alarm for usage of root account should be configured                                              |\n| AWS NIST 7.12 | CloudWatch log metric filter and alarm for VPC changes should be configured                                                        |\n| AWS NIST 7.13 | CloudWatch log metric filter and alarm for VPC route table changes should be configured                                            |\n| AWS NIST 7.14 | CloudWatch log metric filter and alarm for VPC security group changes should be configured                                         |\n| AWS NIST 8.1  | ELB listener security groups should not be set to TCP all                                                                          |\n| AWS NIST 8.2  | VPC default security group should restrict all traffic                                                                             |\n| AWS NIST 8.3  | VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 22                                                        |\n| AWS NIST 8.4  | AWS NIST 8.4 VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 3389                                         |\n| AWS NIST 8.5  | VPC security group inbound rules should not permit ingress from ‘0.0.0.0/0’ to all ports and protocols                             |\n| AWS NIST 8.6  | VPC security group inbound rules should not permit ingress from a public address to all ports and protocols                        |\n| AWS NIST 8.7  | VPC security group inbound rules should not permit ingress from any address to all ports and protocols                             |\n| AWS NIST 8.8  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ except to ports 80 and 443                                     |\n| AWS NIST 8.9  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 3389 (Remote Desktop Protocol)                         |\n| AWS NIST 8.10 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 61621 (Cassandra OpsCenter Agent)              |\n| AWS NIST 8.11 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 636 (LDAP SSL)                                 |\n| AWS NIST 8.12 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 7001 (Cassandra)                               |\n| AWS NIST 8.13 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11214 (Memcached SSL)                          |\n| AWS NIST 8.14 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11215 (Memcached SSL)                          |\n| AWS NIST 8.15 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 135 (MSSQL Debugger)                           |\n| AWS NIST 8.16 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 137 (NetBIOS Name Service)                     |\n| AWS NIST 8.17 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 138 (NetBios Datagram Service)                 |\n| AWS NIST 8.18 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 139 (NetBios Session Service)                  |\n| AWS NIST 8.19 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 1433 (MSSQL Server)                                |\n| AWS NIST 8.20 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 1434 (MSSQL Admin)                             |\n| AWS NIST 8.21 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 22 (SSH)                                               |\n| AWS NIST 8.22 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 23 (Telnet)                                        |\n| AWS NIST 8.23 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 2379 (etcd)                                        |\n| AWS NIST 8.24 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2382 (SQL Server Analysis Services browser)    |\n| AWS NIST 8.25 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2383 (SQL Server Analysis Services)            |\n| AWS NIST 8.26 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2484 (Oracle DB SSL)                           |\n| AWS NIST 8.27 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27017 (MongoDB)                                    |\n| AWS NIST 8.28 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27018 (MongoDB)                                    |\n| AWS NIST 8.29 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27019 (MongoDB)                                    |\n| AWS NIST 8.30 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3000 (Ruby on Rails web server)                |\n| AWS NIST 8.31 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3020 (CIFS / SMB)                              |\n| AWS NIST 8.32 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3306 (MySQL)                                   |\n| AWS NIST 8.33 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4505 (SaltStack Master)                        |\n| AWS NIST 8.34 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4506 (SaltStack Master)                        |\n| AWS NIST 8.35 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5432 (PostgreSQL)                              |\n| AWS NIST 8.36 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5500 (Virtual Network Computing)               |\n| AWS NIST 8.37 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5800 (Virtual Network Computing), unless from ELBs |\n| AWS NIST 8.38 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5900 (Virtual Network Computing)                   |\n| AWS NIST 8.39 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 80 (HTTP), unless from ELBs                        |\n| AWS NIST 8.40 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 8000 (HTTP Alternate)                          |\n| AWS NIST 8.41 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9200 (Elasticsearch)                               |\n| AWS NIST 8.42 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9300 (Elasticsearch)                               |\n| AWS NIST 8.43 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 8.44 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to TCP port 389 (LDAP)                    |\n| AWS NIST 8.45 | VPC security groups attached to RDS instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 9.1  | ECS container definitions should not mount volumes with mount propagation set to shared                                            |\n| AWS NIST 9.2  | ECS task definitions should mount the container’s root filesystem as read-only                                                     |\n| AWS NIST 9.3  | ECS task definitions should not add Linux capabilities beyond defaults and should drop ‘NET_RAW’                                   |\n| AWS NIST 9.4  | ECS task definitions should not mount sensitive host system directories                                                            |\n| AWS NIST 10.1 | IAM password policies should expire passwords within 90 days                                                                       |\n| AWS NIST 10.2 | IAM password policies should have a minimum length of 7 and include both alphabetic and numeric characters                         |\n| AWS NIST 10.3 | IAM password policies should prevent reuse of previously used passwords                                                            |\n| AWS NIST 10.4 | IAM password policies should prevent reuse of the four previously used passwords                                                   |\n| AWS NIST 10.5 | IAM password policies should require at least one lowercase character                                                              |\n| AWS NIST 10.6 | IAM password policies should require at least one number                                                                           |\n| AWS NIST 10.7 | IAM password policies should require at least one symbol                                                                           |\n| AWS NIST 10.8 | IAM password policies should require at least one uppercase character                                                              |\n| AWS NIST 11.1 | ECS task definitions should limit memory usage for containers                                                                      |\n| AWS NIST 11.2 | ECS task definitions should set CPU limit for containers                                                                           |\n| AWS NIST 12.1 | CloudFront distributions should have geo-restrictions specified                                                                    |\n| AWS NIST 12.2 | EC2 instances should not have a public IP association (IPv4)                                                                       |\n| AWS NIST 13.1 | IAM multi-factor authentication should be enabled for all IAM users that have a console password                                   |\n| AWS NIST 13.2 | IAM should have hardware MFA enabled for the root account                                                                          |\n| AWS NIST 13.3 | IAM should have MFA enabled for the root account                                                                                   |\n| AWS NIST 13.4 | IAM users should have MFA (virtual or hardware) enabled                                                                            |\n| AWS NIST 14.1 | CloudFront distributions should be protected by WAFs                                                                               |\n| AWS NIST 15.1 | ECS task definitions should not use the root user                                                                                  |\n| AWS NIST 15.2 | IAM roles used for trust relationships should have MFA or external IDs                                                             |\n| AWS NIST 15.3 | IAM root user access key should not exist                                                                                          |\n| AWS NIST 15.4 | IAM root user should not be used                                                                                                   |\n| AWS NIST 16.1 | API Gateway classic custom domains should use secure TLS protocol versions (1.2 and above)                                         |\n| AWS NIST 16.2 | API Gateway v2 custom domains should use secure TLS protocol versions (1.2 and above)                                              |\n| AWS NIST 16.3 | CloudFront distribution custom origins should use secure TLS protocol versions (1.2 and above)                                     |\n| AWS NIST 16.4 | CloudFront distribution viewer certificate should use secure TLS protocol versions (1.2 and above)                                 |\n| AWS NIST 16.5 | ELB HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                        |\n| AWS NIST 16.6 | ELBv2 HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                      |","readmeFilename":"README.md","gitHead":"b46e0226f4da517f802ccbdcabe94748c9304924","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.8.1-alpha.1","_nodeVersion":"18.12.1","_npmVersion":"8.19.3","dist":{"integrity":"sha512-Ve/SggnC6VvI5OtPlHKHgjymXsmos+Lpla1f3kj/6MqYlu+HrPA+lsQLBbijM1Z/qbTfX1NbSLvpsPH9EVFM/g==","shasum":"d9a89a44ed3acfcf0787ae8d1b27f6f3277ac638","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.8.1-alpha.1.tgz","fileCount":257,"unpackedSize":698617,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIH1lk8rZZEimQ2DWX72+4poc4yqL9QEav8dqCp9TzRafAiBccs0DvkWzHkFbxzoIUdiwO3oULEb8SgVlgfbpo2E6Yw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmRxWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoNDhAAm0fhFuq0+QmL8sFJ6fucjnLRlAfjbA6jAJUmu7CWCT2KjVbr\r\nEWVGTed3ERSFT7KCn811ToQmWr1Ky5BotfrBUOupHo7TYS5vkWKc5tzyi8bu\r\n7AlJyLDGAvtnMZEYoTnKm0I5a+DcvFco8PQNCVeBDwb8wC07srgRI8dMy0v7\r\n1mSL2k2S8i6tIuHMxt02KddDDaMKbvRJFxWrsPv0qd4FgCur/PGIXdguXHdF\r\nXw+2+Uc4GrUYCRcQ8zhnhrJA/zNYJ6DwXogqlsOlFGKPABYeVQidJBxs4hjz\r\nn4JW+ypS2cchTiARgjxgB75k+M2Q1+p9TMrSRvgimlUh8IoEv6/vGic3KcG8\r\nXDMMTWxnZkPSehpTWMvhWbm2HLFyGwSbky2tK3cAoEhJtgeiSpyOY24NrwvS\r\nG0NaAM8Bw3JCQK4KGtdTbgAOy0PdfNLnN0KmA2aNMFqIET1LX/+M1o+7D74R\r\nh7M0mMIf8gjI6vo+iw7m8mGnWA4s4FM8Q5m8IqZxZrt9EFtlghJpS8l+F1Ar\r\nHe155T2KqTafHvWnZWSiiXxFGMbc2EoXfkRQ4O5JFaV4BO5wAQ1IC4pGLNHF\r\n+MlFcjOkLtntj6YxKMotTZPkgdmLy641B9yyDnRhJ5R7W7cJ86sjRt5d8/ZQ\r\nqKXb0jxo1LGGXls7OnS0mvbMfvh4oATAlHE=\r\n=xszz\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.8.1-alpha.1_1670978646085_0.6782921568132634"},"_hasShrinkwrap":false},"1.9.0":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.9.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci"},"gitHead":"2f247e4eb8e20e4a5c75c36f52b9d9d86f2ab984","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.9.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-K1SB9Ja9v3A+1zmpjN4GSqw6XKliK0zxzwF2+IJ0IDbpnUdAv5aeV1CoqoLRulVXa283UDnCO5fj7kVRKJgGGw==","shasum":"74d41728dd1647034d0d6677451400a3ff2c9ba7","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.9.0.tgz","fileCount":257,"unpackedSize":707955,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCc03CKNOAxH0YgbssVFEemKKCYNI0ZaaVvJibuQvLThgIgNcSaAwjZ1/x5l5D1EYaIWxco5d2W2Q0Bqw7sOLis9GE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkS/sDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqjCw/+LbWMsIqQEm6yrx4K4oVZW6eLnBu+sMDxN4SdVRwhuKoyqieM\r\nxZVwTdsUh73W4mU0fz20dWYJx7Ib35eJMOl19BsDex+TZV9hBO9uXQoK1hLE\r\nWOd5aqKAO8wnSUU/7218KKK9CwGHcD/iBAbgL+b4lEVGJTBVBly//qvzuW83\r\nN6fy5WMUESgtA31zMeuOFlA4/zJQ/KhooJB6bCmfhVbd7LAg9qC1OEaTRZha\r\nTYIKzK/mY2RipYKJyMkq3gakqtqccgxPx4bfO0BrDKZjSPwZ77GIEi6jp4VA\r\nUSdxHxzaZTg7In7wM4jf+Py587juGj5U/N9oKjpP/NaqX5h9Z4BpYrJXzAS9\r\nUy/7YAzYtyiw+A3eComd85qjzunCUKC1OzA0WoSok3HOQxklHpjnwgLL3lwO\r\ndXCMwyhUmLuRfdGkajUdy5StmdE24oc6Air9NLGUn85l2e7S2mG9DTyoilIq\r\np+fUljjYgUoCNcROMEFQPZVjvB/5cHoAaTey1YWogkMe2nF7WFGg0wgTJLqU\r\nNZYe0efWRNP7O2pC1v0fhfwq82JZKHDSBFMx7GLBFwMEq7awKYPp6QWxbc6a\r\nrpHndvhGelbb9sn1hK11yy6un4zIF0ky7eIlAwkW7K3TqIW70ny5f494CTwK\r\nrUoVOCp+VWDL0KTTLj8GIx2z2Q3sOm31+js=\r\n=NB4M\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.9.0_1682701058785_0.9866004454354362"},"_hasShrinkwrap":false},"1.9.1-alpha.1":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.9.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# NIST 800-53 Rev. 4 for Amazon Web Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Amazon Web Services benchmark using `cg policy add aws-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| AWS NIST 1.1  | IAM role trust policies should not allow all principals to assume the role                                                         |\n| AWS NIST 1.2  | IAM roles attached to instance profiles should not allow broad list actions on S3 buckets                                          |\n| AWS NIST 1.3  | S3 bucket ACLs should not have public access on S3 buckets that store CloudTrail log files                                         |\n| AWS NIST 2.1  | Auto Scaling groups should span two or more availability zones                                                                     |\n| AWS NIST 2.2  | ELBv1 load balancer cross zone load balancing should be enabled                                                                    |\n| AWS NIST 2.3  | RDS Aurora cluster multi-AZ should be enabled                                                                                      |\n| AWS NIST 2.4  | Require Multi Availability Zones turned on for RDS Instances                                                                       |\n| AWS NIST 2.5  | S3 bucket replication (cross-region or same-region) should be enabled                                                              |\n| AWS NIST 3.1  | CloudTrail log files should be encrypted with customer managed KMS keys                                                            |\n| AWS NIST 3.2  | CloudWatch log groups should be encrypted with customer managed KMS keys                                                           |\n| AWS NIST 3.3  | DynamoDB tables should be encrypted with AWS or customer managed KMS keys                                                          |\n| AWS NIST 3.4  | EBS volume encryption should be enabled                                                                                            |\n| AWS NIST 3.5  | RDS instances should be encrypted                                                                                                  |\n| AWS NIST 3.6  | S3 bucket server-side encryption should be enabled                                                                                 |\n| AWS NIST 3.7  | SQS queue server-side encryption should be enabled with KMS keys                                                                   |\n| AWS NIST 4.1  | CloudFront distribution origin should be set to S3 or origin protocol policy should be set to https-only                           |\n| AWS NIST 4.2  | CloudFront viewer protocol policy should be set to https-only or redirect-to-https                                                 |\n| AWS NIST 4.3  | ElastiCache transport encryption should be enabled                                                                                 |\n| AWS NIST 4.4  | ELBv1 listener protocol should not be set to http                                                                                  |\n| AWS NIST 4.5  | S3 bucket policies should only allow requests that use HTTPS                                                                       |\n| AWS NIST 4.6  | SNS subscriptions should deny access via HTTP                                                                                      |\n| AWS NIST 5.1  | RDS instances should have FedRAMP approved database engines                                                                        |\n| AWS NIST 6.1  | CloudFront access logging should be enabled                                                                                        |\n| AWS NIST 6.2  | CloudTrail log file validation should be enabled                                                                                   |\n| AWS NIST 6.3  | CloudTrail should be enabled in all regions                                                                                        |\n| AWS NIST 6.4  | CloudTrail should have at least one CloudTrail trail set to a multi-region trail                                                   |\n| AWS NIST 6.5  | CloudTrail trails should be configured to log data events for S3 buckets                                                           |\n| AWS NIST 6.6  | CloudTrail trails should be configured to log management events                                                                    |\n| AWS NIST 6.7  | CloudTrail trails should have CloudWatch log integration enabled                                                                   |\n| AWS NIST 6.8  | Exactly one CloudTrail trail should monitor global services                                                                        |\n| AWS NIST 6.9  | Load balancer access logging should be enabled                                                                                     |\n| AWS NIST 6.10 | S3 bucket access logging should be enabled                                                                                         |\n| AWS NIST 6.11 | S3 bucket access logging should be enabled on S3 buckets that store CloudTrail log files                                           |\n| AWS NIST 6.12 | S3 bucket object-level logging for read events should be enabled                                                                   |\n| AWS NIST 6.13 | S3 bucket object-level logging for write events should be enabled                                                                  |\n| AWS NIST 6.14 | VPC flow logging should be enabled                                                                                                 |\n| AWS NIST 7.1  | Alarm for denied connections in CloudFront logs should be configured                                                               |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for AWS Organizations changes should be configured for the master account                   |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for changes to VPC NACLs should be configured                                               |\n| AWS NIST 7.4  | CloudWatch log metric filter and alarm for changes to VPC network gateways should be configured                                    |\n| AWS NIST 7.5  | CloudWatch log metric filter and alarm for CloudTrail configuration changes should be configured                                   |\n| AWS NIST 7.7  | CloudWatch log metric filter and alarm for IAM policy changes should be configured                                                 |\n| AWS NIST 7.8  | CloudWatch log metric filter and alarm for Management Console authentication failures should be configured                         |\n| AWS NIST 7.9  | CloudWatch log metric filter and alarm for Management Console sign-in without MFA should be configured                             |\n| AWS NIST 7.10 | CloudWatch log metric filter and alarm for unauthorized API calls should be configured                                             |\n| AWS NIST 7.11 | CloudWatch log metric filter and alarm for usage of root account should be configured                                              |\n| AWS NIST 7.12 | CloudWatch log metric filter and alarm for VPC changes should be configured                                                        |\n| AWS NIST 7.13 | CloudWatch log metric filter and alarm for VPC route table changes should be configured                                            |\n| AWS NIST 7.14 | CloudWatch log metric filter and alarm for VPC security group changes should be configured                                         |\n| AWS NIST 8.1  | ELB listener security groups should not be set to TCP all                                                                          |\n| AWS NIST 8.2  | VPC default security group should restrict all traffic                                                                             |\n| AWS NIST 8.3  | VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 22                                                        |\n| AWS NIST 8.4  | AWS NIST 8.4 VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 3389                                         |\n| AWS NIST 8.5  | VPC security group inbound rules should not permit ingress from ‘0.0.0.0/0’ to all ports and protocols                             |\n| AWS NIST 8.6  | VPC security group inbound rules should not permit ingress from a public address to all ports and protocols                        |\n| AWS NIST 8.7  | VPC security group inbound rules should not permit ingress from any address to all ports and protocols                             |\n| AWS NIST 8.8  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ except to ports 80 and 443                                     |\n| AWS NIST 8.9  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 3389 (Remote Desktop Protocol)                         |\n| AWS NIST 8.10 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 61621 (Cassandra OpsCenter Agent)              |\n| AWS NIST 8.11 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 636 (LDAP SSL)                                 |\n| AWS NIST 8.12 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 7001 (Cassandra)                               |\n| AWS NIST 8.13 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11214 (Memcached SSL)                          |\n| AWS NIST 8.14 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11215 (Memcached SSL)                          |\n| AWS NIST 8.15 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 135 (MSSQL Debugger)                           |\n| AWS NIST 8.16 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 137 (NetBIOS Name Service)                     |\n| AWS NIST 8.17 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 138 (NetBios Datagram Service)                 |\n| AWS NIST 8.18 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 139 (NetBios Session Service)                  |\n| AWS NIST 8.19 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 1433 (MSSQL Server)                                |\n| AWS NIST 8.20 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 1434 (MSSQL Admin)                             |\n| AWS NIST 8.21 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 22 (SSH)                                               |\n| AWS NIST 8.22 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 23 (Telnet)                                        |\n| AWS NIST 8.23 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 2379 (etcd)                                        |\n| AWS NIST 8.24 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2382 (SQL Server Analysis Services browser)    |\n| AWS NIST 8.25 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2383 (SQL Server Analysis Services)            |\n| AWS NIST 8.26 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2484 (Oracle DB SSL)                           |\n| AWS NIST 8.27 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27017 (MongoDB)                                    |\n| AWS NIST 8.28 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27018 (MongoDB)                                    |\n| AWS NIST 8.29 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27019 (MongoDB)                                    |\n| AWS NIST 8.30 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3000 (Ruby on Rails web server)                |\n| AWS NIST 8.31 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3020 (CIFS / SMB)                              |\n| AWS NIST 8.32 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3306 (MySQL)                                   |\n| AWS NIST 8.33 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4505 (SaltStack Master)                        |\n| AWS NIST 8.34 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4506 (SaltStack Master)                        |\n| AWS NIST 8.35 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5432 (PostgreSQL)                              |\n| AWS NIST 8.36 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5500 (Virtual Network Computing)               |\n| AWS NIST 8.37 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5800 (Virtual Network Computing), unless from ELBs |\n| AWS NIST 8.38 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5900 (Virtual Network Computing)                   |\n| AWS NIST 8.39 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 80 (HTTP), unless from ELBs                        |\n| AWS NIST 8.40 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 8000 (HTTP Alternate)                          |\n| AWS NIST 8.41 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9200 (Elasticsearch)                               |\n| AWS NIST 8.42 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9300 (Elasticsearch)                               |\n| AWS NIST 8.43 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 8.44 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to TCP port 389 (LDAP)                    |\n| AWS NIST 8.45 | VPC security groups attached to RDS instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 9.1  | ECS container definitions should not mount volumes with mount propagation set to shared                                            |\n| AWS NIST 9.2  | ECS task definitions should mount the container’s root filesystem as read-only                                                     |\n| AWS NIST 9.3  | ECS task definitions should not add Linux capabilities beyond defaults and should drop ‘NET_RAW’                                   |\n| AWS NIST 9.4  | ECS task definitions should not mount sensitive host system directories                                                            |\n| AWS NIST 10.1 | IAM password policies should expire passwords within 90 days                                                                       |\n| AWS NIST 10.2 | IAM password policies should have a minimum length of 7 and include both alphabetic and numeric characters                         |\n| AWS NIST 10.3 | IAM password policies should prevent reuse of previously used passwords                                                            |\n| AWS NIST 10.4 | IAM password policies should prevent reuse of the four previously used passwords                                                   |\n| AWS NIST 10.5 | IAM password policies should require at least one lowercase character                                                              |\n| AWS NIST 10.6 | IAM password policies should require at least one number                                                                           |\n| AWS NIST 10.7 | IAM password policies should require at least one symbol                                                                           |\n| AWS NIST 10.8 | IAM password policies should require at least one uppercase character                                                              |\n| AWS NIST 11.1 | ECS task definitions should limit memory usage for containers                                                                      |\n| AWS NIST 11.2 | ECS task definitions should set CPU limit for containers                                                                           |\n| AWS NIST 12.1 | CloudFront distributions should have geo-restrictions specified                                                                    |\n| AWS NIST 12.2 | EC2 instances should not have a public IP association (IPv4)                                                                       |\n| AWS NIST 13.1 | IAM multi-factor authentication should be enabled for all IAM users that have a console password                                   |\n| AWS NIST 13.2 | IAM should have hardware MFA enabled for the root account                                                                          |\n| AWS NIST 13.3 | IAM should have MFA enabled for the root account                                                                                   |\n| AWS NIST 13.4 | IAM users should have MFA (virtual or hardware) enabled                                                                            |\n| AWS NIST 14.1 | CloudFront distributions should be protected by WAFs                                                                               |\n| AWS NIST 15.1 | ECS task definitions should not use the root user                                                                                  |\n| AWS NIST 15.2 | IAM roles used for trust relationships should have MFA or external IDs                                                             |\n| AWS NIST 15.3 | IAM root user access key should not exist                                                                                          |\n| AWS NIST 15.4 | IAM root user should not be used                                                                                                   |\n| AWS NIST 16.1 | API Gateway classic custom domains should use secure TLS protocol versions (1.2 and above)                                         |\n| AWS NIST 16.2 | API Gateway v2 custom domains should use secure TLS protocol versions (1.2 and above)                                              |\n| AWS NIST 16.3 | CloudFront distribution custom origins should use secure TLS protocol versions (1.2 and above)                                     |\n| AWS NIST 16.4 | CloudFront distribution viewer certificate should use secure TLS protocol versions (1.2 and above)                                 |\n| AWS NIST 16.5 | ELB HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                        |\n| AWS NIST 16.6 | ELBv2 HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                      |","readmeFilename":"README.md","gitHead":"d1f1fe77e01b6d9229843b95778741394d0a5403","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.9.1-alpha.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-FUsJblWM4jOF7lHmPClux1t7dKpH1jhJQIRzT7XMIUm9evIE320ffCs5NXlVdBw51fVIhXVzRA/7uVoKXYo7Rg==","shasum":"b66570f2c4923f9064f013b9e852bf7df75d49e3","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.9.1-alpha.1.tgz","fileCount":3,"unpackedSize":47259,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDXk8xQpy2AU3Plv8D+qWjmoNfIh+UnzW5mgGnDw6IoIwIhAKFmBXGWFdONxOSlGKvqZRyvpCkWp+y10Xry+kGbihSr"}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.9.1-alpha.1_1684332671189_0.9868417974201031"},"_hasShrinkwrap":false},"1.9.1-alpha.2":{"name":"@cloudgraph/policy-pack-aws-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","version":"1.9.1-alpha.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# NIST 800-53 Rev. 4 for Amazon Web Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [AWS Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-aws) for CG with the `cg init aws` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Amazon Web Services benchmark using `cg policy add aws-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan aws`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     queryawsFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     queryawsNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     queryawsIamUser {\n       id\n       arn\n       accountId\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| AWS NIST 1.1  | IAM role trust policies should not allow all principals to assume the role                                                         |\n| AWS NIST 1.2  | IAM roles attached to instance profiles should not allow broad list actions on S3 buckets                                          |\n| AWS NIST 1.3  | S3 bucket ACLs should not have public access on S3 buckets that store CloudTrail log files                                         |\n| AWS NIST 2.1  | Auto Scaling groups should span two or more availability zones                                                                     |\n| AWS NIST 2.2  | ELBv1 load balancer cross zone load balancing should be enabled                                                                    |\n| AWS NIST 2.3  | RDS Aurora cluster multi-AZ should be enabled                                                                                      |\n| AWS NIST 2.4  | Require Multi Availability Zones turned on for RDS Instances                                                                       |\n| AWS NIST 2.5  | S3 bucket replication (cross-region or same-region) should be enabled                                                              |\n| AWS NIST 3.1  | CloudTrail log files should be encrypted with customer managed KMS keys                                                            |\n| AWS NIST 3.2  | CloudWatch log groups should be encrypted with customer managed KMS keys                                                           |\n| AWS NIST 3.3  | DynamoDB tables should be encrypted with AWS or customer managed KMS keys                                                          |\n| AWS NIST 3.4  | EBS volume encryption should be enabled                                                                                            |\n| AWS NIST 3.5  | RDS instances should be encrypted                                                                                                  |\n| AWS NIST 3.6  | S3 bucket server-side encryption should be enabled                                                                                 |\n| AWS NIST 3.7  | SQS queue server-side encryption should be enabled with KMS keys                                                                   |\n| AWS NIST 4.1  | CloudFront distribution origin should be set to S3 or origin protocol policy should be set to https-only                           |\n| AWS NIST 4.2  | CloudFront viewer protocol policy should be set to https-only or redirect-to-https                                                 |\n| AWS NIST 4.3  | ElastiCache transport encryption should be enabled                                                                                 |\n| AWS NIST 4.4  | ELBv1 listener protocol should not be set to http                                                                                  |\n| AWS NIST 4.5  | S3 bucket policies should only allow requests that use HTTPS                                                                       |\n| AWS NIST 4.6  | SNS subscriptions should deny access via HTTP                                                                                      |\n| AWS NIST 5.1  | RDS instances should have FedRAMP approved database engines                                                                        |\n| AWS NIST 6.1  | CloudFront access logging should be enabled                                                                                        |\n| AWS NIST 6.2  | CloudTrail log file validation should be enabled                                                                                   |\n| AWS NIST 6.3  | CloudTrail should be enabled in all regions                                                                                        |\n| AWS NIST 6.4  | CloudTrail should have at least one CloudTrail trail set to a multi-region trail                                                   |\n| AWS NIST 6.5  | CloudTrail trails should be configured to log data events for S3 buckets                                                           |\n| AWS NIST 6.6  | CloudTrail trails should be configured to log management events                                                                    |\n| AWS NIST 6.7  | CloudTrail trails should have CloudWatch log integration enabled                                                                   |\n| AWS NIST 6.8  | Exactly one CloudTrail trail should monitor global services                                                                        |\n| AWS NIST 6.9  | Load balancer access logging should be enabled                                                                                     |\n| AWS NIST 6.10 | S3 bucket access logging should be enabled                                                                                         |\n| AWS NIST 6.11 | S3 bucket access logging should be enabled on S3 buckets that store CloudTrail log files                                           |\n| AWS NIST 6.12 | S3 bucket object-level logging for read events should be enabled                                                                   |\n| AWS NIST 6.13 | S3 bucket object-level logging for write events should be enabled                                                                  |\n| AWS NIST 6.14 | VPC flow logging should be enabled                                                                                                 |\n| AWS NIST 7.1  | Alarm for denied connections in CloudFront logs should be configured                                                               |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for AWS Organizations changes should be configured for the master account                   |\n| AWS NIST 7.3  | CloudWatch log metric filter and alarm for changes to VPC NACLs should be configured                                               |\n| AWS NIST 7.4  | CloudWatch log metric filter and alarm for changes to VPC network gateways should be configured                                    |\n| AWS NIST 7.5  | CloudWatch log metric filter and alarm for CloudTrail configuration changes should be configured                                   |\n| AWS NIST 7.7  | CloudWatch log metric filter and alarm for IAM policy changes should be configured                                                 |\n| AWS NIST 7.8  | CloudWatch log metric filter and alarm for Management Console authentication failures should be configured                         |\n| AWS NIST 7.9  | CloudWatch log metric filter and alarm for Management Console sign-in without MFA should be configured                             |\n| AWS NIST 7.10 | CloudWatch log metric filter and alarm for unauthorized API calls should be configured                                             |\n| AWS NIST 7.11 | CloudWatch log metric filter and alarm for usage of root account should be configured                                              |\n| AWS NIST 7.12 | CloudWatch log metric filter and alarm for VPC changes should be configured                                                        |\n| AWS NIST 7.13 | CloudWatch log metric filter and alarm for VPC route table changes should be configured                                            |\n| AWS NIST 7.14 | CloudWatch log metric filter and alarm for VPC security group changes should be configured                                         |\n| AWS NIST 8.1  | ELB listener security groups should not be set to TCP all                                                                          |\n| AWS NIST 8.2  | VPC default security group should restrict all traffic                                                                             |\n| AWS NIST 8.3  | VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 22                                                        |\n| AWS NIST 8.4  | AWS NIST 8.4 VPC network ACLs should not allow ingress from 0.0.0.0/0 to TCP/UDP port 3389                                         |\n| AWS NIST 8.5  | VPC security group inbound rules should not permit ingress from ‘0.0.0.0/0’ to all ports and protocols                             |\n| AWS NIST 8.6  | VPC security group inbound rules should not permit ingress from a public address to all ports and protocols                        |\n| AWS NIST 8.7  | VPC security group inbound rules should not permit ingress from any address to all ports and protocols                             |\n| AWS NIST 8.8  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ except to ports 80 and 443                                     |\n| AWS NIST 8.9  | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 3389 (Remote Desktop Protocol)                         |\n| AWS NIST 8.10 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 61621 (Cassandra OpsCenter Agent)              |\n| AWS NIST 8.11 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 636 (LDAP SSL)                                 |\n| AWS NIST 8.12 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 7001 (Cassandra)                               |\n| AWS NIST 8.13 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11214 (Memcached SSL)                          |\n| AWS NIST 8.14 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 11215 (Memcached SSL)                          |\n| AWS NIST 8.15 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 135 (MSSQL Debugger)                           |\n| AWS NIST 8.16 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 137 (NetBIOS Name Service)                     |\n| AWS NIST 8.17 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 138 (NetBios Datagram Service)                 |\n| AWS NIST 8.18 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 139 (NetBios Session Service)                  |\n| AWS NIST 8.19 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 1433 (MSSQL Server)                                |\n| AWS NIST 8.20 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 1434 (MSSQL Admin)                             |\n| AWS NIST 8.21 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to port 22 (SSH)                                               |\n| AWS NIST 8.22 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 23 (Telnet)                                        |\n| AWS NIST 8.23 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 2379 (etcd)                                        |\n| AWS NIST 8.24 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2382 (SQL Server Analysis Services browser)    |\n| AWS NIST 8.25 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2383 (SQL Server Analysis Services)            |\n| AWS NIST 8.26 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 2484 (Oracle DB SSL)                           |\n| AWS NIST 8.27 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27017 (MongoDB)                                    |\n| AWS NIST 8.28 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27018 (MongoDB)                                    |\n| AWS NIST 8.29 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 27019 (MongoDB)                                    |\n| AWS NIST 8.30 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3000 (Ruby on Rails web server)                |\n| AWS NIST 8.31 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3020 (CIFS / SMB)                              |\n| AWS NIST 8.32 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 3306 (MySQL)                                   |\n| AWS NIST 8.33 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4505 (SaltStack Master)                        |\n| AWS NIST 8.34 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 4506 (SaltStack Master)                        |\n| AWS NIST 8.35 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5432 (PostgreSQL)                              |\n| AWS NIST 8.36 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 5500 (Virtual Network Computing)               |\n| AWS NIST 8.37 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5800 (Virtual Network Computing), unless from ELBs |\n| AWS NIST 8.38 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 5900 (Virtual Network Computing)                   |\n| AWS NIST 8.39 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 80 (HTTP), unless from ELBs                        |\n| AWS NIST 8.40 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP/UDP port 8000 (HTTP Alternate)                          |\n| AWS NIST 8.41 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9200 (Elasticsearch)                               |\n| AWS NIST 8.42 | VPC security group rules should not permit ingress from ‘0.0.0.0/0’ to TCP port 9300 (Elasticsearch)                               |\n| AWS NIST 8.43 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 8.44 | VPC security groups attached to EC2 instances should not permit ingress from ‘0.0.0.0/0’ to TCP port 389 (LDAP)                    |\n| AWS NIST 8.45 | VPC security groups attached to RDS instances should not permit ingress from ‘0.0.0.0/0’ to all ports                              |\n| AWS NIST 9.1  | ECS container definitions should not mount volumes with mount propagation set to shared                                            |\n| AWS NIST 9.2  | ECS task definitions should mount the container’s root filesystem as read-only                                                     |\n| AWS NIST 9.3  | ECS task definitions should not add Linux capabilities beyond defaults and should drop ‘NET_RAW’                                   |\n| AWS NIST 9.4  | ECS task definitions should not mount sensitive host system directories                                                            |\n| AWS NIST 10.1 | IAM password policies should expire passwords within 90 days                                                                       |\n| AWS NIST 10.2 | IAM password policies should have a minimum length of 7 and include both alphabetic and numeric characters                         |\n| AWS NIST 10.3 | IAM password policies should prevent reuse of previously used passwords                                                            |\n| AWS NIST 10.4 | IAM password policies should prevent reuse of the four previously used passwords                                                   |\n| AWS NIST 10.5 | IAM password policies should require at least one lowercase character                                                              |\n| AWS NIST 10.6 | IAM password policies should require at least one number                                                                           |\n| AWS NIST 10.7 | IAM password policies should require at least one symbol                                                                           |\n| AWS NIST 10.8 | IAM password policies should require at least one uppercase character                                                              |\n| AWS NIST 11.1 | ECS task definitions should limit memory usage for containers                                                                      |\n| AWS NIST 11.2 | ECS task definitions should set CPU limit for containers                                                                           |\n| AWS NIST 12.1 | CloudFront distributions should have geo-restrictions specified                                                                    |\n| AWS NIST 12.2 | EC2 instances should not have a public IP association (IPv4)                                                                       |\n| AWS NIST 13.1 | IAM multi-factor authentication should be enabled for all IAM users that have a console password                                   |\n| AWS NIST 13.2 | IAM should have hardware MFA enabled for the root account                                                                          |\n| AWS NIST 13.3 | IAM should have MFA enabled for the root account                                                                                   |\n| AWS NIST 13.4 | IAM users should have MFA (virtual or hardware) enabled                                                                            |\n| AWS NIST 14.1 | CloudFront distributions should be protected by WAFs                                                                               |\n| AWS NIST 15.1 | ECS task definitions should not use the root user                                                                                  |\n| AWS NIST 15.2 | IAM roles used for trust relationships should have MFA or external IDs                                                             |\n| AWS NIST 15.3 | IAM root user access key should not exist                                                                                          |\n| AWS NIST 15.4 | IAM root user should not be used                                                                                                   |\n| AWS NIST 16.1 | API Gateway classic custom domains should use secure TLS protocol versions (1.2 and above)                                         |\n| AWS NIST 16.2 | API Gateway v2 custom domains should use secure TLS protocol versions (1.2 and above)                                              |\n| AWS NIST 16.3 | CloudFront distribution custom origins should use secure TLS protocol versions (1.2 and above)                                     |\n| AWS NIST 16.4 | CloudFront distribution viewer certificate should use secure TLS protocol versions (1.2 and above)                                 |\n| AWS NIST 16.5 | ELB HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                        |\n| AWS NIST 16.6 | ELBv2 HTTPS listeners should use secure TLS protocol versions (1.2 and above)                                                      |","readmeFilename":"README.md","gitHead":"4f9b88d1b10cae4e8e5509622bde5afa4d4a6722","_id":"@cloudgraph/policy-pack-aws-nist-800-53-rev4@1.9.1-alpha.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-2q+ifbIJNM5aSeld2AWYjLACX9ky4/YLOTBL3fLKQHr7FEQQDC/SuYB7YFj+UkDr7mKqdWx462fiyO7Qr+Y/Tw==","shasum":"77e0c0f5eaaa800f32b3331061224f51dcb63dc1","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-aws-nist-800-53-rev4/-/policy-pack-aws-nist-800-53-rev4-1.9.1-alpha.2.tgz","fileCount":257,"unpackedSize":708750,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDCpdEfP6KQL4huDo5PUKUncZKSEiSUWtXZu7aSCTxNZQIgPumdNQnhuolkYWgeRBU557s40ne2T22x80g00zmO0ps="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-aws-nist-800-53-rev4_1.9.1-alpha.2_1684337630558_0.23587940748857994"},"_hasShrinkwrap":false}},"time":{"created":"2022-02-25T19:07:02.552Z","1.0.0":"2022-02-25T19:07:02.797Z","modified":"2023-05-17T15:33:50.872Z","1.1.0":"2022-04-01T16:15:14.728Z","1.2.0":"2022-04-01T16:52:30.545Z","1.3.0":"2022-04-01T19:33:53.564Z","1.4.0-alpha.1":"2022-04-27T19:29:40.939Z","1.4.0-beta.1":"2022-05-02T18:04:46.685Z","1.4.0":"2022-05-02T19:59:50.304Z","1.5.0":"2022-05-12T18:02:30.909Z","1.6.0":"2022-05-26T20:33:05.767Z","1.6.1":"2022-06-29T14:28:35.072Z","1.7.0":"2022-07-11T16:30:38.343Z","1.7.1":"2022-07-11T19:58:41.993Z","1.8.0":"2022-08-01T22:17:01.840Z","1.8.1-alpha.1":"2022-12-14T00:44:06.298Z","1.9.0":"2023-04-28T16:57:38.969Z","1.9.1-alpha.1":"2023-05-17T14:11:11.395Z","1.9.1-alpha.2":"2023-05-17T15:33:50.707Z"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Amazon Web Services","homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/aws/nist-800-53-rev4"},"author":{"name":"AutoCloud"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"license":"MPL-2.0","readme":"","readmeFilename":""}