AWS Security Remediations Following Audit
Budget: $250 – $750 USD
Following a security Audit performed on our AWS account, we are seeking the services of Cloud infrastructure engineers to implement the critical changes identified in the Audit.
S3/ Cloudfront
• Remove all public bucket policies
• Implement CloudFront with Origin Access Control (OAC)
• Conduct comprehensive DNS audit
• Establish automated DNS monitoring procedures
RDS/ Backups
• Enable AWS Backup service for all RDS instances
• Implement cross- region replication
• Establish automated backup encryption and lifecycle policies
• Enable comprehensive RDS log exports
• Complete initial disaster recovery testing
IAM/ Monitoring
• Configure comprehensive CloudWatch alarms for IAM changes
• Enable AWS Config in all operational regions
• Restrict github-cicd-role to minimum privileges
• Implement real-time administrative action alerting
Key Management
• Migrate all critical secrets to customer-managed KMS keys
• Implement automated secret rotation procedures
• Enhanced key lifecycle management
• Update application configurations for CMK access (Will be done by our teams on your direction)
EC2/ Volumes/ VPC
• Implement systematic EBS encryption across all volumes
• Refine security group rules eliminating overly permissive access
• Enhanced network security boundaries
• Enable VPC Flow Logs across all VPCs
Encryption Key Management (HIGH)
• Migrate primary RDS instances to customer-managed KMS keys
• Establish encryption- -default policies
• Complete key lifecycle management framework
• Migrate secondary databases and EBS volumes
Disaster Recovery (HIGH)
• Initial DR testing procedures established
• Cross- region backup replication implemented
• Automated failover procedures development
• Recovery time optimization
S3/ Cloudfront
• Remove all public bucket policies
• Implement CloudFront with Origin Access Control (OAC)
• Conduct comprehensive DNS audit
• Establish automated DNS monitoring procedures
RDS/ Backups
• Enable AWS Backup service for all RDS instances
• Implement cross- region replication
• Establish automated backup encryption and lifecycle policies
• Enable comprehensive RDS log exports
• Complete initial disaster recovery testing
IAM/ Monitoring
• Configure comprehensive CloudWatch alarms for IAM changes
• Enable AWS Config in all operational regions
• Restrict github-cicd-role to minimum privileges
• Implement real-time administrative action alerting
Key Management
• Migrate all critical secrets to customer-managed KMS keys
• Implement automated secret rotation procedures
• Enhanced key lifecycle management
• Update application configurations for CMK access (Will be done by our teams on your direction)
EC2/ Volumes/ VPC
• Implement systematic EBS encryption across all volumes
• Refine security group rules eliminating overly permissive access
• Enhanced network security boundaries
• Enable VPC Flow Logs across all VPCs
Encryption Key Management (HIGH)
• Migrate primary RDS instances to customer-managed KMS keys
• Establish encryption- -default policies
• Complete key lifecycle management framework
• Migrate secondary databases and EBS volumes
Disaster Recovery (HIGH)
• Initial DR testing procedures established
• Cross- region backup replication implemented
• Automated failover procedures development
• Recovery time optimization