| Long-lived IAM access keys on human users | Critical | Migration to IAM Identity Center with SSO and temporary roles; key rotation and removal | CIS 1.4 · ENS op.acc |
Policies with * in action and resource | Critical | Least privilege derived from IAM Access Analyzer and real activity over the last 90 days | CIS 1.16 · ISO A.9 |
| Publicly accessible S3 buckets or RDS snapshots | Critical | Account-level Block Public Access, reviewed bucket policies and alerts on changes | CIS 2.1 · SOC 2 CC6 |
| CloudTrail without multi-region coverage or integrity | High | Organisation trail, integrity validation and retention in an isolated log account | CIS 3.1 · ENS op.exp |
| Security groups open to 0.0.0.0/0 on SSH or RDP | High | Access via Systems Manager Session Manager; removal of exposed admin ports | CIS 5.2 |
| Secrets in environment variables or in the repository | High | Secrets Manager with rotation, secret scanning in CI and revocation of exposed ones | ISO A.9.4 · SOC 2 CC6 |
| Container images neither scanned nor signed | Medium | Inspector on ECR, signing with Signer and admission policy on EKS | SLSA · ISO A.14 |
| No response plan or restore tests | Medium | Runbooks, incident drill and quarterly backup restore test | ISO A.16 · ENS op.cont |