AWS Audit
The 10 domains covered by the AWS audit
Ten domains are analysed in every audit, across the regions you choose, from the configuration of your AWS account.
The ten domains
Inventory
Map of your resources (EC2, RDS, Lambda, S3, DynamoDB…) and tagging quality.
Security
Compliance with AWS Foundational Security Best Practices v1.0.0 and the CIS AWS Foundations Benchmark v3.0.0.
FinOps
Cost optimisation: Cost Explorer, Reserved Instances, Savings Plans, Compute Optimizer.
Well-Architected
The six pillars of the AWS Well-Architected Framework, with Trusted Advisor and AWS Config.
Resilience
Backups, disaster recovery, multi-AZ deployments, RTO and RPO objectives.
Network
VPCs, subnets, routing, peering, VPN, Transit Gateway, NACLs and security groups.
Web security
CloudFront, ALB, API Gateway, WAF, Shield, HTTP headers, TLS and certificates.
IAM
Users, roles, policies, MFA, access key age and excessive privileges.
Containers and serverless
ECS, EKS, Lambda and App Runner: configuration, exposure and best practices.
Secrets and encryption
KMS, Secrets Manager, key and secret rotation, encryption at rest.
Frameworks
- AWS Foundational Security Best Practices v1.0.0 - the AWS Security Hub security standard.
- CIS AWS Foundations Benchmark v3.0.0 - the Center for Internet Security hardening baseline.
- AWS Well-Architected Framework - operational excellence, security, reliability, performance, cost and sustainability.
Optional DAST scan
On request, an OWASP ZAP scan tests the public endpoints of your account, discovered automatically (CloudFront, API Gateway, ALB). Two modes: baseline, passive, up to 20 targets; full, active, with attack payloads, up to 10 targets. A scan failure does not stop the audit.
Regions
20 commercial regions are offered (Europe, North America, Asia Pacific, South America). Opt-in regions, GovCloud and China are not covered.
What the audit does not do
The audit reads configuration: it modifies no resource, installs no agent, and does not replace a manual penetration test or a certification.
Ready to audit your AWS account?
Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.