Skip to main content

AWS Audit

AWS audit deliverables

Every audit produces a set of documents for three audiences: engineering teams, the CISO and leadership.

Reports are currently written in French.

DeliverableFormatFor
10 domain reportsFindings ranked by severity, affected resources (ARNs, IDs) and corrective actions with expected gains.Word and PDFCloud and security teams
Kill-chain report5 to 10 attack scenarios chaining findings from several domains. They drive remediation priorities.Word and PDFCISO
Remediation planTechnical summary of the actions, prioritised P0, P1 and P2. An action that breaks several attack scenarios is raised to P0.Word and PDFCloud teams
Action planPrioritised actions, per-domain summary, Gantt, Pareto and return on investment.ExcelProject steering
Executive summaryA narrative summary: current state, major risks and recommended trajectory.Word and PDF, 5 pagesLeadership, CISO
Board deckOverall verdict, scores for the ten domains, top five risks, flagship attack scenario and roadmap.HTML and PDF, 19 slidesExecutive committee
DAST results (option)OWASP ZAP alerts on your public endpoints are analysed in the web security report.Included in the web security reportApplication teams

Sample deliverables

Two board decks produced on demo environments. Companies and data are fictitious. Samples are shown in English; delivered reports are currently written in French.

  • E-commerce - Maison Verano (demo)

    1 AWS account, 2 regions, 2,146 resources, 142 findings, DAST scan enabled. Overall score: 74/100.

  • Fintech - Kaelis Pay (demo)

    1 AWS account, 3 regions, 1,284 resources, 187 findings, DAST scan enabled. Overall score: 52/100.

Delivery

Deliverables are emailed to the address verified at sign-up, as a ZIP archive and as individual downloads. They remain available for 7 days, then are deleted automatically.

Ready to audit your AWS account?

Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.