Glossary

    CIS Benchmark

    Compliance & Governance

    The CIS AWS Foundations Benchmark is a set of security configuration best practices published by the Center for Internet Security. It provides a prescriptive checklist covering IAM, logging, monitoring, networking, and storage security.

    Versions

    • v6.0: latest version (2025)
    • v5.0: latest version supported by Security Hub automated checks (also supports v3.0, v1.4, v1.2)

    Key Control Areas

    • IAM - password policies, MFA, access key rotation, root account lockdown
    • Logging - CloudTrail enabled in all regions, log file validation, S3 access logging
    • Monitoring - CloudWatch alarms for unauthorized API calls, console sign-in without MFA
    • Networking - restrict default security groups, enable VPC Flow Logs

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.