How it works...

The four checks provided for free with this service are:

  • Unrestricted ports: This is a check on the highest risk ports in your security groups. They'll be flagged if they're open to everyone (0.0.0.0/0).
  • IAM usage: This is a fairly rudimentary check. If there isn't at least one IAM user in your account this check won't pass. It's considered good practice to not use your root login credentials for your AWS account and instead create IAM users with least privilege access.
  • MFA on root account: This is also a fairly rudimentary check. You need to have MFA enabled for your root login in order for this check to pass. It's obviously a good idea to enable MFA for your IAM users too.
  • Service limits: This one is quite handy: if you're ...

Get AWS Administration Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.