## **Overview**

AuditBadger's AWS integration automatically collects compliance evidence from your Amazon Web Services infrastructure. Once connected, it runs checks on configured schedules and gathers evidence that supports assessments for SOC 2 and ISO 27001 compliance frameworks.

### **Key Benefits**

* **Automated evidence collection** - No more manual screenshots or exports

* **Compliance-focused collection** - Evidence collected on schedule (weekly or monthly)

* **Auto-verification** - Many evidence sources are automatically checked against compliance rules

* **Multi-framework support** - A single integration provides evidence that can support controls across SOC 2 and ISO 27001

### **Security Model**

* **Read-only access** - AuditBadger cannot modify your AWS resources

* **Cross-account role assumption** - Secure AWS STS-based authentication

* **External ID protection** - Prevents confused deputy attacks

* **Auditable sessions** - AWS API activity is attributable to the assumed AuditBadger role session in CloudTrail where AWS records the relevant management events

Existing roles created under the previous `HumadroidComplianceRole` name can remain connected. New setup instructions use `AuditBadgerComplianceRole` by default.

---

## **Evidence Sources**

The AWS integration collects 20 distinct evidence types across six categories:

### **Identity & Access Management**

**IAM Password Policy**

* Description: Verifies password complexity, length, expiration, and reuse requirements

* Frequency: Monthly

* Auto-Verify: Yes

**IAM MFA Status**

* Description: Verifies multi-factor authentication is enabled for all users including root

* Frequency: Monthly

* Auto-Verify: Yes

**IAM Access Keys**

* Description: Monitors access key rotation, usage patterns, and lifecycle

* Frequency: Monthly

* Auto-Verify: Yes

### **Logging & Monitoring**

**CloudTrail Configuration**

* Description: Verifies audit logging is enabled and properly configured

* Frequency: Monthly

* Auto-Verify: Yes

**CloudTrail Events**

* Description: Audit trail of API calls and management events

* Frequency: Monthly

* Auto-Verify: No

**CloudWatch Alarms**

* Description: System monitoring and alerting configuration

* Frequency: Monthly

* Auto-Verify: Yes

**VPC Flow Logs**

* Description: Network traffic logging configuration

* Frequency: Monthly

* Auto-Verify: Yes

### **Security Services**

**GuardDuty Status**

* Description: Threat detection service status and configuration

* Frequency: Monthly

* Auto-Verify: Yes

**GuardDuty Findings**

* Description: Security threats and anomalies detected

* Frequency: Weekly

* Auto-Verify: No

**Security Hub Status**

* Description: Consolidated security findings service status

* Frequency: Monthly

* Auto-Verify: Yes

**AWS Config Status**

* Description: Configuration change tracking service status

* Frequency: Monthly

* Auto-Verify: Yes

### **Network Security**

**Security Groups**

* Description: Network security rules and firewall configuration

* Frequency: Monthly

* Auto-Verify: Yes

**Network ACLs**

* Description: Network access control list rules

* Frequency: Monthly

* Auto-Verify: Yes

### **Encryption & Data Protection**

**S3 Bucket Encryption**

* Description: Verifies all S3 buckets have encryption enabled

* Frequency: Monthly

* Auto-Verify: Yes

**S3 Public Access Block**

* Description: Verifies S3 buckets block public access

* Frequency: Monthly

* Auto-Verify: Yes

**RDS Encryption**

* Description: Checks RDS storage encryption, public accessibility, and Multi-AZ configuration

* Frequency: Monthly

* Auto-Verify: Yes

**EBS Volume Encryption**

* Description: Verifies EBS volumes are encrypted

* Frequency: Monthly

* Auto-Verify: Yes

**KMS Key Rotation**

* Description: Verifies KMS keys are configured for automatic rotation

* Frequency: Monthly

* Auto-Verify: Yes

### **Backup & Recovery**

**AWS Backup Jobs**

* Description: Backup execution and success monitoring

* Frequency: Weekly

* Auto-Verify: Yes

**RDS Snapshots**

* Description: Checks automated and manual snapshot coverage, retention settings, and snapshot encryption

* Frequency: Monthly

* Auto-Verify: Yes

---

## **Compliance Coverage and Verification**

For the detailed SOC 2 and ISO 27001 mappings, default verification rules, and evidence-to-control matrix, see the [AWS Integration Control Coverage Guide](guide_aws-integration-control-coverage.md).

---

## **Getting Started**

To set up the AWS integration:

1. Navigate to **Settings** > **Integrations** > **AWS**

2. Click **Connect AWS Account**

3. Follow the setup wizard to create an IAM role in your AWS account

4. Paste the Role ARN and validate the connection

5. Enable evidence sources for your compliance controls

For detailed setup instructions, see the [AWS Setup Guide](guide_aws-setup.md).

---

## **AWS Permissions Required**

The AuditBadger CloudFormation template creates a cross-account role with:

* the AWS-managed [`SecurityAudit`](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SecurityAudit.html) policy

* an AuditBadger inline policy for the integration's evidence checks

* a trust policy restricted by the customer-specific external ID

AWS maintains `SecurityAudit` and can change its permissions independently. Its effective permissions are broader than the API operations AuditBadger's current evidence collectors call.

### **API Operations Used by AuditBadger**

The current integration and shipped AWS evidence collectors use these operations:

**Connection and region discovery**

```
sts:GetCallerIdentity
iam:ListAccountAliases
ec2:DescribeRegions
```

**IAM**

```
iam:GetAccountPasswordPolicy
iam:ListUsers
iam:ListMFADevices
iam:GetLoginProfile
iam:ListAccessKeys
iam:GetAccessKeyLastUsed
iam:GetAccountSummary
```

**CloudTrail, CloudWatch, and AWS Config**

```
cloudtrail:DescribeTrails
cloudtrail:GetTrailStatus
cloudtrail:LookupEvents
cloudwatch:DescribeAlarms
config:DescribeConfigurationRecorders
config:DescribeConfigurationRecorderStatus
config:DescribeDeliveryChannels
config:DescribeConfigRules
config:GetComplianceSummaryByConfigRule
```

**GuardDuty and Security Hub**

```
guardduty:ListDetectors
guardduty:GetDetector
guardduty:ListFindings
guardduty:GetFindings
securityhub:DescribeHub
securityhub:GetEnabledStandards
securityhub:GetFindings
```

**EC2 networking and EBS**

```
ec2:DescribeVpcs
ec2:DescribeFlowLogs
ec2:DescribeSecurityGroups
ec2:DescribeNetworkAcls
ec2:DescribeVolumes
ec2:GetEbsEncryptionByDefault
```

**S3**

```
s3:ListAllMyBuckets
s3:GetBucketLocation
s3:GetBucketEncryption
s3:GetAccountPublicAccessBlock
s3:GetBucketPublicAccessBlock
```

**RDS**

```
rds:DescribeDBInstances
rds:DescribeDBSnapshots
```

**KMS and AWS Backup**

```
kms:ListKeys
kms:DescribeKey
kms:GetKeyRotationStatus
backup:ListBackupPlans
backup:ListBackupVaults
backup:ListBackupJobs
```

The CloudFormation role grants a superset of this list. Do not assume that the inline policy alone is a complete replacement for `SecurityAudit`; validate all operations above when creating a narrower custom role.

### **RDS Database Log Contents**

The AWS-managed `SecurityAudit` policy currently includes:

```
rds:DownloadDBLogFilePortion
```

AWS documents this action as permission to download all or part of an RDS database log file. AuditBadger does not call this operation, and no current evidence check retrieves or stores RDS database log contents.

The two RDS evidence checks use only:

* **RDS Encryption** - `rds:DescribeDBInstances`

* **RDS Snapshots** - `rds:DescribeDBInstances` and `rds:DescribeDBSnapshots`

Customers can explicitly deny `rds:DownloadDBLogFilePortion` on the AuditBadger role without affecting current evidence collection. Under AWS IAM policy evaluation, an explicit deny overrides an allow inherited from `SecurityAudit`.

For the operation definition, see the AWS [`DownloadDBLogFilePortion`](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DownloadDBLogFilePortion.html)[ API reference](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DownloadDBLogFilePortion.html). For deny behavior, see [AWS IAM policy evaluation logic](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html).


