AWS Integration Control Coverage Guide

M

Maciej Litwiniuk

Last updated on Jul 29, 2026

AuditBadger Compliance Platform

This guide explains how AuditBadger AWS evidence sources support SOC 2 and ISO 27001 control assessments and documents the default auto-verification rules. For connection setup, security, and IAM permissions, see the AWS Integration User Guide.


SOC 2 Control Coverage

The AWS integration provides evidence for the following SOC 2 (2017) Trust Services Criteria:

These mappings identify evidence that can support a control assessment. A collected configuration or finding does not, by itself, prove that the full organizational control is implemented or operating effectively.

CC6 - Logical and Physical Access Controls

CC6.1 - Logical Access Security

The entity implements logical access security software, infrastructure, and architectures to protect information assets

  • IAM Password Policy - Password complexity requirements are enforced

  • IAM MFA Status - Multi-factor authentication is enabled

  • IAM Access Keys - Access credentials are properly managed

  • S3 Encryption - Data at rest is encrypted

  • S3 Public Access Block - Data is not publicly exposed

  • RDS Encryption - Databases are encrypted

  • EBS Volume Encryption - Storage volumes are encrypted

  • KMS Key Rotation - Encryption keys are properly rotated

CC6.2 - User Registration and Authorization

Prior to issuing system credentials and granting access, the entity registers and authorizes new users

  • IAM MFA Status - Complete inventory of IAM users with access details

  • IAM Access Keys - Access key creation and authorization records

CC6.3 - Removal of Access Rights

The entity removes credentials and disables system access when no longer required

  • CloudTrail Events - Access revocation events are logged

  • IAM Access Keys - Inactive or unused access keys identified

CC6.5 - Disposal of Data

The entity disposes of data, software, and equipment to prevent unauthorized access

  • S3 Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate object lifecycle or deletion rules

  • RDS Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate database deletion procedures

CC6.6 - Logical Access Security Measures

The entity implements controls to prevent or detect and act upon unauthorized logical access

  • Security Groups - Firewall rules restrict access appropriately

  • Network ACLs - Network-level access controls are in place

  • VPC Flow Logs - Flow-log coverage is verified across VPCs

  • GuardDuty Status - Threat detection is active

  • GuardDuty Findings - Security threats are identified and tracked

CC6.7 - Data Transmission Controls

The entity restricts transmission and movement of data

  • S3 Encryption - Default encryption protects object data at rest

  • RDS Encryption - Storage encryption protects database data at rest

CC7 - System Operations

CC7.1 - Security Monitoring

The entity monitors system components for anomalies and security events

  • GuardDuty Status - Threat detection service is active

  • Security Hub Status - Security monitoring is consolidated

  • CloudWatch Alarms - Alerts are configured for security events

CC7.2 - Security Event Logging

The entity identifies and logs security events

  • CloudTrail Configuration - Audit logging is properly configured

  • CloudTrail Events - Security events are recorded

  • VPC Flow Logs - Network flow-logging coverage is verified

CC7.3 - Security Incident Response

The entity evaluates security events and responds to identified incidents

  • GuardDuty Findings - Threats are detected and tracked

  • CloudWatch Alarms - Incident alerts are configured

CC7.4 - Security Alerting

The entity responds to identified security incidents

  • CloudWatch Alarms - Alarm states and notification actions provide monitoring evidence

CC8 - Change Management

CC8.1 - Change Management

The entity authorizes, documents, and controls infrastructure changes

  • CloudTrail Events - Infrastructure changes are logged

  • AWS Config Status - Configuration changes are tracked

A1 - Availability

A1.1 - System Availability

The entity maintains, monitors, and evaluates current processing capacity

  • Backup Jobs - Data can be recovered

  • RDS Snapshots - Database backups are maintained

  • CloudWatch Alarms - Availability monitoring is active

A1.2 - Recovery Procedures

The entity's recovery procedures support system recovery in accordance with recovery objectives

  • Backup Jobs - Backup procedures are executed successfully

  • RDS Snapshots - Point-in-time recovery is available


ISO 27001:2022 Control Coverage

The AWS integration provides evidence for the following ISO 27001:2022 Annex A controls:

A.5 - Organizational Controls

A.5.15 - Access Control

Rules to control physical and logical access to information and other associated assets shall be established and implemented

  • IAM Password Policy - Password policies enforce access security

  • IAM MFA Status - Strong authentication is required

  • IAM Access Keys - Access credentials are managed

  • Security Groups - Network access is controlled

A.5.16 - Identity Management

The full life cycle of identities shall be managed

  • IAM MFA Status - Complete inventory of identities

  • IAM Access Keys - Access key lifecycle management

A.5.17 - Authentication Information

Allocation and management of authentication information shall be controlled

  • IAM Password Policy - Authentication requirements are enforced

  • IAM MFA Status - MFA is properly configured

  • IAM Access Keys - Credentials are properly managed

A.5.18 - Access Rights

Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed

  • IAM Access Keys - Access key usage is reviewed

  • CloudTrail Events - Access changes are logged

A.5.23 - Cloud Services Security

Processes for acquisition, use, management and exit from cloud services shall be established

  • GuardDuty Status - Cloud threat detection is active

  • Security Hub Status - Cloud security posture is monitored

  • CloudTrail Configuration - Cloud activity is logged

A.8 - Technological Controls

A.8.1 - User Endpoint Devices

Information stored on, processed by or accessible via user endpoint devices shall be protected

  • EBS Volume Encryption - Storage attached to instances is encrypted

A.8.3 - Information Access Restriction

Access to information and other associated assets shall be restricted

  • S3 Public Access Block - Data is not publicly accessible

  • Security Groups - Network access is restricted

  • Network ACLs - Network-level access controls exist

A.8.9 - Configuration Management

Configurations, including security configurations, shall be established, documented, implemented, monitored and reviewed

  • AWS Config Status - Configuration changes are tracked

  • Security Groups - Security configurations are documented

A.8.10 - Information Deletion

Information stored shall be deleted when no longer required

  • S3 Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate lifecycle or deletion policies

A.8.11 - Data Masking

Data masking shall be used in accordance with the organization's topic-specific policy

  • RDS Encryption - Encryption configuration provides supporting protection context; this collector does not test application-level data masking

A.8.12 - Data Leakage Prevention

Data leakage prevention measures shall be applied

  • S3 Public Access Block - Public exposure is prevented

  • GuardDuty Findings - Data exfiltration attempts are detected

  • VPC Flow Logs - Flow-log coverage and destination configuration are checked

A.8.13 - Information Backup

Backup copies of information, software and systems shall be maintained and regularly tested

  • Backup Jobs - Backups are executed regularly

  • RDS Snapshots - Database backups are maintained

A.8.14 - Redundancy

Information processing facilities shall be implemented with sufficient redundancy to meet availability requirements

  • RDS Encryption - Multi-AZ deployment status

  • Backup Jobs - Backup plan, vault, and recent job coverage

A.8.15 - Logging

Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed

  • CloudTrail Configuration - API activity is logged

  • VPC Flow Logs - Network activity is logged

  • CloudWatch Alarms - Alarm configuration, state, and notification actions are inventoried

A.8.16 - Monitoring Activities

Networks, systems and applications shall be monitored for anomalous behaviour

  • GuardDuty Status - Threat monitoring is active

  • GuardDuty Findings - Anomalies are detected and tracked

  • CloudWatch Alarms - System monitoring is configured

  • Security Hub Status - Security posture is monitored

A.8.20 - Networks Security

Networks and network devices shall be secured, managed and controlled

  • Security Groups - Network security rules are configured

  • Network ACLs - Network access controls are in place

  • VPC Flow Logs - Network flow-logging coverage is verified

A.8.21 - Security of Network Services

Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored

  • Security Groups - Network service exposure and risky inbound rules are reviewed

  • Network ACLs - Subnet-level traffic filtering and segmentation are reviewed

A.8.24 - Use of Cryptography

Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented

  • S3 Encryption - Object storage is encrypted

  • RDS Encryption - Databases are encrypted

  • EBS Volume Encryption - Block storage is encrypted

  • KMS Key Rotation - Encryption keys are rotated

A.8.32 - Change Management

Changes to information processing facilities and information systems shall be subject to change management procedures

  • CloudTrail Events - Recent management and write events provide change activity evidence

  • AWS Config Status - Recorder, delivery channel, and configuration-rule status are checked


Verification Rules

Auto-verified evidence sources use the following defaults. Accounts can customize supported thresholds when configuring an evidence source.

IAM Password Policy

  • Minimum password length: 14 characters

  • Require uppercase letters: Yes

  • Require lowercase letters: Yes

  • Require numbers: Yes

  • Require symbols: Yes

  • Maximum password age: 90 days

  • Password reuse prevention: 24 passwords

IAM MFA Status

  • Console users with MFA: 100%

  • Root account has MFA: Required

IAM Access Keys

  • Maximum key age: 90 days

  • Active keys used within the last 90 days: Required

  • Multiple active keys per user: Not allowed

CloudTrail

  • CloudTrail enabled: Required

  • Multi-region trail: Required

  • Log file validation: Required

  • Encryption enabled: Required

S3 Security

  • Default bucket encryption: Required

  • Minimum encryption algorithm: AES-256 or AWS KMS

  • Account-level and bucket-level public access blocks: Required

RDS Encryption

  • All instances encrypted: Required

RDS Snapshots

  • Snapshot coverage for RDS instances: Required

  • Maximum age of latest snapshot: 7 days

EBS and KMS

  • All EBS volumes encrypted: Required

  • Default EBS encryption enabled: Required

  • Automatic rotation for eligible customer-managed KMS keys: Required

  • Maximum key age without rotation: 365 days

Network Security

  • No open SSH (0.0.0.0/0:22): Required

  • No open RDP (0.0.0.0/0:3389): Required

  • No unrestricted all-traffic ingress: Required

  • Network ACLs must not allow unrestricted inbound traffic: Required

  • VPC Flow Logs enabled: Required

Monitoring, Security Services, and Configuration

  • CloudWatch alarms, security-relevant alarms, and notification actions: Required

  • GuardDuty enabled in at least one checked region: Required; partial regional coverage produces a warning

  • Maximum high-severity GuardDuty findings: 0

  • Security Hub enabled in at least one checked region: Required; partial regional coverage produces a warning

  • At least one Security Hub standard enabled: Required

  • Maximum critical Security Hub findings: 0

  • AWS Config enabled in at least one checked region: Required; partial regional coverage produces a warning

  • AWS Config recorder active in all enabled regions: Required

  • AWS Config rule findings: Up to 10 non-compliant rules produce a warning; more than 10 fail verification

Backup Jobs

  • AWS Backup plans and a recent successful backup: Required

  • Maximum time since successful backup: 7 days


Summary: Control Coverage Matrix

SOC 2 Controls by Evidence Source

IAM Password Policy

  • CC6.1: Yes

IAM MFA Status

  • CC6.1: Yes

  • CC6.2: Yes

IAM Access Keys

  • CC6.1: Yes

  • CC6.2: Yes

  • CC6.3: Yes

CloudTrail Config

  • CC7.2: Yes

CloudTrail Events

  • CC6.3: Yes

  • CC7.2: Yes

  • CC8.1: Yes

CloudWatch Alarms

  • CC7.1: Yes

  • CC7.3: Yes

  • CC7.4: Yes

  • A1.1: Yes

VPC Flow Logs

  • CC6.6: Yes

  • CC7.2: Yes

GuardDuty Status

  • CC6.6: Yes

  • CC7.1: Yes

GuardDuty Findings

  • CC6.6: Yes

  • CC7.3: Yes

Security Hub

  • CC7.1: Yes

AWS Config

  • CC8.1: Yes

Security Groups

  • CC6.6: Yes

Network ACLs

  • CC6.6: Yes

S3 Encryption

  • CC6.1: Yes

  • CC6.5: Yes

  • CC6.7: Yes

S3 Public Access

  • CC6.1: Yes

RDS Encryption

  • CC6.1: Yes

  • CC6.5: Yes

  • CC6.7: Yes

EBS Encryption

  • CC6.1: Yes

KMS Key Rotation

  • CC6.1: Yes

Backup Jobs

  • A1.1: Yes

  • A1.2: Yes

RDS Snapshots

  • A1.1: Yes

  • A1.2: Yes

ISO 27001 Controls by Evidence Source

IAM Password Policy

  • A.5.15: Yes

  • A.5.17: Yes

IAM MFA Status

  • A.5.15: Yes

  • A.5.16: Yes

  • A.5.17: Yes

IAM Access Keys

  • A.5.15: Yes

  • A.5.16: Yes

  • A.5.17: Yes

  • A.5.18: Yes

CloudTrail Config

  • A.5.23: Yes

  • A.8.15: Yes

CloudTrail Events

  • A.5.18: Yes

  • A.8.32: Yes

CloudWatch Alarms

  • A.8.15: Yes

  • A.8.16: Yes

VPC Flow Logs

  • A.8.12: Yes

  • A.8.15: Yes

  • A.8.20: Yes

GuardDuty Status

  • A.5.23: Yes

  • A.8.16: Yes

GuardDuty Findings

  • A.8.12: Yes

  • A.8.16: Yes

Security Hub

  • A.5.23: Yes

  • A.8.16: Yes

AWS Config

  • A.8.9: Yes

  • A.8.32: Yes

Security Groups

  • A.5.15: Yes

  • A.8.3: Yes

  • A.8.9: Yes

  • A.8.20: Yes

  • A.8.21: Yes

Network ACLs

  • A.8.3: Yes

  • A.8.20: Yes

  • A.8.21: Yes

S3 Encryption

  • A.8.10: Yes

  • A.8.24: Yes

S3 Public Access

  • A.8.3: Yes

  • A.8.9: Yes

  • A.8.12: Yes

RDS Encryption

  • A.8.11: Yes

  • A.8.14: Yes

  • A.8.24: Yes

EBS Encryption

  • A.8.1: Yes

  • A.8.24: Yes

KMS Key Rotation

  • A.8.24: Yes

Backup Jobs

  • A.8.13: Yes

  • A.8.14: Yes

RDS Snapshots

  • A.8.13: Yes

Related Documentation


Last updated: July 2026