AuditBadger Compliance Platform
This guide explains how AuditBadger AWS evidence sources support SOC 2 and ISO 27001 control assessments and documents the default auto-verification rules. For connection setup, security, and IAM permissions, see the AWS Integration User Guide.
SOC 2 Control Coverage
The AWS integration provides evidence for the following SOC 2 (2017) Trust Services Criteria:
These mappings identify evidence that can support a control assessment. A collected configuration or finding does not, by itself, prove that the full organizational control is implemented or operating effectively.
CC6 - Logical and Physical Access Controls
CC6.1 - Logical Access Security
The entity implements logical access security software, infrastructure, and architectures to protect information assets
-
IAM Password Policy - Password complexity requirements are enforced
-
IAM MFA Status - Multi-factor authentication is enabled
-
IAM Access Keys - Access credentials are properly managed
-
S3 Encryption - Data at rest is encrypted
-
S3 Public Access Block - Data is not publicly exposed
-
RDS Encryption - Databases are encrypted
-
EBS Volume Encryption - Storage volumes are encrypted
-
KMS Key Rotation - Encryption keys are properly rotated
CC6.2 - User Registration and Authorization
Prior to issuing system credentials and granting access, the entity registers and authorizes new users
-
IAM MFA Status - Complete inventory of IAM users with access details
-
IAM Access Keys - Access key creation and authorization records
CC6.3 - Removal of Access Rights
The entity removes credentials and disables system access when no longer required
-
CloudTrail Events - Access revocation events are logged
-
IAM Access Keys - Inactive or unused access keys identified
CC6.5 - Disposal of Data
The entity disposes of data, software, and equipment to prevent unauthorized access
-
S3 Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate object lifecycle or deletion rules
-
RDS Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate database deletion procedures
CC6.6 - Logical Access Security Measures
The entity implements controls to prevent or detect and act upon unauthorized logical access
-
Security Groups - Firewall rules restrict access appropriately
-
Network ACLs - Network-level access controls are in place
-
VPC Flow Logs - Flow-log coverage is verified across VPCs
-
GuardDuty Status - Threat detection is active
-
GuardDuty Findings - Security threats are identified and tracked
CC6.7 - Data Transmission Controls
The entity restricts transmission and movement of data
-
S3 Encryption - Default encryption protects object data at rest
-
RDS Encryption - Storage encryption protects database data at rest
CC7 - System Operations
CC7.1 - Security Monitoring
The entity monitors system components for anomalies and security events
-
GuardDuty Status - Threat detection service is active
-
Security Hub Status - Security monitoring is consolidated
-
CloudWatch Alarms - Alerts are configured for security events
CC7.2 - Security Event Logging
The entity identifies and logs security events
-
CloudTrail Configuration - Audit logging is properly configured
-
CloudTrail Events - Security events are recorded
-
VPC Flow Logs - Network flow-logging coverage is verified
CC7.3 - Security Incident Response
The entity evaluates security events and responds to identified incidents
-
GuardDuty Findings - Threats are detected and tracked
-
CloudWatch Alarms - Incident alerts are configured
CC7.4 - Security Alerting
The entity responds to identified security incidents
- CloudWatch Alarms - Alarm states and notification actions provide monitoring evidence
CC8 - Change Management
CC8.1 - Change Management
The entity authorizes, documents, and controls infrastructure changes
-
CloudTrail Events - Infrastructure changes are logged
-
AWS Config Status - Configuration changes are tracked
A1 - Availability
A1.1 - System Availability
The entity maintains, monitors, and evaluates current processing capacity
-
Backup Jobs - Data can be recovered
-
RDS Snapshots - Database backups are maintained
-
CloudWatch Alarms - Availability monitoring is active
A1.2 - Recovery Procedures
The entity's recovery procedures support system recovery in accordance with recovery objectives
-
Backup Jobs - Backup procedures are executed successfully
-
RDS Snapshots - Point-in-time recovery is available
ISO 27001:2022 Control Coverage
The AWS integration provides evidence for the following ISO 27001:2022 Annex A controls:
A.5 - Organizational Controls
A.5.15 - Access Control
Rules to control physical and logical access to information and other associated assets shall be established and implemented
-
IAM Password Policy - Password policies enforce access security
-
IAM MFA Status - Strong authentication is required
-
IAM Access Keys - Access credentials are managed
-
Security Groups - Network access is controlled
A.5.16 - Identity Management
The full life cycle of identities shall be managed
-
IAM MFA Status - Complete inventory of identities
-
IAM Access Keys - Access key lifecycle management
A.5.17 - Authentication Information
Allocation and management of authentication information shall be controlled
-
IAM Password Policy - Authentication requirements are enforced
-
IAM MFA Status - MFA is properly configured
-
IAM Access Keys - Credentials are properly managed
A.5.18 - Access Rights
Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed
-
IAM Access Keys - Access key usage is reviewed
-
CloudTrail Events - Access changes are logged
A.5.23 - Cloud Services Security
Processes for acquisition, use, management and exit from cloud services shall be established
-
GuardDuty Status - Cloud threat detection is active
-
Security Hub Status - Cloud security posture is monitored
-
CloudTrail Configuration - Cloud activity is logged
A.8 - Technological Controls
A.8.1 - User Endpoint Devices
Information stored on, processed by or accessible via user endpoint devices shall be protected
- EBS Volume Encryption - Storage attached to instances is encrypted
A.8.3 - Information Access Restriction
Access to information and other associated assets shall be restricted
-
S3 Public Access Block - Data is not publicly accessible
-
Security Groups - Network access is restricted
-
Network ACLs - Network-level access controls exist
A.8.9 - Configuration Management
Configurations, including security configurations, shall be established, documented, implemented, monitored and reviewed
-
AWS Config Status - Configuration changes are tracked
-
Security Groups - Security configurations are documented
A.8.10 - Information Deletion
Information stored shall be deleted when no longer required
- S3 Encryption - Encryption configuration provides supporting data-protection context; this collector does not evaluate lifecycle or deletion policies
A.8.11 - Data Masking
Data masking shall be used in accordance with the organization's topic-specific policy
- RDS Encryption - Encryption configuration provides supporting protection context; this collector does not test application-level data masking
A.8.12 - Data Leakage Prevention
Data leakage prevention measures shall be applied
-
S3 Public Access Block - Public exposure is prevented
-
GuardDuty Findings - Data exfiltration attempts are detected
-
VPC Flow Logs - Flow-log coverage and destination configuration are checked
A.8.13 - Information Backup
Backup copies of information, software and systems shall be maintained and regularly tested
-
Backup Jobs - Backups are executed regularly
-
RDS Snapshots - Database backups are maintained
A.8.14 - Redundancy
Information processing facilities shall be implemented with sufficient redundancy to meet availability requirements
-
RDS Encryption - Multi-AZ deployment status
-
Backup Jobs - Backup plan, vault, and recent job coverage
A.8.15 - Logging
Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed
-
CloudTrail Configuration - API activity is logged
-
VPC Flow Logs - Network activity is logged
-
CloudWatch Alarms - Alarm configuration, state, and notification actions are inventoried
A.8.16 - Monitoring Activities
Networks, systems and applications shall be monitored for anomalous behaviour
-
GuardDuty Status - Threat monitoring is active
-
GuardDuty Findings - Anomalies are detected and tracked
-
CloudWatch Alarms - System monitoring is configured
-
Security Hub Status - Security posture is monitored
A.8.20 - Networks Security
Networks and network devices shall be secured, managed and controlled
-
Security Groups - Network security rules are configured
-
Network ACLs - Network access controls are in place
-
VPC Flow Logs - Network flow-logging coverage is verified
A.8.21 - Security of Network Services
Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored
-
Security Groups - Network service exposure and risky inbound rules are reviewed
-
Network ACLs - Subnet-level traffic filtering and segmentation are reviewed
A.8.24 - Use of Cryptography
Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented
-
S3 Encryption - Object storage is encrypted
-
RDS Encryption - Databases are encrypted
-
EBS Volume Encryption - Block storage is encrypted
-
KMS Key Rotation - Encryption keys are rotated
A.8.32 - Change Management
Changes to information processing facilities and information systems shall be subject to change management procedures
-
CloudTrail Events - Recent management and write events provide change activity evidence
-
AWS Config Status - Recorder, delivery channel, and configuration-rule status are checked
Verification Rules
Auto-verified evidence sources use the following defaults. Accounts can customize supported thresholds when configuring an evidence source.
IAM Password Policy
-
Minimum password length: 14 characters
-
Require uppercase letters: Yes
-
Require lowercase letters: Yes
-
Require numbers: Yes
-
Require symbols: Yes
-
Maximum password age: 90 days
-
Password reuse prevention: 24 passwords
IAM MFA Status
-
Console users with MFA: 100%
-
Root account has MFA: Required
IAM Access Keys
-
Maximum key age: 90 days
-
Active keys used within the last 90 days: Required
-
Multiple active keys per user: Not allowed
CloudTrail
-
CloudTrail enabled: Required
-
Multi-region trail: Required
-
Log file validation: Required
-
Encryption enabled: Required
S3 Security
-
Default bucket encryption: Required
-
Minimum encryption algorithm: AES-256 or AWS KMS
-
Account-level and bucket-level public access blocks: Required
RDS Encryption
- All instances encrypted: Required
RDS Snapshots
-
Snapshot coverage for RDS instances: Required
-
Maximum age of latest snapshot: 7 days
EBS and KMS
-
All EBS volumes encrypted: Required
-
Default EBS encryption enabled: Required
-
Automatic rotation for eligible customer-managed KMS keys: Required
-
Maximum key age without rotation: 365 days
Network Security
-
No open SSH (0.0.0.0/0:22): Required
-
No open RDP (0.0.0.0/0:3389): Required
-
No unrestricted all-traffic ingress: Required
-
Network ACLs must not allow unrestricted inbound traffic: Required
-
VPC Flow Logs enabled: Required
Monitoring, Security Services, and Configuration
-
CloudWatch alarms, security-relevant alarms, and notification actions: Required
-
GuardDuty enabled in at least one checked region: Required; partial regional coverage produces a warning
-
Maximum high-severity GuardDuty findings: 0
-
Security Hub enabled in at least one checked region: Required; partial regional coverage produces a warning
-
At least one Security Hub standard enabled: Required
-
Maximum critical Security Hub findings: 0
-
AWS Config enabled in at least one checked region: Required; partial regional coverage produces a warning
-
AWS Config recorder active in all enabled regions: Required
-
AWS Config rule findings: Up to 10 non-compliant rules produce a warning; more than 10 fail verification
Backup Jobs
-
AWS Backup plans and a recent successful backup: Required
-
Maximum time since successful backup: 7 days
Summary: Control Coverage Matrix
SOC 2 Controls by Evidence Source
IAM Password Policy
- CC6.1: Yes
IAM MFA Status
-
CC6.1: Yes
-
CC6.2: Yes
IAM Access Keys
-
CC6.1: Yes
-
CC6.2: Yes
-
CC6.3: Yes
CloudTrail Config
- CC7.2: Yes
CloudTrail Events
-
CC6.3: Yes
-
CC7.2: Yes
-
CC8.1: Yes
CloudWatch Alarms
-
CC7.1: Yes
-
CC7.3: Yes
-
CC7.4: Yes
-
A1.1: Yes
VPC Flow Logs
-
CC6.6: Yes
-
CC7.2: Yes
GuardDuty Status
-
CC6.6: Yes
-
CC7.1: Yes
GuardDuty Findings
-
CC6.6: Yes
-
CC7.3: Yes
Security Hub
- CC7.1: Yes
AWS Config
- CC8.1: Yes
Security Groups
- CC6.6: Yes
Network ACLs
- CC6.6: Yes
S3 Encryption
-
CC6.1: Yes
-
CC6.5: Yes
-
CC6.7: Yes
S3 Public Access
- CC6.1: Yes
RDS Encryption
-
CC6.1: Yes
-
CC6.5: Yes
-
CC6.7: Yes
EBS Encryption
- CC6.1: Yes
KMS Key Rotation
- CC6.1: Yes
Backup Jobs
-
A1.1: Yes
-
A1.2: Yes
RDS Snapshots
-
A1.1: Yes
-
A1.2: Yes
ISO 27001 Controls by Evidence Source
IAM Password Policy
-
A.5.15: Yes
-
A.5.17: Yes
IAM MFA Status
-
A.5.15: Yes
-
A.5.16: Yes
-
A.5.17: Yes
IAM Access Keys
-
A.5.15: Yes
-
A.5.16: Yes
-
A.5.17: Yes
-
A.5.18: Yes
CloudTrail Config
-
A.5.23: Yes
-
A.8.15: Yes
CloudTrail Events
-
A.5.18: Yes
-
A.8.32: Yes
CloudWatch Alarms
-
A.8.15: Yes
-
A.8.16: Yes
VPC Flow Logs
-
A.8.12: Yes
-
A.8.15: Yes
-
A.8.20: Yes
GuardDuty Status
-
A.5.23: Yes
-
A.8.16: Yes
GuardDuty Findings
-
A.8.12: Yes
-
A.8.16: Yes
Security Hub
-
A.5.23: Yes
-
A.8.16: Yes
AWS Config
-
A.8.9: Yes
-
A.8.32: Yes
Security Groups
-
A.5.15: Yes
-
A.8.3: Yes
-
A.8.9: Yes
-
A.8.20: Yes
-
A.8.21: Yes
Network ACLs
-
A.8.3: Yes
-
A.8.20: Yes
-
A.8.21: Yes
S3 Encryption
-
A.8.10: Yes
-
A.8.24: Yes
S3 Public Access
-
A.8.3: Yes
-
A.8.9: Yes
-
A.8.12: Yes
RDS Encryption
-
A.8.11: Yes
-
A.8.14: Yes
-
A.8.24: Yes
EBS Encryption
-
A.8.1: Yes
-
A.8.24: Yes
KMS Key Rotation
- A.8.24: Yes
Backup Jobs
-
A.8.13: Yes
-
A.8.14: Yes
RDS Snapshots
- A.8.13: Yes
Related Documentation
Last updated: July 2026