**AuditBadger Compliance Platform**

This guide explains how AuditBadger AWS evidence sources support SOC 2 and ISO 27001 control assessments and documents the default auto-verification rules. For connection setup, security, and IAM permissions, see the [AWS Integration User Guide](guide_aws-integration.md).

---

## **SOC 2 Control Coverage**

The AWS integration provides evidence for the following SOC 2 (2017) Trust Services Criteria:

These mappings identify evidence that can support a control assessment. A collected configuration or finding does not, by itself, prove that the full organizational control is implemented or operating effectively.

### **CC6 - Logical and Physical Access Controls**

#### **CC6.1 - Logical Access Security**

> *The entity implements logical access security software, infrastructure, and architectures to protect information assets*

* **IAM Password Policy** - Password complexity requirements are enforced

* **IAM MFA Status** - Multi-factor authentication is enabled

* **IAM Access Keys** - Access credentials are properly managed

* **S3 Encryption** - Data at rest is encrypted

* **S3 Public Access Block** - Data is not publicly exposed

* **RDS Encryption** - Databases are encrypted

* **EBS Volume Encryption** - Storage volumes are encrypted

* **KMS Key Rotation** - Encryption keys are properly rotated

#### **CC6.2 - User Registration and Authorization**

> *Prior to issuing system credentials and granting access, the entity registers and authorizes new users*

* **IAM MFA Status** - Complete inventory of IAM users with access details

* **IAM Access Keys** - Access key creation and authorization records

#### **CC6.3 - Removal of Access Rights**

> *The entity removes credentials and disables system access when no longer required*

* **CloudTrail Events** - Access revocation events are logged

* **IAM Access Keys** - Inactive or unused access keys identified

#### **CC6.5 - Disposal of Data**

> *The entity disposes of data, software, and equipment to prevent unauthorized access*

* **S3 Encryption** - Encryption configuration provides supporting data-protection context; this collector does not evaluate object lifecycle or deletion rules

* **RDS Encryption** - Encryption configuration provides supporting data-protection context; this collector does not evaluate database deletion procedures

#### **CC6.6 - Logical Access Security Measures**

> *The entity implements controls to prevent or detect and act upon unauthorized logical access*

* **Security Groups** - Firewall rules restrict access appropriately

* **Network ACLs** - Network-level access controls are in place

* **VPC Flow Logs** - Flow-log coverage is verified across VPCs

* **GuardDuty Status** - Threat detection is active

* **GuardDuty Findings** - Security threats are identified and tracked

#### **CC6.7 - Data Transmission Controls**

> *The entity restricts transmission and movement of data*

* **S3 Encryption** - Default encryption protects object data at rest

* **RDS Encryption** - Storage encryption protects database data at rest

### **CC7 - System Operations**

#### **CC7.1 - Security Monitoring**

> *The entity monitors system components for anomalies and security events*

* **GuardDuty Status** - Threat detection service is active

* **Security Hub Status** - Security monitoring is consolidated

* **CloudWatch Alarms** - Alerts are configured for security events

#### **CC7.2 - Security Event Logging**

> *The entity identifies and logs security events*

* **CloudTrail Configuration** - Audit logging is properly configured

* **CloudTrail Events** - Security events are recorded

* **VPC Flow Logs** - Network flow-logging coverage is verified

#### **CC7.3 - Security Incident Response**

> *The entity evaluates security events and responds to identified incidents*

* **GuardDuty Findings** - Threats are detected and tracked

* **CloudWatch Alarms** - Incident alerts are configured

#### **CC7.4 - Security Alerting**

> *The entity responds to identified security incidents*

* **CloudWatch Alarms** - Alarm states and notification actions provide monitoring evidence

### **CC8 - Change Management**

#### **CC8.1 - Change Management**

> *The entity authorizes, documents, and controls infrastructure changes*

* **CloudTrail Events** - Infrastructure changes are logged

* **AWS Config Status** - Configuration changes are tracked

### **A1 - Availability**

#### **A1.1 - System Availability**

> *The entity maintains, monitors, and evaluates current processing capacity*

* **Backup Jobs** - Data can be recovered

* **RDS Snapshots** - Database backups are maintained

* **CloudWatch Alarms** - Availability monitoring is active

#### **A1.2 - Recovery Procedures**

> *The entity's recovery procedures support system recovery in accordance with recovery objectives*

* **Backup Jobs** - Backup procedures are executed successfully

* **RDS Snapshots** - Point-in-time recovery is available

---

## **ISO 27001:2022 Control Coverage**

The AWS integration provides evidence for the following ISO 27001:2022 Annex A controls:

### **A.5 - Organizational Controls**

#### **A.5.15 - Access Control**

> *Rules to control physical and logical access to information and other associated assets shall be established and implemented*

* **IAM Password Policy** - Password policies enforce access security

* **IAM MFA Status** - Strong authentication is required

* **IAM Access Keys** - Access credentials are managed

* **Security Groups** - Network access is controlled

#### **A.5.16 - Identity Management**

> *The full life cycle of identities shall be managed*

* **IAM MFA Status** - Complete inventory of identities

* **IAM Access Keys** - Access key lifecycle management

#### **A.5.17 - Authentication Information**

> *Allocation and management of authentication information shall be controlled*

* **IAM Password Policy** - Authentication requirements are enforced

* **IAM MFA Status** - MFA is properly configured

* **IAM Access Keys** - Credentials are properly managed

#### **A.5.18 - Access Rights**

> *Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed*

* **IAM Access Keys** - Access key usage is reviewed

* **CloudTrail Events** - Access changes are logged

#### **A.5.23 - Cloud Services Security**

> *Processes for acquisition, use, management and exit from cloud services shall be established*

* **GuardDuty Status** - Cloud threat detection is active

* **Security Hub Status** - Cloud security posture is monitored

* **CloudTrail Configuration** - Cloud activity is logged

### **A.8 - Technological Controls**

#### **A.8.1 - User Endpoint Devices**

> *Information stored on, processed by or accessible via user endpoint devices shall be protected*

* **EBS Volume Encryption** - Storage attached to instances is encrypted

#### **A.8.3 - Information Access Restriction**

> *Access to information and other associated assets shall be restricted*

* **S3 Public Access Block** - Data is not publicly accessible

* **Security Groups** - Network access is restricted

* **Network ACLs** - Network-level access controls exist

#### **A.8.9 - Configuration Management**

> *Configurations, including security configurations, shall be established, documented, implemented, monitored and reviewed*

* **AWS Config Status** - Configuration changes are tracked

* **Security Groups** - Security configurations are documented

#### **A.8.10 - Information Deletion**

> *Information stored shall be deleted when no longer required*

* **S3 Encryption** - Encryption configuration provides supporting data-protection context; this collector does not evaluate lifecycle or deletion policies

#### **A.8.11 - Data Masking**

> *Data masking shall be used in accordance with the organization's topic-specific policy*

* **RDS Encryption** - Encryption configuration provides supporting protection context; this collector does not test application-level data masking

#### **A.8.12 - Data Leakage Prevention**

> *Data leakage prevention measures shall be applied*

* **S3 Public Access Block** - Public exposure is prevented

* **GuardDuty Findings** - Data exfiltration attempts are detected

* **VPC Flow Logs** - Flow-log coverage and destination configuration are checked

#### **A.8.13 - Information Backup**

> *Backup copies of information, software and systems shall be maintained and regularly tested*

* **Backup Jobs** - Backups are executed regularly

* **RDS Snapshots** - Database backups are maintained

#### **A.8.14 - Redundancy**

> *Information processing facilities shall be implemented with sufficient redundancy to meet availability requirements*

* **RDS Encryption** - Multi-AZ deployment status

* **Backup Jobs** - Backup plan, vault, and recent job coverage

#### **A.8.15 - Logging**

> *Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed*

* **CloudTrail Configuration** - API activity is logged

* **VPC Flow Logs** - Network activity is logged

* **CloudWatch Alarms** - Alarm configuration, state, and notification actions are inventoried

#### **A.8.16 - Monitoring Activities**

> *Networks, systems and applications shall be monitored for anomalous behaviour*

* **GuardDuty Status** - Threat monitoring is active

* **GuardDuty Findings** - Anomalies are detected and tracked

* **CloudWatch Alarms** - System monitoring is configured

* **Security Hub Status** - Security posture is monitored

#### **A.8.20 - Networks Security**

> *Networks and network devices shall be secured, managed and controlled*

* **Security Groups** - Network security rules are configured

* **Network ACLs** - Network access controls are in place

* **VPC Flow Logs** - Network flow-logging coverage is verified

#### **A.8.21 - Security of Network Services**

> *Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored*

* **Security Groups** - Network service exposure and risky inbound rules are reviewed

* **Network ACLs** - Subnet-level traffic filtering and segmentation are reviewed

#### **A.8.24 - Use of Cryptography**

> *Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented*

* **S3 Encryption** - Object storage is encrypted

* **RDS Encryption** - Databases are encrypted

* **EBS Volume Encryption** - Block storage is encrypted

* **KMS Key Rotation** - Encryption keys are rotated

#### **A.8.32 - Change Management**

> *Changes to information processing facilities and information systems shall be subject to change management procedures*

* **CloudTrail Events** - Recent management and write events provide change activity evidence

* **AWS Config Status** - Recorder, delivery channel, and configuration-rule status are checked

---

## **Verification Rules**

Auto-verified evidence sources use the following defaults. Accounts can customize supported thresholds when configuring an evidence source.

### **IAM Password Policy**

* Minimum password length: 14 characters

* Require uppercase letters: Yes

* Require lowercase letters: Yes

* Require numbers: Yes

* Require symbols: Yes

* Maximum password age: 90 days

* Password reuse prevention: 24 passwords

### **IAM MFA Status**

* Console users with MFA: 100%

* Root account has MFA: Required

### **IAM Access Keys**

* Maximum key age: 90 days

* Active keys used within the last 90 days: Required

* Multiple active keys per user: Not allowed

### **CloudTrail**

* CloudTrail enabled: Required

* Multi-region trail: Required

* Log file validation: Required

* Encryption enabled: Required

### **S3 Security**

* Default bucket encryption: Required

* Minimum encryption algorithm: AES-256 or AWS KMS

* Account-level and bucket-level public access blocks: Required

### **RDS Encryption**

* All instances encrypted: Required

### **RDS Snapshots**

* Snapshot coverage for RDS instances: Required

* Maximum age of latest snapshot: 7 days

### **EBS and KMS**

* All EBS volumes encrypted: Required

* Default EBS encryption enabled: Required

* Automatic rotation for eligible customer-managed KMS keys: Required

* Maximum key age without rotation: 365 days

### **Network Security**

* No open SSH (0.0.0.0/0:22): Required

* No open RDP (0.0.0.0/0:3389): Required

* No unrestricted all-traffic ingress: Required

* Network ACLs must not allow unrestricted inbound traffic: Required

* VPC Flow Logs enabled: Required

### **Monitoring, Security Services, and Configuration**

* CloudWatch alarms, security-relevant alarms, and notification actions: Required

* GuardDuty enabled in at least one checked region: Required; partial regional coverage produces a warning

* Maximum high-severity GuardDuty findings: 0

* Security Hub enabled in at least one checked region: Required; partial regional coverage produces a warning

* At least one Security Hub standard enabled: Required

* Maximum critical Security Hub findings: 0

* AWS Config enabled in at least one checked region: Required; partial regional coverage produces a warning

* AWS Config recorder active in all enabled regions: Required

* AWS Config rule findings: Up to 10 non-compliant rules produce a warning; more than 10 fail verification

### **Backup Jobs**

* AWS Backup plans and a recent successful backup: Required

* Maximum time since successful backup: 7 days

---

## **Summary: Control Coverage Matrix**

### **SOC 2 Controls by Evidence Source**

**IAM Password Policy**

* CC6.1: Yes

**IAM MFA Status**

* CC6.1: Yes

* CC6.2: Yes

**IAM Access Keys**

* CC6.1: Yes

* CC6.2: Yes

* CC6.3: Yes

**CloudTrail Config**

* CC7.2: Yes

**CloudTrail Events**

* CC6.3: Yes

* CC7.2: Yes

* CC8.1: Yes

**CloudWatch Alarms**

* CC7.1: Yes

* CC7.3: Yes

* CC7.4: Yes

* A1.1: Yes

**VPC Flow Logs**

* CC6.6: Yes

* CC7.2: Yes

**GuardDuty Status**

* CC6.6: Yes

* CC7.1: Yes

**GuardDuty Findings**

* CC6.6: Yes

* CC7.3: Yes

**Security Hub**

* CC7.1: Yes

**AWS Config**

* CC8.1: Yes

**Security Groups**

* CC6.6: Yes

**Network ACLs**

* CC6.6: Yes

**S3 Encryption**

* CC6.1: Yes

* CC6.5: Yes

* CC6.7: Yes

**S3 Public Access**

* CC6.1: Yes

**RDS Encryption**

* CC6.1: Yes

* CC6.5: Yes

* CC6.7: Yes

**EBS Encryption**

* CC6.1: Yes

**KMS Key Rotation**

* CC6.1: Yes

**Backup Jobs**

* A1.1: Yes

* A1.2: Yes

**RDS Snapshots**

* A1.1: Yes

* A1.2: Yes

### **ISO 27001 Controls by Evidence Source**

**IAM Password Policy**

* A.5.15: Yes

* A.5.17: Yes

**IAM MFA Status**

* A.5.15: Yes

* A.5.16: Yes

* A.5.17: Yes

**IAM Access Keys**

* A.5.15: Yes

* A.5.16: Yes

* A.5.17: Yes

* A.5.18: Yes

**CloudTrail Config**

* A.5.23: Yes

* A.8.15: Yes

**CloudTrail Events**

* A.5.18: Yes

* A.8.32: Yes

**CloudWatch Alarms**

* A.8.15: Yes

* A.8.16: Yes

**VPC Flow Logs**

* A.8.12: Yes

* A.8.15: Yes

* A.8.20: Yes

**GuardDuty Status**

* A.5.23: Yes

* A.8.16: Yes

**GuardDuty Findings**

* A.8.12: Yes

* A.8.16: Yes

**Security Hub**

* A.5.23: Yes

* A.8.16: Yes

**AWS Config**

* A.8.9: Yes

* A.8.32: Yes

**Security Groups**

* A.5.15: Yes

* A.8.3: Yes

* A.8.9: Yes

* A.8.20: Yes

* A.8.21: Yes

**Network ACLs**

* A.8.3: Yes

* A.8.20: Yes

* A.8.21: Yes

**S3 Encryption**

* A.8.10: Yes

* A.8.24: Yes

**S3 Public Access**

* A.8.3: Yes

* A.8.9: Yes

* A.8.12: Yes

**RDS Encryption**

* A.8.11: Yes

* A.8.14: Yes

* A.8.24: Yes

**EBS Encryption**

* A.8.1: Yes

* A.8.24: Yes

**KMS Key Rotation**

* A.8.24: Yes

**Backup Jobs**

* A.8.13: Yes

* A.8.14: Yes

**RDS Snapshots**

* A.8.13: Yes

---

## **Related Documentation**

* [AWS Integration User Guide](guide_aws-integration.md)

* [AWS Setup Guide](guide_aws-setup.md)

---

*Last updated: July 2026*