sample-aiml-security-assessment

Changelog

All notable user-facing and deployable changes to this project are documented in this file.

Changes are accumulated under Unreleased as they are merged. Creating a release is not required for every change. When a version is tagged, move its entries into a dated version section and create a new empty Unreleased section.

Unreleased

Added

Fixed

Deployment impact

These instructions assume the 2.0.0 prerequisites below are already applied. When upgrading from an earlier release, complete the 2.0.0 member-role and central infrastructure updates first. Then apply this feature’s parameters and rerun CodeBuild to deploy the assessment/report changes. No additional IAM permissions are introduced by service selection.

2.0.0 - 2026-09-18

This release grows the catalog from 161 checks across five areas to 208 checks across seven, adding OWASP Top 10 for LLM and AWS Agent Registry as assessment areas and renaming the Financial Services GenAI risk capability to Responsible AI GRC. It also hardens the assessment IAM roles and makes incomplete multi-account coverage fail a run rather than publish a partial report.

Upgrading is not a single step and is not fully backward compatible:

Added

Changed

Fixed

Deployment impact

Apply these updates in order.

  1. Multi-account member-role StackSet update required first because deployment/1-aiml-security-member-roles.yaml changed. It creates the member-role customer-managed deployment policy and narrows AIMLSecurityMemberRole to deployment, execution-polling, and report-retrieval operations, including narrowly scoped recovery of failed assessment or SAM-managed stacks; assessment service API permissions remain on SAM Lambda execution roles.
  2. Multi-account central infrastructure update required next because deployment/2-aiml-security-codebuild.yaml changed with the AWS Agent Registry baselines, least-privilege CodeBuild deployment policy, and narrowly scoped failed-stack recovery. This update also removes the obsolete conditional local member-role resource if an older stack still tracks it.
  3. Single-account infrastructure update required because deployment/aiml-security-single-account.yaml changed with the same baselines, CodeBuild policy hardening, and failed-stack recovery. This update also removes the obsolete local member-role resource if an older stack still tracks it.
  4. CodeBuild run required last to deploy the updated assessment code, dependencies, buildspec.yml, and AWS SAM templates (aiml-security-assessment/template.yaml and aiml-security-assessment/template-multi-account.yaml). The updated buildspec also makes incomplete multi-account coverage fail the run instead of publishing an apparently complete consolidated report, and report rendering or upload failures now fail the Step Functions execution. The SAM templates create the standalone AWS Agent Registry assessment Lambda and update the state machine.

The template and CodeBuild updates above also tighten the TargetRegions AllowedPattern to reject all. Any stored parameter value, saved stack input, or automation that passes TargetRegions=all must be changed to an empty value or an explicit region list before the next deployment or CodeBuild run, or CloudFormation/buildspec validation will fail.

Deployments pinned to a tag or commit must update the GitHubBranch CloudFormation parameter to the revision containing these changes before starting CodeBuild.

1.0.0 - 2026-07-10