sample-aiml-security-assessment

Security Checks Reference

This document provides a comprehensive reference for all 208 security checks performed by the AI/ML Security Assessment framework (94 core checks across Amazon Bedrock, Amazon SageMaker AI, Amazon Bedrock AgentCore, and AWS Agent Registry, 38 Agentic AI Security checks, 64 Responsible AI GRC checks, and 12 OWASP Top 10 for LLM checks).

Sources differ by bucket and are not interchangeable: the core Bedrock, SageMaker, AgentCore, and AWS Agent Registry checks derive from the AWS Well-Architected Generative AI Lens security best practices (gensec*) and service security documentation; the Agentic AI Security checks from the AWS Well-Architected Agentic AI Lens; the FS-* Responsible AI GRC checks from the AWS GRC User Guide; and the OW-* checks from the OWASP Top 10 for LLM. The AWS Well-Architected Responsible AI Lens is not a source for any of them — see Responsible AI GRC — scope, sources, and compatibility.

The 64 Responsible AI GRC checks occupy 69 FS-* numbers: 64 ship as standalone checks and 5 are merged into upstream Bedrock/SageMaker checks. The framework also emits BR-00, SM-00, AC-00, AR-00, FS-00, and OW-00 operational marker rows at runtime; these are not controls and are excluded from the 208-check total. Per-control provenance, including which controls are project extensions rather than guide-derived, is recorded in provenance.json.

The counts above describe the full catalog. Core service assessments are enabled by default and can be selected independently with the four Enable*Assessment switches. Deselected services produce no findings and appear as Not selected in the report; this is not an N/A finding or a compliant result. Agentic AI and OWASP mapping coverage decreases when their direct-service sources are deselected.

Table of Contents


Overview

The framework evaluates your AI/ML workloads against AWS security best practices across four services:

Service Number of Checks Focus Areas
Amazon SageMaker AI 29 Security Hub controls, encryption, network isolation, GuardDuty AI Protection, HyperPod, IAM, MLOps, Model Registry policy exposure
Amazon Bedrock 40 Guardrails, prompt-attack/image filters, retention, inference profiles, automated reasoning and Marketplace endpoint governance, encryption, networking, IAM, logging, monitoring, and evaluation
Amazon Bedrock AgentCore 17 Runtime/tool VPC isolation, encryption, browser recording, observability, resource policies, Identity token vaults, and online evaluation
AWS Agent Registry 8 IAM access, approval governance, discovery authorization, encryption, organization auto-detection, record lifecycle, and provenance
Agentic AI Security 38 Bounded autonomy, agent identity, tool authorization, Registry governance and provenance, guardrail enforcement, prompt/input protection, memory privacy, auditability, continuous assurance, abuse protection
Responsible AI GRC 64 Unbounded consumption, excessive agency, supply chain, training data poisoning, vector weaknesses, non-compliant output, misinformation, harmful output, biased output, PII disclosure, hallucination, prompt injection, improper output handling, off-topic output, out-of-date training data
OWASP Top 10 for LLM 12 LLM01 Prompt Injection, LLM02 Sensitive Info Disclosure, LLM03 Supply Chain, LLM04 Data/Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector/Embedding Weaknesses, LLM09 Misinformation, LLM10 Unbounded Consumption

Check ID Convention

Each security check has a unique identifier with a service prefix:

Prefix Service Example
SM-XX Amazon SageMaker SM-01, SM-30 (SM-29 reserved)
BR-XX Amazon Bedrock BR-01, BR-40
AC-XX Amazon Bedrock AgentCore AC-01, AC-17
AR-XX AWS Agent Registry AR-01, AR-08
AG-XX Agentic AI Security AG-01, AG-38
FS-XX Responsible AI GRC FS-01, FS-69
OW-XX OWASP Top 10 for LLM OW-01, OW-12

Runtime marker IDs (not controls)

The *-00 rows below make assessment coverage and execution problems visible in CSV and HTML reports. They are operational markers rather than security controls, do not increase the published check counts, and must not be treated as evidence that a control passed or failed.

Marker Runtime meaning Normal status / severity
BR-00 Amazon Bedrock is unavailable or not enabled in the target region, so regional Bedrock checks were not run. N/A / Informational
SM-00 Amazon SageMaker AI is unavailable or not enabled in the target region, so regional SageMaker checks were not run. N/A / Informational
AC-00 Amazon Bedrock AgentCore is unavailable in the target region, or the Runtime availability probe rejected the assessment credentials before regional checks could run. Unexpected errors inside individual checks use their affected AC-* or AG-* control IDs instead. N/A / Informational
AR-00 AWS Agent Registry is unavailable in the target region, so regional AR-03 through AR-08 checks were not run. N/A / Informational
FS-00 No regional Bedrock, AgentCore, or SageMaker resource footprint was found, so Responsible AI GRC was not applicable to that region. N/A / Informational
OW-00 A required upstream assessment CSV was missing, so one or more mapping-derived OWASP rows could not be generated. N/A / Informational

When a Bedrock API is access-denied or an AgentCore check raises an unexpected execution error, the affected control ID is reported as informational N/A with an incomplete-assessment message. These rows remain visible for troubleshooting but are excluded from scoring. A control is Failed only when the scanner successfully observes evidence that violates its baseline.

FS-00 is described in more detail in Responsible AI GRC Checks, and OW-00 in OWASP Top 10 for LLM Security Checks.


Report Scoring

Pass rates are calculated from unique direct-service Check_ID values, not from report-row counts. Findings for resources, Regions, or accounts are aggregated into one result per control: any assessable Failed row makes the control fail, and a control passes only when all assessable rows pass. Informational and N/A rows are excluded from the score. Agentic AI and compliance-mapping rows are contextual views of source evidence and are also excluded to prevent double counting. Resource-level rows remain visible for investigation and remediation.


Severity Levels

Severity Description Action Required
High Critical security issues that could lead to data exposure, unauthorized access, or compliance violations Immediate remediation recommended
Medium Important security improvements that strengthen your security posture Address in next maintenance window
Low Minor optimizations and best practice recommendations Address when convenient
Informational Advisory information about your configuration No action required

Status Values

Status Description
Failed Security issue identified that requires remediation
Passed Checked resources met the assessed best practice at time of scan
N/A The check was not applicable, advisory-only, unavailable in the region, or could not be assessed (for example, because no resources exist or access was denied).

Amazon SageMaker AI Security Checks (29)

SM-01: Internet Access

SM-02: AWS IAM Permissions

SM-03: Data Protection

SM-04: Amazon GuardDuty Integration

SM-05: MLOps Features

SM-06: Clarify Usage

SM-07: Model Monitor

SM-08: Model Registry

SM-09: Notebook Root Access

SM-10: Notebook Amazon VPC Deployment

SM-11: Model Network Isolation

SM-12: Endpoint Instance Count

SM-13: Monitoring Network Isolation

SM-14: Model Container Repository

SM-15: Feature Store Encryption

SM-16: Data Quality Encryption

SM-17: Processing Job Encryption

SM-18: Transform Job Encryption

SM-19: Hyperparameter Tuning Encryption

SM-20: Compilation Job Encryption

SM-21: AutoML Network Isolation

SM-22: Model Approval Workflow

SM-23: Model Drift Detection

SM-24: A/B Testing and Shadow Deployment

SM-25: ML Lineage Tracking

SM-26: GuardDuty AI Protection

SM-27: HyperPod EBS CMK Encryption

SM-28: HyperPod VPC Configuration

SM-29 is reserved for SageMaker Unified Studio private networking. It is not currently emitted because the available domain APIs do not expose a sufficient domain-level networking configuration.

SM-30: Model Package Group Resource Policy Exposure


Amazon Bedrock Security Checks (40)

BR-01: AWS IAM Least Privilege

BR-02: Amazon VPC Endpoint Configuration

BR-03: Marketplace Subscription Access

BR-01, BR-02, BR-03, BR-08, BR-10, and BR-21 depend on the shared IAM permissions cache. If that prerequisite is missing, unreadable, or malformed, each affected control is reported as informational N/A; an empty replacement inventory is never treated as evidence of compliance.

BR-04: Model Invocation Logging

BR-05: Guardrail Configuration

BR-06: AWS CloudTrail Logging

BR-07: Prompt Management

BR-08: Agent AWS IAM Configuration

BR-09: Knowledge Base Encryption

BR-10: Guardrail AWS IAM Enforcement

BR-11: Custom Model Encryption

BR-12: Invocation Log Encryption

BR-13: Flows Guardrails

BR-14: Stale Bedrock Access

BR-15: Cross-Account Guardrails Enforcement

BR-16: Guardrail Tier Validation

BR-17: Custom Model Customer-Managed KMS Encryption

BR-18: Model Evaluation Implementation

BR-19: Prompt Flow Validation

BR-20: Knowledge Base Encryption Enhancement

BR-21: Agent Action Group IAM Least Privilege

BR-22: Model Invocation Throttling Limits

BR-23: Guardrail Content Filter Coverage

BR-24: Automated Reasoning Policy Implementation

BR-25: RAG Evaluation Jobs

BR-26: Guardrail Sensitive Information Filter

BR-27: Guardrail Contextual Grounding Check

BR-28: Agent Guardrail Association

BR-29: Agent Idle Session TTL

BR-30: Imported Model Customer-Managed KMS Encryption

BR-31: Batch Inference Output Encryption

BR-32: CloudWatch Alarms on Bedrock Metrics

BR-33: Amazon Inspector Lambda Code Scanning

BR-34: Guardrail Prompt Attack Filter

BR-35: Guardrail Image Content Filter Coverage

BR-36: Application Inference Profile Governance

BR-37: Bedrock Account Data Retention

BR-38: Automated Reasoning Policy CMK Encryption

BR-39: Marketplace Model Endpoint VPC Configuration

BR-40: Marketplace Model Endpoint CMK Encryption


Amazon Bedrock AgentCore Security Checks (17)

AC-01: Runtime Amazon VPC Configuration

AC-02: AWS IAM Full Access

AC-03: Stale Access

AC-04: Observability

AC-05: Amazon ECR Repository Encryption

AC-06: Browser Tool Recording

AC-07: Memory Encryption

AC-08: Amazon VPC Endpoints

AC-09: Service-Linked Role

AC-10: Resource-Based Policies

AC-11: Policy Engine Encryption

AC-12: Gateway Encryption

AC-13: Gateway Configuration

AC-14: Identity Token Vault CMK Encryption

AC-15: Code Interpreter Network Isolation

AC-16: Custom Browser Network Isolation

AC-17: Online Evaluation Coverage


AWS Agent Registry Security Checks (8)

AWS Agent Registry checks use the AR-XX namespace and run in a dedicated regional Lambda that writes its own CSV artifact and HTML report area. They are included with the default assessment.

AR-01 and AR-02 are account-scoped IAM checks that read the shared permission cache and are reported once under the Global region. AR-03 through AR-08 are regional and use the generally available agent-registry-control API. Registry detail is read once per registry and shared across AR-03 through AR-06; record inventory is shared between AR-07 and AR-08.

Record inventory is bounded to 1,000 records and paginates within the Lambda deadline. When the cap or the deadline is reached, AR-07 and AR-08 report a single informational N/A incomplete-assessment row and continue assessing the records already collected. A registry that is not READY, a registry whose detail call fails, an access-denied response, and a region where AWS Agent Registry is unavailable all resolve to informational N/A with error-specific remediation rather than to a failure.

AR-01: AWS IAM Full Access

AR-02: Stale Access

AR-03: Registry Publication Approval Governance

AR-04: Registry Discovery Authorization

AR-05: Registry Customer-Managed KMS Encryption

AR-06: Registry Organization Auto-Detection

AR-07: Registry Record Lifecycle Governance

AR-08: Registry Record Provenance


Agentic AI Security Checks (38)

Agentic AI Security checks use the AG-XX namespace and are included with the default assessment. They follow a hybrid model:

These checks reference the AWS Well-Architected Agentic AI Lens, with scope limited to the Security pillar.

AG-01: Agent Guardrail Association

AG-02: Harmful Content Guardrail Coverage

AG-03: Sensitive Information Protection

AG-04: Automated Reasoning Guardrails

AG-05: Grounding Controls

AG-06: Tool Execution Least Privilege

AG-07: Model Invocation Logging

AG-08: API Audit Trail

AG-09: Guardrail Enforcement Boundary

AG-10: Adversarial Evaluation Coverage

AG-11: Prompt Flow Validation

AG-12: Invocation Abuse Controls

AG-13: Session Boundary

AG-14: Operational Abuse Alarms

AG-15: Runtime Network Boundary

AG-16: AgentCore Least Privilege

AG-17: Stale AgentCore Access

AG-18: AgentCore Observability

AG-19: Memory Data Protection

AG-20: Private AgentCore Connectivity

AG-21: Resource Policy Boundary

AG-22: Policy Engine Data Protection

AG-23: Gateway Data Protection

AG-24: Gateway Inbound Authorization

AG-25: Gateway Tool Policy Enforcement

AG-26: Gateway Error Detail Exposure

AG-27: Gateway WAF Protection

AG-28: Identity Token Vault Protection

AG-29: Code Interpreter Isolation

AG-30: Prompt Attack Protection

AG-31: Browser Tool Isolation

AG-32: Online Evaluation Assurance

AG-33: Registry Publication Approval Governance

AG-34: Registry Discovery Authorization

AG-35: Registry Metadata Encryption

AG-36: Organization Discovery Coverage

AG-37: Registry Record Lifecycle Governance

AG-38: Registry Record Provenance

Runtime guardrail methodology note

InvokeGuardrailChecks / ApplyGuardrail are per-request runtime APIs rather than a persistent configuration surface. The assessment therefore does not emit a pass/fail finding for their use; applications should validate these calls through runtime architecture review, telemetry, and testing.


Additional Resources


Responsible AI GRC Checks (64 additional, 5 upstream extensions)

These 64 standalone checks (FS-XX) extend the framework with cross-industry AI governance, risk, and compliance controls derived from the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. An additional 5 FS checks are contributed as extensions to existing SM-07, SM-22, SM-23, BR-04, and BR-06 (see in-file extension notes).

The full catalog is in SECURITY_CHECKS_RESPONSIBLE_AI_GRC.md, organized into three parts:

The same document includes the shared intro, severity rubric, validation note, upstream-overlap table, and the compliance framework mapping table (SR 11-7, FFIEC CAT, NYDFS 500.06, PCI-DSS 12.3.2, DORA Art.6, MAS TRM 9, ISO 27001 A.12, ECOA, OWASP LLM Top 10).


OWASP Top 10 for LLM Checks (12)

These 12 checks (OW-XX) map the AI/ML Security Assessment findings to the OWASP Top 10 for LLM 2025 categories. OW-01..OW-10 are derived by mapping from existing BR/SM/AC/FS findings. The OWASP Lambda itself does not call AWS APIs for mapped rows, but enabling OWASP can auto-run Responsible AI GRC to produce FS-* source findings when Responsible AI GRC is otherwise disabled. OW-11 and OW-12 are net-new checks that address LLM07 (System Prompt Leakage), which the existing checks do not directly cover. If a required source CSV is missing, the OWASP Lambda emits an informational OW-00 completeness row rather than silently dropping derived rows.

Opt-in. OWASP checks run only when the EnableOWASPAssessment deployment parameter is true and the Step Functions execution includes "enableOWASP": "true".

Rendered under a new “By Compliance Standard” sidebar section of the HTML report, alongside future NIST AI RMF and EU AI Act sections.

The full catalog is in SECURITY_CHECKS_OWASP.md, organized by OWASP category:

Preliminary and illustrative. OWASP mappings have not been reviewed by external auditors. Validate mappings with your Security/Compliance team before using as audit evidence.